Voice AI Phishing Service Tricks iPhone Owners Into Giving Up Passcodes

Security researchers at SOCRadar uncover a phishing-as-a-service platform called AnonyMousKIT that uses AI voice agents to trick iPhone owners into revealing their device passcodes. The illegal service, active since early 2024, automates the theft of codes needed to unlock stolen Apple devices and bypass the Activation Lock feature. It powers a broad criminal ecosystem that sells stolen iPhones, harvests Apple IDs, and accesses iCloud backups and Keychain credentials.

The platform connects to 506 domains and supports 168 storefront brands acting as resellers. SOCRadar recovers records of 200 calls made to victims between August 2025 and May 2026, handled by a voice AI agent operating under five distinct personas. Each call costs the operator only about $0.10, and 90% of the calls target victims in Brazil. The researchers gain insight into the operation by exploiting the operator's use of bare relative paths, which expose internal data.

The scheme exploits Apple's Activation Lock, which keeps a stolen iPhone tied to its owner's account even after a factory reset. AnonyMousKIT pulls contact details from the device's Lost Mode and impersonates Apple through email, SMS, WhatsApp, or phone calls, citing the correct model and IMEI to appear legitimate. Victims are directed to fake Find My pages where they enter their passcode, Apple Account credentials, and two-factor authentication code, allowing criminals to unlock the device and significantly increase its resale value.

Read More at the original source →