There's a frightening scam going around where hackers take over your iPhone and won't unlock it until you send money
Getty
Attackers, armed with stolen iCloud passwords, are turning Apple's "Find My iPhone" feature into a way to collect ransom.
It's a new, chiefly Russian scam affecting iPhones and iPads. An attacker uses iCloud's "find device" feature to lock an Apple device remotely, then demands money before he unlocks the device, usually $30 to $50.
But where are the attackers getting the iCloud passwords from?
CSO reports that certain security professionals have been discussing "rumblings of a massive data breach at Apple."
Apple says there is no truth to the rumor and that there has not been a data breach.
Instead, it's likely the attackers are getting passwords through more traditional methods, such as guessing or using account information from leaked databases like LinkedIn.
The scam
Imgur
One day, his phone locked itself, and put itself in "lost mode," which is usually used by an iPhone's owner to secure a device that's been stolen or lost.
Instead, an attacker activated lost mode, and used Apple's lost iPhone message function to display a message in Russian that translates roughly to "to get your password send an e-mail to helpicloud3@gmail.com."
When Kilishek emailed the address, they asked him for 1500 rubles, or about $23, or else they would use Apple's built-in functions to wipe his phone.
A forum thread on Apple's website reports a similar incident from last December and Apple security expert Thomas Reed posted a good explanation of the scam in March.
This kind of attack first surfaced in 2014.
In order for the attacker to activate lost mode, he needed Kilishek's iCloud username and password.
These scams are possible because people reuse passwords across sites, and since several Russian social networks and LinkedIn have been hacked, passwords are floating around.
Reused passwords are probably how a separate hacking group has been able to send messages from the social accounts of major tech executives, such the CEOs of Google and Facebook.
- I spent 2 weeks in India. A highlight was visiting a small mountain town so beautiful it didn't seem real.
- I quit McKinsey after 1.5 years. I was making over $200k but my mental health was shattered.
- Some Tesla factory workers realized they were laid off when security scanned their badges and sent them back on shuttles, sources say
- Stock markets stage strong rebound after 4 days of slump; Sensex rallies 599 pts
- Sustainable Transportation Alternatives
- 10 Foods you should avoid eating when in stress
- 8 Lesser-known places to visit near Nainital
- World Liver Day 2024: 10 Foods that are necessary for a healthy liver