{"id":598,"date":"2026-03-09T15:11:29","date_gmt":"2026-03-09T15:11:29","guid":{"rendered":"https:\/\/xn--mnchen-3ya.xyz\/index.php\/2026\/03\/09\/matt-gone-almost-phishin\/"},"modified":"2026-03-09T15:11:29","modified_gmt":"2026-03-09T15:11:29","slug":"matt-gone-almost-phishin","status":"publish","type":"post","link":"https:\/\/xn--mnchen-3ya.xyz\/index.php\/2026\/03\/09\/matt-gone-almost-phishin\/","title":{"rendered":"Matt: Gone (Almost) Phishin\u2019"},"content":{"rendered":"<p class=\"wp-block-paragraph\">This is a little embarrassing to share, but I\u2019d rather someone else be able to spot a dangerous scam before they fall for it. So, here goes.<\/p>\n<p class=\"wp-block-paragraph\">One evening last month, my Apple Watch, iPhone, and Mac all lit up with a message prompting me to reset my password<em>.<\/em> This came out of nowhere; I hadn\u2019t done anything to elicit it. I even had <a href=\"https:\/\/support.apple.com\/en-us\/105120\">Lockdown Mode<\/a> running on all my devices. It didn\u2019t matter. Someone was spamming Apple\u2019s legitimate password reset flow against my account\u2014a technique<a href=\"https:\/\/krebsonsecurity.com\/2024\/03\/recent-mfa-bombing-attacks-targeting-apple-users\/\"> Krebs documented back in 2024<\/a>. I dismissed the prompts, but the stage was set.<\/p>\n<p class=\"wp-block-paragraph\">What made the attack impressive was the next move: The scammers actually contacted Apple Support themselves, pretending to be me, and opened a real case claiming I\u2019d lost my phone and needed to update my number. That generated a real case ID, and triggered real Apple emails to my inbox,<em> properly signed<\/em>, from Apple\u2019s actual servers. These were legitimate; no filter on earth could have caught them.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-151420\" height=\"587\" src=\"https:\/\/i0.wp.com\/ma.tt\/files\/2026\/03\/CleanShot-2026-02-07-at-19.36.31%402x-1-1024x996.png?resize=604%2C587&amp;quality=80&amp;ssl=1\" width=\"604\" \/><\/figure>\n<p class=\"wp-block-paragraph\">Then \u201cAlexander from Apple Support\u201d called. He was calm, knowledgeable, and <em>careful<\/em>. His first moves were solid security advice: check your account, verify nothing\u2019s changed, consider updating your password. He was so good that I actually thanked him for being excellent at his job.<\/p>\n<p class=\"wp-block-paragraph\">That, of course, was when he moved into the next phase of the attack.<\/p>\n<p class=\"wp-block-paragraph\">He texted me a link to review and cancel the \u201cpending request.\u201d The site, audit-apple.com, was a pixel-perfect Apple replica, and displayed the exact case ID from the real emails I\u2019d just received. There was even a fake chat transcript of the scammers\u2019 actual conversation with Apple, presented back to me as evidence of the attack against my account. At the bottom of the page was a Sign in with Apple button that he told me to use.<\/p>\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-151411\" height=\"395\" src=\"https:\/\/i0.wp.com\/ma.tt\/files\/2026\/03\/CleanShot-2026-02-07-at-18.14.37%402x-1024x670.png?resize=604%2C395&amp;quality=80&amp;ssl=1\" width=\"604\" \/><\/figure>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" class=\"wp-image-151412\" height=\"418\" src=\"https:\/\/i0.wp.com\/ma.tt\/files\/2026\/03\/CleanShot-2026-02-07-at-18.08.36%402x-1024x708.png?resize=604%2C418&amp;quality=80&amp;ssl=1\" width=\"604\" \/><\/figure>\n<\/figure>\n<p class=\"wp-block-paragraph\">I started poking at the page and noticed I could enter any case ID and get the same result. Nothing was being validated. It was all theater.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis is really good,\u201d I told Alexander. \u201cThis is obviously phishing. So tell me about the scam.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Silence. *Click*.<\/p>\n<p class=\"wp-block-paragraph\">Once I\u2019d suspected what was happening, I\u2019d started recording the call, so I was able to save a good chunk of it, which Jamie Marsland used to make a video about the encounter. You can hear for yourself exactly how convincing \u201cAlexander\u201d was.<\/p>\n<p class=\"wp-block-paragraph\">So let my almost-disaster help you avoid your own. Remember these rules.<\/p>\n<ul class=\"wp-block-list\">\n<li><strong>Don\u2019t approve any password-reset prompts<\/strong>\u2014those are the first part of the attack. Do not pass Go, just head directly to your Apple ID settings. <\/li>\n<li><strong>Apple will <\/strong><strong><em>never<\/em><\/strong><strong> call you first.<\/strong> <\/li>\n<li>When you get an email from Apple\u2014or, really, anyone telling you to complete a digital security measure\u2014<strong>check the URL<\/strong> they\u2019re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">After all, the best protection is knowing what this looks like before it happens.<\/p>\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\">\n<div class=\"wp-block-embed__wrapper\">\n<\/div>\n<\/figure>","protected":false},"excerpt":{"rendered":"<p>This is a little embarrassing to share, but I\u2019d rather someone else be able to spot a dangerous scam before they fall for it. So, here goes. One evening last month, my Apple Watch, iPhone, and Mac all lit up with a message prompting me to reset my password. This came out of nowhere; I [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":599,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-598","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"_links":{"self":[{"href":"https:\/\/xn--mnchen-3ya.xyz\/index.php\/wp-json\/wp\/v2\/posts\/598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xn--mnchen-3ya.xyz\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xn--mnchen-3ya.xyz\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xn--mnchen-3ya.xyz\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/xn--mnchen-3ya.xyz\/index.php\/wp-json\/wp\/v2\/comments?post=598"}],"version-history":[{"count":0,"href":"https:\/\/xn--mnchen-3ya.xyz\/index.php\/wp-json\/wp\/v2\/posts\/598\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xn--mnchen-3ya.xyz\/index.php\/wp-json\/wp\/v2\/media\/599"}],"wp:attachment":[{"href":"https:\/\/xn--mnchen-3ya.xyz\/index.php\/wp-json\/wp\/v2\/media?parent=598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xn--mnchen-3ya.xyz\/index.php\/wp-json\/wp\/v2\/categories?post=598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xn--mnchen-3ya.xyz\/index.php\/wp-json\/wp\/v2\/tags?post=598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}