When 'Apple Support' Calls, the Voice on the Line Might Be AI

Key takeaways
- SOCRadar linked the fake 'Apple Support' calls to AnonyMousKIT, a phishing-as-a-service operation that uses an AI voice agent to ask victims for passcodes or 2FA codes, remove Activation Lock, and resell stolen iPhones.
- The tactic mirrors real-world help-desk social engineering: in 2023 Scattered Spider used LinkedIn data to impersonate an MGM Resorts employee to the IT help desk, and MGM later reported a $100 million hit to third-quarter results from the breach; CISA/FBI advisory AA23-320A warns attackers pose as IT/help desk staff to steal one-time codes or reset credentials.
- Deloitte’s Center for Financial Services projects US generative AI-enabled fraud losses will rise from $12.3 billion in 2023 to $40 billion by 2027, while Adaptive Security says deepfake-enabled attacks in the US grew 17-fold over a similar period.
- The article’s core risk shift is scale: an AI voice agent can handle thousands of patient, convincing calls simultaneously, making a caller’s voice alone no longer reliable proof of identity.
- For individuals, the recommended defense is to hang up and call back using a number from the company’s official website; Hany Farid of UC Berkeley also recommends household safe words, calling them 'an analog solution to a digital problem.'
- For security teams, the article recommends callback verification policies for any password or MFA reset, phishing-resistant MFA such as FIDO/WebAuthn or PKI-based authentication per CISA guidance, and live AI-voice simulations so employees practice spotting convincing phone scams before attackers test them.
A woman loses her iPhone on a Tuesday. Two days later, the phone rings. The caller ID reads Apple Support. The voice on the line sounds patient and professional, the way a good customer service call is supposed to sound. The caller says they need her passcode to verify her identity and lift the Activation Lock on the missing device. She reads it off. Within minutes, the phone is unlocked, wiped, and headed for a resale market.
That call never touched an Apple employee. Researchers at SOCRadar traced it to a phishing-as-a-service operation called AnonyMousKIT, which rents scammers an AI voice agent built to make exactly this kind of call at scale. The agent poses as Apple Support, asks for a passcode or a two-factor code, and uses it to strip the phone's Activation Lock so the device can be resold.
Security teams have seen this basic move before. In 2023, a group known as Scattered Spider found an MGM Resorts employee’s information on LinkedIn, called the company’s own IT help desk, impersonated that employee, and talked their way into a credential reset. MGM later reported a $100 million hit to its third-quarter results tied to the resulting breach. CISA and the FBI took the pattern seriously enough to publish a standing joint advisory, AA23-320A, describing how attackers “pose as company IT and/or help desk staff” to get employees, or help desk staff themselves, to hand over one-time codes or reset passwords and MFA tokens. The Apple Support scam runs that same play with one new variable: the caller isn’t a person.
The Trend Behind the Story
Two numbers frame the scale of this shift. Deloitte’s Center for Financial Services projects that generative AI-enabled fraud losses in the United States will climb from $12.3 billion in 2023 to $40 billion by 2027. Separately, Adaptive Security’s own tracking has found deepfake-enabled attacks in the US growing seventeen-fold over roughly the same period, with more than half of security leaders now reporting they’ve personally encountered one, up from close to one in ten less than two years ago.
Both numbers point at the same underlying change: scale. A single AI voice agent can hold thousands of conversations at once, each one patient, each one willing to repeat the same request as many times as it takes. A human scammer works down a call list one name at a time. This kind of tool works the whole list simultaneously, whether the target is a device owner or a company’s own help desk.
Most support calls remain exactly what they claim to be. A caller's voice, on its own, is no longer sufficient proof of who is on the line. That's a specific, fixable gap. The fix is a habit around any request for a code or a reset, and it's a small one to build.
What Individuals Can Do
Hany Farid, a professor at the University of California, Berkeley, who studies digital forensics, recommends a household safe word for calls that claim to involve a family member in distress. “I love safety words,” Farid said in an interview with Scientific American. “My wife and I have one. It's an analog solution to a digital problem.” His broader advice: “Know that you’re going to get a call at two in the morning from your son, who’s saying something terrifying, so hang up, call him back.”
The same habit applies to the Apple Support scenario. Hang up. Call the company back using a number pulled from its official website instead of the one that just called in. Support lines don’t call out of nowhere asking for a passcode or a two-factor code. A request that leans hard on urgency is exactly the moment to slow down.
What Security Teams Can Do
The enterprise version of “hang up, call back” is a callback verification policy: no password or MFA reset proceeds from an inbound call alone, regardless of how convincing or urgent it sounds. CISA’s own guidance on this attack pattern points to phishing-resistant MFA, specifically FIDO/WebAuthn or PKI-based authentication, because it resists the push-bombing and SIM-swap techniques that voice-based social engineering often leads into.
Training matters here too. The version that holds up is one employees have practiced, delivered as a live scenario instead of a slide deck skimmed once a year. Some awareness platforms, Adaptive included, now run these same AI-generated voice scenarios against help desk staff and general employees as simulations, so a team’s response gets measured before an attacker measures it for them. An employee who has already handled a convincing, too-smooth phone call recognizes the shape of it immediately the next time it shows up on the job.
The Good News
The tools driving this new generation of scams are the same tools that can catch them. AI can flag an anomalous reset request as fast as it can generate a convincing call. Training can be practiced as precisely as an attack can be personalized. Trust in support lines can stay intact. It just needs a second input alongside the voice on the phone: a callback, a code word, a verified number.
A callback policy at a help desk and a shared phrase between family members are the same idea at two different scales: don’t let a single phone call be the only thing standing between a request and a reset. That’s a habit worth building well before the call comes in.
Get started with Adaptive Security