We're hearing more and more about password reset attacks being used to target Apple iPhone users.
As Mashablereported last month, hackers are attacking iPhones via a method that inundates them with password reset prompts. These hacking campaigns have also been called MFA (multi-factor authentication) bombing or fatigue attacks.
These attacks aren't new. Reports about them online have been shared for a few years now. However, based on online discussions around them, there seems to be an uptick in cases now.
Basically, in this attack, an iPhone user is asked through dozens of notification pop-ups to reset their Apple ID password. As X user @parth220shared in his retelling of being the target of this attack, this renders a user's iPhone inoperable — unless the user chooses the "Don't Allow" option for every reset password notification.
Tweet may have been deleted
The attack takes it up a notch in the next step. The hacker then spoofs an official Apple phone number and calls the target about the password issue, presenting themself as an Apple employee. According to KrebsonSecurity, individuals impacted by the attack report that the malicious actor possesses personal data gleaned from the web about the target, enabling them to construct a persuasive facade as a genuine Apple employee. The hacker then attempts to use that trust to gain access to the target's phone and its data remotely.
However, iPhone users don't have to fall for this. A few outlets, such as 9to5Mac,have now put out guides on how to avoid being a successful target of a MFA bombing attack.
And here's Mashable's guide to making sure you avoid being a victim of the password reset attack.
This is an extremely important rule — and it is a tried-and-tested method to avoid getting hacked or scammed in a multitude of different attacks.
In this particular attack, the phone call from someone claiming to work at Apple is a key component to scamming their target. But take a moment to think about this. Why would Apple call you? When has Apple ever called you before on their own when you are going through real, legit technical difficulties? Never! Apple doesn't make outbound calls to users without an Apple customer calling them first and requesting a callback.
As a rule of thumb, don't trust a call you receive claiming to be from a company, even if the number checks out because that can be spoofed. If you're worried about it being legit, hang up on the call you received, go to the company's website, and call their official number back. That way, because you initiatedthe call, you know you are actually connected to the real company's official number. Next, you can ask about your issue and check if they actually called you first. Very often you'll find out that they did not.
With so many scam calls, the best way to be safe is to just not answer a call from a number you're not familiar with. Let them leave a message if it's that important. Then, if they say they are from Apple in the voicemail, you can just directly call Apple's official phone number yourself to check on the supposed issue.
The password reset prompts are, at the same time, annoying and convincing. These are the same official system notifications you receive for legitimate issues.
But don't be fooled. There's a bad actor trying to use these prompts to gain access to your device. Click "Don't Allow" each and every time.
Eventually, the attacker will give up.
As 9to5Mac points out, users can also change the phone number connected to their Apple ID, which will stop these notifications.
This should really be a last resort as this will mess up with your current iPhone settings. For example, you won't be able to use features such as iMessage or FaceTime until the number is set back.
Ideally, it won't come to this. Just don't give these attackers the time of day. If they see that they are wasting their time trying to gain access to your phone, and you aren't falling for the notifications nor answering their phone calls, they will very likely move on to a new target.
Copyright © 2023 Powered by
iPhone password reset attacks are real – how to protect yourself-寸地尺天网
sitemap
文章
61
浏览
1216
获赞
194
Mia Farrow's Twitter account is joyfully bizarre
Stream of consciousness writing made for great 20th century fiction, and now it's coming for 21st ceTrump suggests his supporters could just shoot Clinton if she wins
Donald Trump just might get a visit from the same Secret Service that is charged with protecting himApple Watch Series 10 unveiled: What's new for Apple's thinnest, lightest watch yet?
Opens in a new windowFrank Ocean's visual album brought out a mix of emotions in everyone last night
Well, the day has finally come. Sort of. Frank Ocean's mysterious live stream returned late ThursdayTwitter admits it went too far with '5G causes COVID
Even Twitter admits it was too heavy-handed with its misinformation labels for posts about COVID-19,The best Prime Day Apple Watch deals are now live — check out our top picks
UPDATE: Jul. 16, 2024, 12:15 a.m. EDT This article has been updated with the latest Apple Watch dealAmazon deals of the day: AirPods Max, Dash Tasti
Amazon deals of the day at a glance: OUR TOP PICKBest headphones deal: Get the Sony WH
SAVE 43%: The Sony WH-1000XM4 noise-cancelling headphones are on sale for just $198 at Amazon, discoGoFundMe bans anti
GoFundMe is cracking down on anti-vaxxers.The popular fundraising website says it will no longer allYes, Super Mario is hiding in a mustachioed strawberry
Super Mario has jumped his way over billions of turtles and pipes all to get to this one moment: hisPrime Day 2024: 20+ wireless earbuds deals on Bose, Apple, Sony, and more
Table of ContentsTable of ContentsUPDATE: Jul. 16, 2024, 10:45 a.m. EDT This post has been updated wShop our favorite iPad for reading for just $379.99
SAVE 24%:The Apple iPad Mini is down to $379.99 — its lowest price ever. Shop now on Amazon anHBO Max vs. HBO Go and HBO Now: What makes each service different
There are now three streaming services with HBO's name on them. Wednesday marked the official launchApple's FineWoven cases may get replaced soon
Last year, Apple ditched all of its leather accessories in favor for a new material. Called FineWoveOpen letter to Facebook asks for 'anti
An open letter has been sent to Facebook's Mark Zuckerberg on behalf of a collection of activists ca