Phishing Scams Exploit Apple Account Notifications

Phishing Scams Exploit Apple Account Notifications

First seen 21 Apr 2026, 00:59 UTC BleepingcomputerScworldAu.Pcmag 86% similarity 64.5

Article Content

Browse articles
ThreatCluster

Threat actors are abusing Apple account change notifications to distribute phishing emails that falsely claim an $899 iPhone purchase was made via PayPal. These emails appear legitimate as they are sent from Apple's own servers, increasing their credibility and likelihood of bypassing spam filters. The scam involves creating an Apple ID, embedding phishing text within the first and last name fields, and modifying shipping information to trigger the notification. Victims are misled into believing their accounts have been compromised and are prompted to call a scammer's number for cancellation, where they may be coerced into providing sensitive information or installing malware. This tactic highlights the evolving nature of phishing attacks that leverage legitimate infrastructure. Users are advised to be cautious with unexpected account alerts and verify claims through official channels.

Key Points: • Phishing emails exploit legitimate Apple notifications to appear credible. • Attackers create Apple IDs to embed scam messages in account alerts. • Victims are tricked into calling scammers, risking financial and data theft.

ThreatCluster AI

Timeline

2026-04-14
Phishing emails sent following account information modification.
2026-04-19
BleepingComputer reports on the phishing campaign.
2026-04-20
Scworld publishes a brief on the same phishing scams.

Community

Browse all →