Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
- ID
- 18005
- Status
- summarized
- Published
- 26 Aug 2026, 1:47 PM
- Fetched
- 26 Aug 2026, 3:24 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/fake-apple-support-ai-calls-target.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 26 Aug 2026, 3:24 PM
- Tags
- Audience
- developersai_agent_userssaas_founders
What happened
SOCRadar disclosed a phishing-as-a-service platform called AnonyMousKIT that uses rented AI voice agents (via Vapi) to call owners of stolen Apple devices, posing as Apple Support to extract device passcodes, Apple ID credentials, and live 2FA codes. The platform is credit-metered across five channels (email at 1.5 credits, AI voice agent at 2 credits, etc.) and operated as a full criminal SaaS with tiered subscriptions, customer support, and infrastructure replacement. 200 call records were recovered, 179 targeting Brazilian numbers, running from August 2025 to May 2026.
Why it matters
If you build or use AI voice agent platforms like Vapi, this is a concrete example of your tooling being weaponized for automated social engineering at scale — the operator ran five configured personas on a commercial voice platform with no apparent friction. Founders shipping voice agents should consider what abuse-detection obligations their platforms impose and whether their terms cover this.
Discussion angle
The PhaaS operator treated this like a real SaaS business — credit bundles, published pricing, customer support — and ran 200 calls through a mainstream voice agent API. What does platform responsibility look like for AI voice agent providers, and should builders expect KYC or usage limits before this becomes regulated?