Phishing Campaign Attempts to Bypass iOS Protections

Stu Sjouwerman | Jan 20, 2025

SMS Messaging Smishing ScamAn SMS phishing (smishing) campaign is attempting to trick Apple device users into disabling measures designed to protect them against malicious links, BleepingComputer reports.

“Apple iMessage automatically disables links in messages received from unknown senders, whether that be an email address or phone number,” BleepingComputer explains.

“However, Apple told BleepingComputer that if a user replies to that message or adds the sender to their contact list, the links will be enabled....Over the past couple of months, BleepingComputer has seen a surge in smishing attacks that attempt to trick users into replying to a text so that links are enabled again.”

The messages purport to be routine text notifications, such as package delivery updates or unpaid road toll notices. Unlike past smishing attempts, however, the messages contain instructing users, “Please reply Y, then exit the text message, reopen the text message activation link, or copy the link to Safari browser to open it.” If a user follows these instructions, they’ll be able to click on the phishing link.

“As users have become used to typing STOP, Yes, or NO to confirm appointments or opt out of text messages, the threat actors are hoping this familiar act will lead the text recipient to reply to the text and enable the links,” BleepingComputer notes.

“Doing so will enable the links again and turn off iMessage's built-in phishing protection for this text. Even if a user doesn't click on the now-enabled link, the act of replying tells the threat actor that they now have a target that responds to phishing texts, making them a bigger target.”

New-school security awareness training can give your organization an essential layer of defense against targeted social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

BleepingComputer has the story.

Ready to Build a Security Culture That Lasts?

Stop treating training like a checkbox exercise. Using 15+ years of behavioral data, our AI-powered platform personalizes training for every user to significantly reduce human risk and stop attacks before they start.

Get a Quote

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.