Apple is warning users to be wary of unsolicited FaceTime calls amidst a wave of scams impersonating Apple Support, Malwarebytes reports. The scammers inform the user that there’s been fraudulent activity or a technical problem associated with their account, and trick the victim into handing over payment card details, banking credentials or Apple ID logins.
“Nothing in this process requires malware on the device,” Malwarebytes says. “The ‘exploit’ is human trust, backed by familiar names, logos, and a real‑time call that feels inherently more legitimate than a text message. That makes FaceTime a useful delivery channel for social engineering, especially since users are used to seeing Apple notifications and support prompts elsewhere in their digital life.”
Attackers are also using social engineering attacks to target vulnerabilities on unpatched Apple devices.
“From an attacker’s point of view, combining social engineering with vulnerabilities is attractive,” Malwarebytes adds. “Social engineering can steal your usernames and passwords, while a browser‑side exploit can silently execute malicious code when users visit a booby‑trapped site. Chain those attacks together and the attacker can move from app‑level compromise to full system control.”
Apply offers the following advice to help users avoid falling for these attacks.
“Scammers use fake Caller ID info to spoof phone numbers of companies like Apple and often claim that there's suspicious activity on your account or device to get your attention,” the company says. “Or they may use flattery or threats to pressure you into giving them information, money, and even Apple gift cards. If you get an unsolicited or suspicious phone call from someone claiming to be from Apple or Apple Support, just hang up. You can report scam phone calls to the Federal Trade Commission (U.S. only) at reportfraud.ftc.gov or to your local law enforcement agency.”
Malwarebytes has the story: Warning: Scammers are using FaceTime to empty bank accounts
