Thursday, 17 April 2025
26.8 C
Singapore
28.2 C
Thailand
21.7 C
Indonesia
28.7 C
Philippines

Beware of MFA bombing: A new phishing scam targeting Apple users

"MFA Bombing" phishing attack targeting Apple users and how to protect yourself from being locked out of your account.

In a concerning trend, numerous Apple enthusiasts have become the unsuspecting victims of a phishing scheme known as “MFA Bombing.” This cunning attack exploits a loophole in Apple’s password reset system, preying on the shared human traits of impatience and oversight.

How does the scam unfold?

Imagine your day is interrupted by a barrage of “Reset Password” notifications on your iPhone, urging you to “Use this iPhone to reset your Apple ID password.” For those caught in the crosshairs of this scam, such alerts have become a frustrating reality. Parth Patel recounted his ordeal on X, detailing how he was bombarded with up to 100 of these notifications.

The attackers’ strategy hinges on weariness and error. They bombard you with notifications in the hope that, in a moment of frustration or distraction, you’ll mistakenly press “Allow” instead of “Don’t Allow.” Falling into this trap grants the scammer the power to reset your Apple ID password, effectively locking you out of your account and devices.

Should this initial ploy fail, the scammer might escalate their tactics by impersonating Apple Support in a phone call. The aim is to coax you into revealing a one-time password, which they can use to gain control over your Apple ID.

The email addresses and phone numbers linked to your Apple ID are all the scammers need to launch this attack. These details are used on Apple’s page for a forgotten Apple ID password, triggering the relentless notifications. The exact method by which these attackers manage to spam users with multiple alerts remains unclear, though it is suspected that a glitch in the system is being exploited.

Steps to take if you’re targeted

There is no definitive solution to this problem currently. If you receive persistent notifications, remain calm and methodically tap “Don’t Allow” on each one.

Moreover, should you receive an unsolicited call claiming to be from Apple Support, remember that Apple does not make outbound calls unless requested by the customer. Notably, Apple would never ask for your one-time password reset codes over the phone.

This ordeal underscores the importance of vigilance in the digital age. By staying informed and cautious, you can protect yourself from falling victim to such schemes.

Hot this week

Trump leaves smartphones and computers out of new tariff hike

Trump exempts phones, laptops, and chips from new tariffs, easing price fears but keeping pressure on China with other duties.

Christensen Advisory secures exclusive APAC rights to InferenceCloud.ai to drive AI adoption in communications

Christensen Advisory partners with InferenceCloud.ai to bring AI-driven communications tools to the APAC region, driving data-backed strategies.

GITEX Asia x Ai Everything Singapore set to unlock Southeast Asia’s US$1 trillion digital economy

GITEX Asia x Ai Everything Singapore 2025 brings the global tech community together to unlock Southeast Asia’s US$1 trillion digital economy.

Chelsea Football Club partners with FPT to drive global digital transformation

Chelsea FC partners with Vietnam’s FPT to boost global digital transformation and enhance fan experiences through advanced technology solutions.

OpenAI may soon require a verified ID to access future AI models

OpenAI may soon require verified ID for access to advanced AI models, aiming to boost safety and prevent misuse of its tools.

Five fun new games arrive on Apple Arcade this May, including a quirky multiplayer title

Apple Arcade will add five fun new games in May, including What The Clash? and updates to Hello Kitty, PGA TOUR, and What The Car?

Garmin launches Varia Vue, its first cycling headlight with 4K camera

Garmin’s new Varia Vue headlight features a 4K camera and smart lighting to boost cycling safety and visibility on the road.

ABA Bank partners with SUSE to enhance digital banking in Cambodia

ABA Bank expands its partnership with SUSE, improving service uptime, reducing costs, and preparing for AI-driven digital banking in Cambodia.

StarHub strengthens enterprise services with new Cisco certifications

StarHub earns Cisco Premier Provider and Webex CC Specialisation, boosting enterprise IT and customer engagement capabilities.

Related Articles

Popular Categories