New phishing attack tries to steal Apple IDs from users

phising

Careful. As Pedro Rodas notifies us, our colleague from currentgadget.com has received an email in which he is notified that his iPhone has been blocked because someone has tried to steal it, inviting him to modify his data on the "My Apple" website ID». The problem is that it is a attack of what is known as Phishing, a practice in which a malicious user tries to impersonate a person or organization to get our credentials to misuse them.

As you can see, they have created a website very similar to Apple's, but not on the fake website we can click on the tabs from the store, such as the one on Mac, iPhone or Watch, tabs that do not appear in the same order either. In addition, in the mail, of which you have a screenshot below, they ask for our "iPhone ID", something that Apple would never do because it does not exist.

mail-pishing

As Pedro points out, the mail has reached him in English to a Spanish-speaking user, something Apple would never do either. There is no point in asking me to validate my account in a language I don't understand. And, worst of all and as usually happens in this type of forgeries, there are spelling mistakes, as is "apologize" when the correct word is "apologize" or the absence of words like "here TO validate", not to mention that iTunes has the lowercase T.

If we click on the link in the email, it sends us to iTunes Connect, a service that is supposed to be for developers and, logically, the text of the URL is not in green, as it is on the original Apple website, of which you have a screenshot below.

web-apple-id

If we put our credentials, that I wanted to send a "loving" message to the creator of the website (in the form of a false email and password), it sends us to a website so that we can put all our data. No matter the data we put in, we will never get any error, not even when putting letters in the number of our card. At the end we will see a message that everything is correct and it will take us to apple.com, not to the website of our country.

web-phishing

You have to be very careful with these types of requests. As we have explained, if we ever had a problem like the one that we are supposed to be invited to solve in this phishing attack, Apple would send us an email in our language, without spelling mistakes and with a link to a short website, never like the link in this email, which will appear green in Safari. Of course, there is no iPhone ID, if not a general Apple ID, which will serve us for our iPhone, iPod, iPad, Mac, Apple TV and any device that has a bitten apple as a logo.


You are interested in:
According to Apple, it is the most effective company in the world in security
Follow us on Google News

Leave a Comment

Your email address will not be published. Required fields are marked with *

*

*

  1. Responsible for the data: AB Internet Networks 2008 SL
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.

  1.   Maria said

    There is no need to put apologize since it can be written as you want, with z O s. Before saying that this is a fault, find out.
    A greeting.

    1.    Paul Aparicio said

      Hello Maria. I did it and in my dictionary it puts it with Z (Apple's, I have looked at it again). It does not put anything that with S is correct. I cannot do anything if my dictionary does not add an alternative to S and I am not born in any country where it is used like that.

      A greeting.

  2.   Paul said

    Well, according to the RAE, it is with Z in all its verb forms, and some with C, but with S, it will be that no ... .. therefore, before wanting to correct someone, perhaps get better information.
    regards

    1.    altergeek said

      the rae of spain says how to write in english? Well, now they broke me, well I don't care. It is apologize, there is NO other.

  3.   Edu28 said

    Hello Mate, a question, if the ID is requested on an iPhone, is it correct to put it?

    1.    Paul Aparicio said

      Hello Edu28. You NEVER have to enter the data if you notice something strange. In this case it has asked for the iPhone ID, I don't know if you ask for that, but the iPhone ID does not exist. On the iPhone you use the Apple ID, Apple ID or Apple ID, but you do not use the iPhone ID because it does not exist. For example, you can have a nickname that you use with friends, but nowhere will they ask for your nickname to use it. It will ask for your real name (or the one you used to register).

      A greeting.

  4.   JMN said

    Well… I am writing you a small review that you have not commented on.

    This bridge has opened my car and I have been stolen Ipad air WIFI, immediately I activated the block with the "search for lost device", I went to file a complaint and hope if I was lucky and it connected to an open wifi and it gave me its location since the device had activated blocking by number and therefore it is impossible to do anything with it.

    The point is that today at 23.58:XNUMX p.m. I get an SMS with the title FIND MY PHONE: Dear User: Lost Device has been found. Last Location: http://tinyurl.com/od63egt ICloud support. (If you want a screenshot, I can provide it to you ADMIN)

    Imagine my face when I saw the surprise that they are trying to direct me to a fake Appel page to steal my ID and thus be able to unlock my device.

    Obviously the message "with affection" has been one of the good ones ... and indeed ... it does not matter what you write since it links you to the official ICLOUD page so that you can re-enter the data, only that on the way they have charged the toll .

    I have been doing a bit of checking on the internet and I have not found anything about this modus operandi.

    It would be very good if you published it as an example so that those of us who have suffered the scourge of the theft of our device do not have to give away our IDs to do business with it.

    A greeting.

    1.    Hec said

      What you mention is something very used here in Mexico with stolen Apple devices. There are groups on Facebook that among their many "services" they offer, is that of unlocking iCloud from "lost" computers. The only requirement they ask is that they have the client's message with their cell phone number and email, it seems that what they do is send you the SMS and they also try to hack your email account to be able to access the data of your Apple account and so you can remove the iCloud lock. They are cursed.

  5.   alvaroaguilar852546615 said

    I got this:

    Dear Customer,
    Your account ID has been used to purchase "Hello" by Adele ($ 3,99) from the iTunes Store in a
    device that we do not have associated with you.
    If you made this transaction, you can discard this email.
    If you did not complete this transaction, please go to http: /apple.com/support/cancel-84039165 to cancel the transaction.
    Manzana !,
    Itunes

    I put my account and my password… fool! ..