# Voice AI Is Now Cold-Calling iPhone Theft Victims to Steal Their Passcodes


A stolen iPhone used to have a ceiling on its value. Apple's Activation Lock — the feature that ties a device to an Apple Account and survives a factory reset — meant that most phones grabbed off tables, snatched from hands, or lifted from bags ended up stripped for parts. The phone itself was worthless without the owner's credentials. That ceiling just got raised.


A phishing-as-a-service operation called AnonyMousKIT has built a fully automated pipeline that turns stolen iPhones into unlocked, data-drained, resaleable devices — using AI voice agents to call victims, impersonate Apple support, and talk them into handing over their passcodes. Researchers at SOCRadar documented the operation this week, and the scope of what they found reveals how thoroughly the gray market for stolen devices has industrialized.


## The Problem Activation Lock Was Supposed to Solve


When Apple introduced Activation Lock, the calculus around phone theft shifted. A thief who can't bypass Find My is holding hardware worth maybe $50 in scrap components. A thief who can bypass it is holding a device worth $300 to $700 on the secondary market — plus, potentially, everything in the victim's iCloud backup and Keychain.


That gap in value created demand for a solution. AnonyMousKIT is that solution, sold as a service.


The operation has been running since early 2024 and has grown into something closer to a franchise than a criminal side project: 506 domains, 168 storefront brands acting as resellers, each selling access to the platform's phishing infrastructure under their own labels. SOCRadar was able to map the full architecture because the platform operator left bare relative paths exposed — a basic operational security failure that handed researchers a window into everything.


## How "Alice from Apple Support" Works


The attack chain starts with the device itself. When a phone's Lost Mode is enabled, the owner can attach contact information — a callback number, a message. AnonyMousKIT harvests that data directly from stolen phones and uses it to reach out to victims. The platform can contact them via email, SMS, WhatsApp, or phone call, all impersonating Apple.


The email variant is polished. It includes the correct device model and IMEI — details that make the message look indistinguishable from a legitimate Apple notification. It claims the device has been located and directs the victim to a fake Find My or Apple account page where they're asked for their passcode, Apple ID credentials, and two-factor authentication code.


But the phone call variant is what makes this operation genuinely novel. SOCRadar recovered records of 200 calls made between August 2025 and May 2026, with 55 distinct interaction transcripts. The calls were handled by a voice AI agent operating under five different personas. One documented persona — "Alice from Apple Support" — tells victims that someone brought their phone to an Apple Store, that the store retained it for verification, and that the victim needs to confirm ownership by dictating their passcode. Then Alice directs them to the phishing page.


The economics are worth sitting with: each call costs the operator approximately $0.10. At that price, volume is trivial. There's no expensive call center, no hired actors who might get nervous or make linguistic mistakes, no shift scheduling. The AI doesn't hesitate, doesn't have an accent that might trigger suspicion, and runs 24 hours a day.


Ninety percent of the documented calls targeted victims in Brazil, though the platform's reach extends to South Africa, Indonesia, Italy, India, and Kenya.


## What Comes After the Passcode


Once the operators have valid credentials, the damage extends well past the device. A compromised Apple ID unlocks iCloud backups, which for most users contain years of messages, photos, documents, and app data. Keychain — Apple's credential manager — stores passwords for banking apps, email accounts, and, critically, corporate systems. A percentage of the emails SOCRadar found in the platform's records were sent to government and corporate addresses, suggesting that some of the stolen devices were employer-issued or carried work accounts.


The device itself gets factory-reset, removed from Find My, and listed for resale. The victim is left with nothing but the phishing page they just submitted their credentials to.


## HackWire Analysis


AnonyMousKIT is being reported primarily as a PhaaS story, but the more significant development is what it represents for the secondary device market. This is the maturation of a supply chain. Stolen phones flow in, credentials flow out, unlocked devices flow out the other side. The 168 reseller storefronts suggest a distribution network that's already running at scale — this isn't experimental criminal infrastructure, it's an established business with margins.


The voice AI component is the part that should concern defenders most, and it's getting insufficient attention. Every social engineering training program tells employees to be suspicious of bad grammar, foreign accents, and scripted-sounding callers. Voice AI strips away most of those signals. "Alice" speaks naturally, responds contextually, and doesn't crack under mild pressure. The $0.10-per-call cost means operators can run hundreds of attempts for the price of a meal. That changes the math on who's a viable target — it's no longer worth phishing only high-value individuals when you can carpet-bomb a region.


The Brazil concentration (90% of calls) points to a specific criminal ecosystem feeding into the platform — almost certainly organized street theft networks in major Brazilian cities, where phone snatching has been a documented epidemic for years. The platform is, in effect, their monetization layer. As that model proves out in Brazil, expect geographic expansion.


For defenders, the practical implication is this: Apple's Activation Lock is not a sufficient theft deterrent when the unlock service is available for pennies per attempt. Organizations managing Apple device fleets through MDM should audit what personal Apple IDs are enrolled alongside corporate accounts. Employees who lose devices should be instructed to change their Apple ID password and revoke trusted devices immediately — before they take any call from "Apple Support." And security awareness training needs to explicitly address AI voice calls as a phishing vector, not a future threat but a current one.


The credential interception pipeline — device stolen, victim called, passcode harvested, iCloud drained, Keychain dumped — is fully automated and fully operational. The only human decision left in this chain is which stolen phone to feed in next.


— HackWire Editorial


---


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)