Sunday, 13 July 2025
27.5 C
Singapore
28.5 C
Thailand
19.9 C
Indonesia
28.1 C
Philippines

Beware of MFA bombing: A new phishing scam targeting Apple users

"MFA Bombing" phishing attack targeting Apple users and how to protect yourself from being locked out of your account.

In a concerning trend, numerous Apple enthusiasts have become the unsuspecting victims of a phishing scheme known as “MFA Bombing.” This cunning attack exploits a loophole in Apple’s password reset system, preying on the shared human traits of impatience and oversight.

How does the scam unfold?

Imagine your day is interrupted by a barrage of “Reset Password” notifications on your iPhone, urging you to “Use this iPhone to reset your Apple ID password.” For those caught in the crosshairs of this scam, such alerts have become a frustrating reality. Parth Patel recounted his ordeal on X, detailing how he was bombarded with up to 100 of these notifications.

The attackers’ strategy hinges on weariness and error. They bombard you with notifications in the hope that, in a moment of frustration or distraction, you’ll mistakenly press “Allow” instead of “Don’t Allow.” Falling into this trap grants the scammer the power to reset your Apple ID password, effectively locking you out of your account and devices.

Should this initial ploy fail, the scammer might escalate their tactics by impersonating Apple Support in a phone call. The aim is to coax you into revealing a one-time password, which they can use to gain control over your Apple ID.

The email addresses and phone numbers linked to your Apple ID are all the scammers need to launch this attack. These details are used on Apple’s page for a forgotten Apple ID password, triggering the relentless notifications. The exact method by which these attackers manage to spam users with multiple alerts remains unclear, though it is suspected that a glitch in the system is being exploited.

Steps to take if you’re targeted

There is no definitive solution to this problem currently. If you receive persistent notifications, remain calm and methodically tap “Don’t Allow” on each one.

Moreover, should you receive an unsolicited call claiming to be from Apple Support, remember that Apple does not make outbound calls unless requested by the customer. Notably, Apple would never ask for your one-time password reset codes over the phone.

This ordeal underscores the importance of vigilance in the digital age. By staying informed and cautious, you can protect yourself from falling victim to such schemes.

Hot this week

TikTok may dodge US ban with new app and ownership deal

TikTok could avoid a US ban with the launch of a new app on September 5 and a possible sale to non-Chinese investors, including Oracle.

Xiaomi Mijia Smart Dehumidifier 50L review: Powerful dehumidification for modern living

Powerful and smart, the Xiaomi Mijia Smart Dehumidifier 50L offers effective humidity control and air purification for modern homes.

AI will make cyber defence harder unless you think like a hacker

Cyber experts warn that AI is making cyber attacks smarter, urging firms to adopt a hacker mindset and prepare through simulations.

Rubio meets with China’s Wang Yi amid growing trade and defence tensions

Rubio meets China’s Wang Yi in Malaysia amid trade tensions, with both sides pushing for influence over Southeast Asia’s future.

Most Asian firms overestimate cyber readiness, Commvault study finds

Commvault’s new report reveals a major gap between confidence and real-world cyber resilience in Singapore, Malaysia, and across Asia.

OpenAI preparing to launch AI-powered web browser to rival Chrome

OpenAI plans to launch a new AI-powered web browser, aiming to transform the browsing experience using ChatGPT technology.

Singapore to get Huawei’s 480kW ultra-fast EV charger by the end of 2025

Huawei brings 480kW ultra-fast EV charger to Singapore by late 2025, slashing charge times and boosting support for commercial vehicles.

Samsung, Google, and Qualcomm share their vision for where mobile AI is heading

Samsung, Google, and Qualcomm share how mobile AI will become more helpful, personal, and invisible in your everyday life.

Razer unveils DeathAdder V4 Pro with pro-level features and ultra-lightweight design

Razer’s DeathAdder V4 Pro lands with 8000Hz wireless polling, a lighter design, and esports-level precision for serious gamers.

Related Articles

Popular Categories