Monday, 15 December 2025
24.1 C
Singapore
22.2 C
Thailand
25.3 C
Indonesia
26.8 C
Philippines

Beware of MFA bombing: A new phishing scam targeting Apple users

"MFA Bombing" phishing attack targeting Apple users and how to protect yourself from being locked out of your account.

In a concerning trend, numerous Apple enthusiasts have become the unsuspecting victims of a phishing scheme known as “MFA Bombing.” This cunning attack exploits a loophole in Apple’s password reset system, preying on the shared human traits of impatience and oversight.

How does the scam unfold?

Imagine your day is interrupted by a barrage of “Reset Password” notifications on your iPhone, urging you to “Use this iPhone to reset your Apple ID password.” For those caught in the crosshairs of this scam, such alerts have become a frustrating reality. Parth Patel recounted his ordeal on X, detailing how he was bombarded with up to 100 of these notifications.

The attackers’ strategy hinges on weariness and error. They bombard you with notifications in the hope that, in a moment of frustration or distraction, you’ll mistakenly press “Allow” instead of “Don’t Allow.” Falling into this trap grants the scammer the power to reset your Apple ID password, effectively locking you out of your account and devices.

Should this initial ploy fail, the scammer might escalate their tactics by impersonating Apple Support in a phone call. The aim is to coax you into revealing a one-time password, which they can use to gain control over your Apple ID.

The email addresses and phone numbers linked to your Apple ID are all the scammers need to launch this attack. These details are used on Apple’s page for a forgotten Apple ID password, triggering the relentless notifications. The exact method by which these attackers manage to spam users with multiple alerts remains unclear, though it is suspected that a glitch in the system is being exploited.

Steps to take if you’re targeted

There is no definitive solution to this problem currently. If you receive persistent notifications, remain calm and methodically tap “Don’t Allow” on each one.

Moreover, should you receive an unsolicited call claiming to be from Apple Support, remember that Apple does not make outbound calls unless requested by the customer. Notably, Apple would never ask for your one-time password reset codes over the phone.

This ordeal underscores the importance of vigilance in the digital age. By staying informed and cautious, you can protect yourself from falling victim to such schemes.

Hot this week

Singapore leads global third-party cyber risk maturity as supply-chain threats intensify

Singapore leads global third-party cyber risk maturity but faces rising supply-chain cyber threats, according to new BlueVoyant research.

DJI launches Neo 2, its lightest and most compact drone yet

DJI launches the Neo 2, a lightweight, compact drone with advanced shooting modes and obstacle avoidance.

Deepal marks Christmas in Singapore with Pantler Café collaboration and S07 test drive giveaway

Deepal partners with Pantler Café in Singapore for festive treats, an S07 showcase and a 3D2N electric SUV test drive giveaway.

Veeam completes acquisition of Securiti AI to build unified trusted data platform

Veeam completes its US$1.725 billion acquisition of Securiti AI to form a unified trusted data platform for secure and scalable AI adoption.

Grab signs partnership with Charge+ to expand EV charging network in Vietnam

Grab and Charge+ partner to expand Vietnam’s EV charging network and support the country’s shift towards green mobility.

Tiiny AI unveils pocket-sized AI supercomputer verified by Guinness World Records

Tiiny AI reveals a Guinness-verified pocket-sized AI supercomputer designed to run massive models locally without relying on the cloud.

Samsung Galaxy Z TriFold sells out first batch, second waitlist opens in Singapore

Samsung’s Galaxy Z TriFold sells out its first batch in Singapore, with a second waitlist now open for the premium tri-fold phone.

PlayStation introduces limited edition Genshin Impact DualSense controller

PlayStation announces a limited edition Genshin Impact DualSense controller for PS5, launching in Singapore on 21 January 2026.

PGL brings Counter-Strike 2 Major to Singapore in November 2026

PGL confirms the Counter-Strike 2 Major is coming to Singapore in November 2026, marking the first CS2 Major in Southeast Asia.

Related Articles

Popular Categories