Your Stolen iPhone Calls You Back, in a Voice That Says It's Apple Support. Lost Mode Handed Over Your Number, and the AI on the Line Costs Less Per Call Than the Thief's Bus Fare.
- Patrick Duggan
- 5 minutes ago
- 5 min read
Somebody steals your iPhone. It locks. Activation Lock means the device is worth roughly its weight in aluminium, because it cannot be paired to a new owner without your Apple ID.
So you do the correct thing. You put it in Lost Mode, which displays a message and a contact number, so that an honest finder can get it back to you.
You have just told the thief how to reach you. And within hours a voice with an Apple Support script will call that number, in English, Spanish or Portuguese, and talk you through reading your passcode aloud.
The voice is a rented commercial AI agent. Her name, in the transcripts, is Alice.
What the operation actually is
AnonyMousKIT is a phishing-as-a-service platform, running since early 2024, and it has exactly one commercial purpose: getting the passcode and Apple ID off a stolen device so that Activation Lock can be removed and the phone can be resold as clean stock.
It is not a hacking operation that happens to touch phones. It is the software layer of a physical theft economy, and the scale tells you that plainly: 506 domains, and 168 storefront brands operating as resellers on top of the platform. Somebody built a channel programme for stolen iPhones.
The research is SOCRadar's, reported 24–26 August 2026, and the recovered artefacts are what make it worth your attention rather than another PhaaS write-up: 200 calls placed to victims between August 2025 and May 2026, and 55 distinct interaction transcripts handled by a voice AI agent operating under five personas.
The seam: a good feature that produces a targeting list
Lost Mode is not a vulnerability. It is a well-designed recovery feature doing precisely what it was built to do — put a way of contacting you on the screen of a device you no longer hold, so a decent stranger can return it.
The problem is that the stranger holding your phone is usually not the decent one, and the feature cannot tell the difference. What it produces, from the thief's side of the glass, is a verified phone number attached to a person who is known to have just lost a phone and is known to want it back. In sales language that is a qualified lead with intent. In social-engineering language it is the two things that normally cost the most: a working contact and a plausible pretext.
We keep finding this shape and it deserves its name — the control held, the handoff was unassigned. Apple built recovery. Apple built Activation Lock. Both work. Nobody owns the seam where the recovery feature's output becomes the attacker's input, because from inside either system nothing has failed.
Five channels, and only one of them is new
The platform runs five fully automated pipelines at the same target: email, SMS, WhatsApp, pre-recorded voice calls, and a conversational AI agent that phones the victim and holds a conversation.
Four of those are ordinary. The fifth is the story, and not for the reason people usually reach for.
The AI is not impressive. It is a rented commercial voice product, scripted as "Alice from Apple Support," running in three languages. Nothing about it is bespoke or advanced. What matters is the unit economics.
Live phone social engineering has always been the highest-conversion channel and the most expensive one, because it needed a fluent human being on a call, one victim at a time, in the victim's language, sounding calm and institutional. That cost is what kept voice phishing rare and targeted.
That cost is now a subscription. Three languages, five personas, no fatigue, no accent mismatch, no wage. That is what turns a phone-theft ring into a platform with 168 resellers — not cleverness, affordability.
If you want the checkable version rather than the adjective: 200 calls, 55 distinct transcripts, 5 personas, 3 languages, dated August 2025 to May 2026. That is demonstrated evolution with a date range on it, and it is a great deal more useful than calling anyone sophisticated.
The ask, in order, and why the order matters
The pages and calls request three things in sequence:
First, the device passcode — the 4- or 6-digit code, read aloud on the call. Second, the Apple ID credentials, via a phishing page the caller walks you to. Third, a live two-factor code, captured in real time while the operator uses it.
Notice that the passcode comes first, before the account credentials. That is because the passcode is not the prize. Activation Lock removal is the prize, and that is what pays the 168 storefronts. The Apple ID theft, the iCloud backups and the Keychain credentials are a second revenue stream harvested on the same call — your photos, your saved passwords and your accounts, monetised separately from the hardware.
So the person who loses a phone loses it twice, and the second loss is the one they will not notice for weeks.
What to actually tell people
This one is worth passing to non-technical people in your life, because the victims here are not enterprises with a SOC. They are whoever just had a phone taken outside a bar.
Apple will not phone you about a lost device, and nobody legitimate will ever ask for your device passcode. Not support, not a carrier, not a recovery service. There is no scenario in which reading those digits to a caller is the right move.
Notifications about a found device appear on your other Apple devices and in Find My. They do not arrive as a WhatsApp message, an SMS with a link, or a phone call from a warm voice. If you get contacted out of the blue, the answer is to go and look in Find My yourself, on a device you are already holding.
The call sounding human is no longer evidence of anything. That was a reasonable heuristic for twenty years and it stopped being one this year. Fluency is now a rented commodity.
If you have already given a passcode away: change the Apple ID password from another device, revoke trusted devices, check for unknown devices on the account, and change any password stored in Keychain that matters — starting with email and banking, because those are the ones that unlock everything else.
Sources
AnonyMousKIT phishing-as-a-service, active since early 2024, targeting owners of recently lost or stolen Apple devices for passcode and Apple ID capture in order to remove Activation Lock. Research by SOCRadar; reported by BleepingComputer, The Hacker News, Help Net Security and CyberInsider, 24–26 August 2026. Figures — 506 domains, 168 reseller storefronts, five automated channel pipelines, 200 recovered calls between August 2025 and May 2026, 55 distinct transcripts, five voice personas across English, Spanish and Portuguese — are SOCRadar's.
Capped at 95 percent, and the cap is doing real work on this one: we hold no first-party observation of this campaign. No AnonyMousKIT-attributed indicators in our feed, no domains of our own to publish, and we have not independently verified the call counts or the domain total. This is other people's research, credited, and we are reporting it because the population it targets is exactly the population that reads no security press at all.
The useful thing you can do today costs nothing and is not technical: tell someone who has ever lost a phone that Apple will not ring them about it, and that nobody legitimate asks for a passcode. That sentence is worth more to them than this entire post. Rate this post below.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=your-stolen-iphone-calls-you-back-in-a-voice-that-says-it-s-apple-support-lost-mode-handed-over-yo




Comments