ECONOMY & WORK
MONEY 101
NEWS
PERSONAL FINANCE
NET WORTH
About Us Contact Us Privacy Policy Terms of Use DMCA Opt-out of personalized ads
© Copyright 2023 Market Realist. Market Realist is a registered trademark. All Rights Reserved. People may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.
MARKETREALIST.COM / ECONOMY & WORK

Think Twice Before Hitting ‘Allow’ on Your iPhone—It Could Be a Scam

The main idea of the scam is to bombard the target's phone with several push notifications in hopes that the target will press the allow option.
PUBLISHED MAR 28, 2024
Cover Image Source: iPhone Home Screen | Unsplash | Photo by Jamie Street
Cover Image Source: iPhone Home Screen | Unsplash | Photo by Jamie Street

A new Apple ID spearphishing campaign that uses "push bombing" or "MFA Bombings" has been targeting several tech professionals over the last few weeks. The core concept of the scam involves bombarding the victim's phone with numerous push notifications, commonly referred to as Multi-Factor Authentication (MFA) notifications. The aim is to induce the victim to inadvertently grant permission by selecting "Allow" instead of "Don't Allow" at least once.

Image Source: Photo by PhotoMIX Company | Pexels
Image Source: Photo by PhotoMIX Company | Pexels

Tech professional Parth Patel recently shared his encounter with a scam on X, recounting the onslaught of push notifications across all his Apple devices. These notifications suspiciously requested permission to reset his Apple ID password, raising red flags. What alarmed him most was that these notifications appeared to be "system-level notifications."

Patel found himself bombarded with over 100 push notifications. After clearing them, he received a call from a fake caller ID posing as Apple's legitimate support line, asking for an OTP sent to his phone. To his dismay, the caller possessed accurate personal details, including his date of birth and current address, obtained from a "people search" site called People Data Labs.



 

A separate report from Krebs on Security highlighted similar encounters involving cryptocurrency hedge fund owners and security industry experts. They too fell victim to the scam, emphasizing that the issue was related to their Apple accounts rather than specific devices.

"If you haven’t already, I’d highly suggest scrubbing yourself from people data aggregators such as People Data Labs, Spokeo, Pimeyes, Social Catfish, and others," Patel wrote in a follow-up post. Currently, there's no way one can avoid this scam apart from hitting "Don't Allow" every time the notification appears. 

Cover Image Source: : An Apple corporate logo | Getty Images | Gary Hershorn
Image Source: An Apple corporate logo | Getty Images | Photo by Gary Hershorn

As of now, there haven't been any public reports of individuals succumbing to the Apple ID password reset scam. However, should you inadvertently grant permission by clicking "allow" on the push notification, it could result in permanent loss of access to your iCloud account. This scenario enables a successful attacker to seize control of your photos, and contacts, and even remotely erase your device.

In a particular case mentioned by AppleInsider, a target received guidance from a senior Apple engineer to activate an Apple Recovery Key as a precautionary measure. This key, comprising a 28-character code, serves as a safeguard against the standard account recovery process, providing an avenue for future account retrieval.



 

This isn't the first time Apple has confronted such an attack. In 2019, a bug dubbed "AirDoS" emerged, enabling attackers to inundate nearby iOS devices with incessant prompts to share a file via AirDrop. The Cupertino giant eventually resolved the issue through its iOS 13.3 update.

Now, with reports circulating about the company's emphasis on integrating AI into their upcoming iOS 18, it raises curiosity about potential advancements in screening and addressing such vulnerabilities. It remains to be seen whether Apple will leverage AI to implement more effective measures for identifying and mitigating these types of security threats.

This strategic shift towards AI in iOS 18 could mark a significant step forward in fortifying Apple's ecosystem against emerging cyber threats.

MORE ON MARKET REALIST
Even the host, Ryan Seacrest admitted that the contestant needed more help to solve the puzzle.
18 hours ago
Steve Harvey is known for his wit and comic timing, but he was caught off guard.
20 hours ago
"Don't get me wrong, I'm human. Naturally, the thought crosses your mind," she said.
2 days ago
The Family Feud host doesn't easily get flustered but it seems like he can't handle flirty responses.
3 days ago
Cars are popular as prizes on several gameshows although contestants don't necessarily drive away in them.
3 days ago
There are multiple theories about cash randomly tucked under wipers, but they are all based on assumptions.
4 days ago
The entrepreneur's business model didn't tempt sharks as much as her oatmeal toppings.
4 days ago
The guest found weird notes on the fridge, TV, washing machine and other spaces in the house.
4 days ago
Ever since he got his six-figure deal on "Shark Tank", there has been no turning back.
5 days ago
While the man was hoping that he had amassed a small fortune, the total calculated by the machine was rather surprising.
6 days ago
After examining the stone cooler, the expert called it a "monumental piece of American stoneware".
7 days ago
Sajak who cut a round to make up time for his farewell speech, made things sweeter for the contestants
Jan 6, 2025
There are plenty of wrong answers but some are completely unbelievable for hosts and audiences alike.
Jan 5, 2025
Viewers labelled the meat used in the steak sandwiches as 'mystery meat'.
Jan 5, 2025
Cuban was backed by two others on the panel while others believed that she deserved to be on the show.
Jan 3, 2025
In a viral video with over 1.3 million views, the creator talked about the dangerous levels of PFAS in smartwatches and fitness trackers.
Jan 3, 2025
This happened when 42-year-old Matt Busbice left his house in a rush one morning after he heard a fire alarm.
Jan 3, 2025
The former teacher says he doesn't need any more degrees to climb up the ladder at the company.
Jan 2, 2025
The 68-year-old won $3.8 million of which he was able to take home close to $2 million after taxes.
Jan 1, 2025
It's not new for Harvey to come across answers which sound bizarre and at times even gross.
Jan 1, 2025