A newly exposed phishing-as-a-service platform called AnonyMousKIT is automating the theft of passcodes from stolen iPhones, allowing criminals to bypass Apple’s Activation Lock and resell the devices at a higher value. The service, active since early 2024, also harvests Apple IDs, accesses iCloud backups, and extracts Keychain credentials, according to researchers at threat intelligence platform SOCRadar. The illegal operation has been tied to 506 domains and supports 168 storefront brands acting as resellers for stolen phones.

SOCRadar leveraged the platform operator’s sloppy use of bare relative paths to map out the service’s infrastructure, operators, and workflow. The researchers recovered records of 200 calls made to victims between August 2025 and May 2026, using 55 distinct interaction transcripts handled by a voice AI agent operating under five personas. The calls cost the operator about $0.10 per attempt, and 90 percent were directed at phone owners in Brazil. The research also found that a small percentage of the platform’s phishing emails were sent to government and corporate organizations.

Apple’s Activation Lock, which automatically turns on when Find My is enabled, ties a device to the owner’s Apple Account. Even after a factory reset, a stolen iPhone remains locked and requires the original owner’s authorization code during setup. Because of that safeguard, many stolen phones are normally sold for parts, but unlocking them dramatically boosts their resale value, especially if the attacker can also access the owner’s sensitive data.

AnonyMousKIT gathers contact details from a stolen device’s Lost Mode feature and contacts the owner via email, SMS, WhatsApp, or a phone call. These messages impersonate Apple and claim the missing device has been found, including the correct model and IMEI number to appear legitimate. The victim is then directed to a fake Find My or Apple page where they are asked to enter their device passcode, Apple Account credentials, and two-factor authentication code.

In some cases documented by SOCRadar, the AI agent adopts an “Alice from Apple Support” persona and tells victims that someone brought the locked phone to an Apple store, where it was retained. The agent then asks the victim to confirm ownership by dictating the passcode, after which the attacker redirects them to the phishing page. Once the code is captured, the criminals can access personal data, factory reset the device, and remove it from Find My before selling it.

A compromised Apple ID can expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued iPhones, SOCRadar warns. The campaigns behind AnonyMousKIT had a global footprint, with higher concentrations in South Africa, Indonesia, Italy, India, Kenya, and Brazil. For US users, the threat underscores how stolen-device schemes are merging with AI-driven social engineering to target the same credentials that protect corporate networks and personal accounts.

More AI news from TechManNews.