
What The Service Is Selling
BleepingComputer says SOCRadar tracked AnonyMousKIT as a phishing-as-a-service operation active since early 2024. The service is designed to help criminals unlock stolen iPhones, disable Activation Lock, and increase resale value while also exposing the victim's Apple account and synced data.
The reporting says the broader ecosystem is tied to harvesting Apple IDs, accessing iCloud backups, and reaching Keychain credentials, which turns a phone-theft story into a real identity and data-exposure story.
How The Lure Works
Victims receive emails that impersonate Apple and claim the missing phone has been located. The messages reportedly include the correct model and IMEI details to make the lure feel legitimate and urgent.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
From there, the victim is sent to a fake Find My or Apple page and asked for the device passcode, Apple account credentials, and the two-factor authentication code. In some cases, an AI voice persona such as "Alice from Apple Support" reinforces the lie by claiming someone tried to unlock the phone at an Apple Store and asking the victim to confirm ownership verbally.
Why The Enterprise Angle Matters
This is not only a consumer-fraud problem. SOCRadar warns that a compromised Apple ID can expose iCloud backups, Keychain passwords, work email, and other corporate information on personal or employer-issued Apple devices.
The reporting also says researchers recovered records of 200 calls made between August 2025 and May 2026, using 55 interaction transcripts handled by a voice AI agent across five personas. That suggests a structured operation, not a one-off scam.
What Teams Should Do Next
- Tell employees and support staff that Apple or IT should never ask them to dictate a device passcode over the phone.
- Treat a stolen corporate or dual-use iPhone as an identity-and-data exposure event, not only a lost-device event.
- Review whether Apple account recovery, passcode-reset, and managed-device guidance are covered clearly in incident-response playbooks.
- Use this story to revisit how much corporate access or sensitive data can ride on a personal Apple ID tied to a work-used device.
Source Context
CyberExperts used BleepingComputer as the primary source and kept the operational details that matter most: early-2024 service activity, realistic Apple lures with model and IMEI details, fake Find My pages, AI voice personas, 200 recovered call records, and the iCloud/Keychain/work-email exposure angle described by SOCRadar.
Related In The Daily Brief
See this item in The 5-Minute Cyber Brief