Your stolen iPhone can now call you back – pretending to be Apple Support
Hackers just built an entire criminal ecosystem that can trick you into unlocking your device.

Image by Tada Images | Shutterstock
- Hackers are using fake Apple Support calls and real stolen-device data to steal iPhone passcodes.
- One phishing platform was tied to 506 domains and 168 different storefronts.
- AI voice calls cost just pennies, making stolen-iPhone scams cheap enough to run at massive scale.
- The operation is still active, with dozens of backends and domains continuing to target victims.
Someone stole your iPhone? Hackers have now built an entire "powered by AI" criminal ecosystem – all designed to trick Apple owners into unlocking their phones.
AI phishing is being taken to a whole new level – and it’s targeting iPhone owners who have lost or had their phones stolen, according to new research published Monday by SOCRadar.
Crafty hackers have built an intricate phishing platform, complete with an AI agent named Alice, who attempts to trick former owners into giving up their iPhone passcodes – all so thieves can unlock the stolen phones and resell/trade them on third-party marketplaces like Telegram.
What's more, the AI-powered Phishing-as-a-Service (PhaaS) kit – dubbed AnonyMousKIT – aims to steal victims’ passcodes by repeatedly targeting them across five separate and completely automated attack "channel pipelines."
These include email, SMS, WhatsApp, recorded voice calls, and conversational AI agents capable of calling the target themselves, the SOCRadar Threat Research Unit (STRU) says.
Your stolen iPhone has been "found"
For those unfamiliar, an iPhone's passcode unlocks the device, while Apple's Activation Lock ties it to its owner's Apple ID, essentially preventing anyone from removing the owner's account from the device.
Hackers need to get past those protections to resell the device.
To make the phish as convincing as possible, the attackers start by profiling the iPhone itself, gathering data points such as the actual Apple model, its associated number, and even incorporating its live Find My status.
All the gathered details are then uploaded into the phishing kit, creating a profile the AI uses to lure that specific iPhone owner using the attack channels mentioned above.
One email uncovered by researchers tells the victim that their iPhone 15 Plus was detected near another Apple device in Johannesburg, actually providing a "View Location" button.
Another shows a Telegram message simply telling the owner: "Your lost iPhone 14 has been found online and located."
SOCRadar said it found 691 email attempts on AnonyMousKIT alone, and more than 6,000 across related versions of the kit, including those targeting government, education, and corporate email addresses.
Researchers say they also uncovered thousands of WhatsApp attempts and 200 AI voice calls recorded in exposed logs.
Roughly 90% of the 200 recovered AI calls targeted Brazil, while two calls went to Chile, one to the US or Canada, and 18 had unresolved prefixes.
Meet "Alice" from Apple Support
AnonyMousKIT takes the scam a step further by renting commercial conversational AI agents that actually call victims and pretend to work for Apple.
And those multiple AI personas – including "Alice" from Apple Support – have been quite busy.
SOCRadar says along with the 200 AI call records, it recovered five separate AI personas and 55 transcripts – including the agents' underlying prompts – directly from the platform.
The AI known as Alice is programmed to confirm ownership of the stolen device, tell the victim someone attempted to remove its Activation Lock, ask for the phone's four- or six-digit passcode, even a 2FA code, and eventually direct the owner to a phishing link.
In one recovered conversation, the AI tells a victim that someone brought their stolen iPhone 16 Pro Max into an Apple Store, with employees holding the device after discovering it was in Lost Mode.
The still-active platform, which appears to have first launched sometime last September, shows its AI personas were actually created months earlier in March 2025.
Another fun fact: each AI agent call set back the developers a mere 10 cents, with the entire batch of 200 calls costing just $19.24.
And, in what could be considered a comical spin, it appears the developers buried a cybersecurity Easter egg in the operation by choosing the name "Alice" for the AI agent.
"Alice" and "Bob" have long been used as fictional characters to explain encryption and network communications instead of generic mathematical variables like "A" and "B" – alongside "Eve," the eavesdropper attempting to intercept their exchange.
Phishing by subscription
AnonyMousKIT is best understood not as a phishing kit but as a small software business with a criminal customer base,the SOCRadar Threat Research Unit (STRU) said.
Just like a subscription service, criminals can upload the iPhone profile once to the platform, and then pay to target the victim across the different channels until one works.
The platform itself looks just like legitimate software – with a dashboard tracking orders, balances, successful attempts, blocked attempts, links, and customer activity. Criminals buy credits to use each individual phishing service.
SOCRadar noted it was only able to examine so many parts of the operation because the developers apparently made a basic coding mistake that exposed the platform's entire backend.
They say the exposed data shows a layered criminal supply chain involving a seller, developer, buyers, storefront operators, and hundreds of WhatsApp accounts.
Researchers also found 30 distinct backend installations across 42 domains using the same core codebase.
Even more interesting, SOCRadar says it observed three different storefronts launch on April 10th, 2026 – at the exact same second and using the same Gmail accounts – evidence pointing to one buyer operating all three brands.
What iPhone owners should watch for
SOCRadar reminds iPhone users that a compromised Apple ID could potentially expose iCloud backups, Keychain credentials, and work-related information stored within the victim's Apple ecosystem.
They also say if you've lost your phone or had it stolen, you should watch out for unexpected emails, texts, WhatsApp messages, or calls claiming the device has suddenly been located and directing you to a link.
And of course, “no legitimate support entity will request a device passcode or 2FA code by phone,” SOCRadar says.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.