# Your iPhone Gets Stolen. Then "Apple Support" Calls — and That's the Real Attack.


The theft is almost a setup. A phone gets grabbed on a subway platform, lifted from a coffee shop table, or snatched mid-walk. The victim immediately puts the device in Lost Mode, which triggers Activation Lock — Apple's feature designed to render stolen hardware useless without the owner's Apple ID credentials. Game over for the thief.


Except it isn't. Within hours, sometimes minutes, the victim's phone rings. It's Apple Support — or at least, an eerily convincing facsimile of it. The "representative" knows the device was just stolen. They're calling to help. They just need to verify identity: the six-digit passcode, maybe a two-factor code sent to a backup number.


The victim, already rattled, already burned, gives it up. The thief now has everything they need to disable Activation Lock and resell a fully wiped iPhone for several hundred dollars.


## The Platform Behind the Call


SOCRadar's Threat Research Unit has published details on the infrastructure making this possible at scale: a phishing-as-a-service platform they're tracking as AnonyMousKIT. It's credit-metered — operators buy credits, feed in target phone numbers, and the platform handles the rest, including deploying rented AI voice agents that handle the calls autonomously.


This isn't someone with a script calling from a burner phone. It's an automated pipeline. The AI agent conducts the conversation, adapts to responses, sounds calm and professional, and extracts credentials without a human social engineer ever getting on the line. The commoditization of what used to require skilled manipulation is now the headline here.


## Why Activation Lock Makes Stolen Phones Valuable — And Worthless


Apple introduced Activation Lock in 2013 with iOS 7, directly in response to the "iPhone mugging epidemic" that plagued cities when a stolen iPhone fetched top dollar on grey markets. Activation Lock ties the device to an Apple ID. Without the owner's credentials, the phone is effectively a brick — it can't be set up, wiped through normal means, or paired to a new account.


The secondary market responded by creating unlock services — many of them operating through the same grey-market ecosystems that sell the stolen devices. AnonyMousKIT is the industrialized version of that unlock service, just targeting the weakest link in the chain: the victim themselves, at the exact moment they're most likely to comply.


The attack window is narrow and deliberately exploited. Theft victims are stressed, emotional, and actively trying to recover their device. When a call arrives that matches their mental model of "what happens next" — Apple detecting the loss and reaching out — the cognitive defenses are already compromised.


## AI Vishing Goes Professional


Voice phishing, or vishing, isn't new. What's changed is the barrier to entry. Until recently, running a convincing vishing operation required either skilled human social engineers or recordings that couldn't handle real-time conversation. AI voice agents change both constraints. They can hold a dynamic conversation, handle objections, maintain a consistent persona under pressure, and scale across dozens of simultaneous calls.


AnonyMousKIT's credit-based model means operators aren't even running the AI infrastructure themselves — they're renting access to it, the same way a ransomware affiliate rents access to ransomware-as-a-service infrastructure. The criminal labor required has been compressed to: acquire stolen device information, buy credits, submit targets.


The sophistication gap between professional fraud operations and opportunistic criminals is closing fast.


## What Defenders — and Victims — Should Know


Apple will not call you. The company does not proactively phone customers about device theft, Activation Lock status, or verification codes. If you receive such a call after losing a device, hang up.


The specific tell in this attack: the request for your device passcode. Apple Support has no legitimate reason to ask for that. Apple ID password, possibly. Two-factor codes sent to Apple's own systems, in specific authenticated contexts. A local device passcode? Never.


For anyone who has already fallen for this: immediately change your Apple ID password, review trusted devices in your Apple ID settings, and revoke any sessions you don't recognize. If your Apple ID credentials were compromised, cycle passwords on accounts that share that email address.


For organizations issuing iPhones to employees: MDM enrollment with supervised mode means Activation Lock can be managed through institutional Apple IDs, removing the individual credential dependency that this attack exploits.


---


## HackWire Analysis


AnonyMousKIT should be read in the context of a broader pattern that's accelerating in 2025 and 2026: the full-stack commoditization of attacks that previously required human expertise at every step.


Ransomware-as-a-service normalized the outsourcing of malware development and infrastructure. Phishing kits normalized outsourcing the credential-harvesting front end. Now AI voice agents are normalizing the outsourcing of the social engineering layer — the part that previously required a skilled human on a phone. When that last barrier falls, vishing campaigns become as scalable as email phishing, with significantly higher success rates.


What's particularly notable about the AnonyMousKIT case is the targeting logic. This isn't bulk dialing. The platform targets people whose devices were just stolen — meaning there's an upstream data source feeding it fresh victim information. Where is that data coming from? Theft networks that log device identifiers and associated contact information, or possibly dark web markets where stolen device listings include owner contact details scraped at time of theft. Either way, the attack chain now starts at the moment of physical theft and completes within the hour.


The comparison to check is the surge in AI-powered IRS and Social Security impersonation calls in 2023-2024. Those were early-generation robocalls with limited conversational flexibility. The next generation — what AnonyMousKIT represents — holds a real conversation. Prior research from companies like Hiya and Pindrop documented victim compliance rates climbing sharply when calls feel interactive rather than scripted. Apple's brand trust makes this worse: its Net Promoter Score is among the highest of any consumer technology company, meaning victims extend more good faith to someone claiming to represent it.


The defender-side answer isn't just user education — it's pressure on Apple to make the theft-to-activation-lock workflow more adversarially robust, specifically by adding delays or secondary verification that doesn't route through the victim's own compromised device or phone number.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)