Thursday, 13 March 2025
29.4 C
Singapore
35.7 C
Thailand
22 C
Indonesia
28.2 C
Philippines

Beware of MFA bombing: A new phishing scam targeting Apple users

"MFA Bombing" phishing attack targeting Apple users and how to protect yourself from being locked out of your account.

In a concerning trend, numerous Apple enthusiasts have become the unsuspecting victims of a phishing scheme known as “MFA Bombing.” This cunning attack exploits a loophole in Apple’s password reset system, preying on the shared human traits of impatience and oversight.

How does the scam unfold?

Imagine your day is interrupted by a barrage of “Reset Password” notifications on your iPhone, urging you to “Use this iPhone to reset your Apple ID password.” For those caught in the crosshairs of this scam, such alerts have become a frustrating reality. Parth Patel recounted his ordeal on X, detailing how he was bombarded with up to 100 of these notifications.

The attackers’ strategy hinges on weariness and error. They bombard you with notifications in the hope that, in a moment of frustration or distraction, you’ll mistakenly press “Allow” instead of “Don’t Allow.” Falling into this trap grants the scammer the power to reset your Apple ID password, effectively locking you out of your account and devices.

Should this initial ploy fail, the scammer might escalate their tactics by impersonating Apple Support in a phone call. The aim is to coax you into revealing a one-time password, which they can use to gain control over your Apple ID.

The email addresses and phone numbers linked to your Apple ID are all the scammers need to launch this attack. These details are used on Apple’s page for a forgotten Apple ID password, triggering the relentless notifications. The exact method by which these attackers manage to spam users with multiple alerts remains unclear, though it is suspected that a glitch in the system is being exploited.

Steps to take if you’re targeted

There is no definitive solution to this problem currently. If you receive persistent notifications, remain calm and methodically tap “Don’t Allow” on each one.

Moreover, should you receive an unsolicited call claiming to be from Apple Support, remember that Apple does not make outbound calls unless requested by the customer. Notably, Apple would never ask for your one-time password reset codes over the phone.

This ordeal underscores the importance of vigilance in the digital age. By staying informed and cautious, you can protect yourself from falling victim to such schemes.

Hot this week

StarHubโ€™s HER Hub supports women entrepreneurs with networking and mentorship

StarHubโ€™s HER Hub connects women entrepreneurs with industry leaders, providing mentorship, networking opportunities, and digital solutions for growth.

Microsoft expands AI Pinnacle Program with new industry partnerships in Singapore

Microsoft expands its AI Pinnacle Program in Singapore with new industry partnerships, AI research collaborations, and initiatives to upskill local talent.

Google launches free AI prompting course to boost workplace efficiency

Google launches a free AI prompting course on Coursera to help professionals use AI effectively and improve workplace efficiency. Available in Singapore.

Microsoft intensifies AI race to rival OpenAI

Microsoft is increasing its AI efforts, developing its models and testing alternatives to OpenAI technology for products like Copilot.

ASUS launches AMD Radeon RX 9070 and 9070 XT graphics cards with advanced cooling and AI-powered features

ASUS launches the Radeon RX 9070 and 9070 XT graphics cards, featuring AI-powered super resolution, improved cooling, and durable designs.

Singapore Airlines and Scoot to ban in-flight power bank charging from April 1

Singapore Airlines and Scoot will ban in-flight power bank use from April 1 due to safety concerns over battery fires. Check their new policies here.

Sandmarc launches 10x optical zoom lens for iPhones, leaving Android users amused

Sandmarc launches a 10x optical zoom lens for iPhones, enhancing long-range photography while amusing Android users already using this feature.

Lego unveils 1,972-piece Mario Kart set with posable arms and head

Lego unveils a 1,972-piece Mario Kart set featuring a posable Mario figure and display stand, which will be available on May 15 for US$249.90.

Trump vows to classify violence against Tesla as domestic terrorism

Trump vows to classify attacks on Tesla dealerships as domestic terrorism, sparking debate over protests, government cuts, and Muskโ€™s influence.

Related Articles