AI Voice Scams Hijack Stolen Apple Devices via Phishing-as-a-Service

Cybercriminals have unleashed a new phishing-as-a-service (PhaaS) platform called AnonyMousKIT that uses AI voice calls to target people whose Apple devices have been lost or stolen. These scams attempt to obtain device passcodes, Apple ID credentials, and two-factor authentication (2FA) codes by impersonating Apple Support.

How the Scam Works

AnonyMousKIT offers its criminal customers a full toolkit: for a price, victims can be reached via email, SMS, WhatsApp, pre-recorded voice calls, or live AI voice agents. Fake Apple-branded pages and calls lure victims into providing their 4- or 6-digit device passcode, then their Apple ID, and finally a live 2FA code. According to public guidance, Apple never asks for such sensitive information to provide support.

The scam includes an animated capture page showing the stolen device’s location via Find My, and references the actual model identifier of the device to lend legitimacy. The AI voice component works from a commercial text-to-speech platform, with at least five personas learned (all using a name like “Alice from Apple Support”) speaking in English, Spanish, Portuguese. Calls recorded between August 2025 and May 2026 reveal many going to Brazil, and cost around $0.10 each.

Scale, Infrastructure & Risks

Analysis estimated that across numerous back-end websites tied to AnonyMousKIT, more than 6,000 send attempts were logged between March and July 2026. Three storefronts—i-Blocker, Key Unlock, and KG-KING—launched simultaneously in April, sharing email relay infrastructure, suggesting they’re operated by a single group.

The email phishing side uses subject lines like “Your device has been found” or simply “Alert,” sender names spoofing official Apple channels, and Gmail relay accounts with Apple-style display names. Tactics also include tracking victim city via location tokens embedded in-email, and using malicious capture pages hosted under anonymous URLs.

Why This Matters & How to Protect Yourself

The activation lock feature Apple added in iOS 7 is meant to tie hardware to an Apple ID, rendering stolen devices useless. But these social engineering attacks attempt to bypass it—if successful, thieves can restore or reuse stolen hardware.

Security researchers warn that 2FA is the final target, enabling account takeover in real time. Moving valuable Apple IDs to hardware-based security keys is advised, as this mitigates interception attacks that depend on entering codes.

All told, AnonyMousKIT is not a small spam operation; it resembles a criminal business with service tiers, subscriptions, customer support, and credit bundles. The AI-driven voice agent appears to be its most advanced innovation to date, blending technical tools and social engineering for large-scale attacks.

Watchpoints

Users should always be wary of unsolicited calls or messages claiming to be Apple Support. Apple’s published policy is clear: the company never demands passcodes, 2FA codes, or passwords through third-party links or unsolicited contact. Anyone receiving suspicious messages should report them to Apple directly.

What this means: AI has now empowered scammers to run these attacks at scale, dropping costs per victim down drastically. Protecting your Apple ecosystem means more than strong passwords—it means using hardware keys, staying alert to impersonation, and remembering that real support never asks for your most sensitive credentials. Expect these attacks to evolve, so vigilance and verified security practices are more crucial than ever.