Tuesday, 29 April 2025
30.7 C
Singapore
32.7 C
Thailand
23.6 C
Indonesia
29.2 C
Philippines

Beware of MFA bombing: A new phishing scam targeting Apple users

"MFA Bombing" phishing attack targeting Apple users and how to protect yourself from being locked out of your account.

In a concerning trend, numerous Apple enthusiasts have become the unsuspecting victims of a phishing scheme known as “MFA Bombing.” This cunning attack exploits a loophole in Apple’s password reset system, preying on the shared human traits of impatience and oversight.

How does the scam unfold?

Imagine your day is interrupted by a barrage of “Reset Password” notifications on your iPhone, urging you to “Use this iPhone to reset your Apple ID password.” For those caught in the crosshairs of this scam, such alerts have become a frustrating reality. Parth Patel recounted his ordeal on X, detailing how he was bombarded with up to 100 of these notifications.

The attackers’ strategy hinges on weariness and error. They bombard you with notifications in the hope that, in a moment of frustration or distraction, you’ll mistakenly press “Allow” instead of “Don’t Allow.” Falling into this trap grants the scammer the power to reset your Apple ID password, effectively locking you out of your account and devices.

Should this initial ploy fail, the scammer might escalate their tactics by impersonating Apple Support in a phone call. The aim is to coax you into revealing a one-time password, which they can use to gain control over your Apple ID.

The email addresses and phone numbers linked to your Apple ID are all the scammers need to launch this attack. These details are used on Apple’s page for a forgotten Apple ID password, triggering the relentless notifications. The exact method by which these attackers manage to spam users with multiple alerts remains unclear, though it is suspected that a glitch in the system is being exploited.

Steps to take if you’re targeted

There is no definitive solution to this problem currently. If you receive persistent notifications, remain calm and methodically tap “Don’t Allow” on each one.

Moreover, should you receive an unsolicited call claiming to be from Apple Support, remember that Apple does not make outbound calls unless requested by the customer. Notably, Apple would never ask for your one-time password reset codes over the phone.

This ordeal underscores the importance of vigilance in the digital age. By staying informed and cautious, you can protect yourself from falling victim to such schemes.

Hot this week

Semperis launches Ready1 to boost cyber crisis response for Singapore businesses

Semperis unveils Ready1 to streamline cyber crisis management, with Singapore ranking among the most prepared yet still facing major response gaps.

Early cancer detection startup Craif raises US$22M to expand into the U.S.

Craif raises $22M to expand its microRNA early cancer detection technology into the U.S., aiming to make testing simple and accessible.

Oracle rolls out NVIDIA Blackwell GPUs to power advanced AI and reasoning models

Oracle deploys NVIDIA Blackwell GPUs on OCI to power agentic AI, offering scalable and efficient support for reasoning model workloads.

Tesla profits drop sharply as sales weaken and Musk backlash grows

Tesla’s profits fall 71% as sales dip, political backlash grows, and hopes turn to cheaper EVs and robotaxi plans.

StarHub celebrates 25 years of connection and innovation

StarHub celebrates 25 years of connecting Singapore, marking the milestone with island-wide festivities, giveaways, and new entertainment experiences.

ASUS teams up with Bethesda to launch ROG Astral GeForce RTX 5080 DOOM Edition

ASUS celebrates 30 years of graphics cards with a limited ROG RTX 5080 DOOM Edition, launched in partnership with Bethesda and id Software.

Commvault expands cyber recovery services through CrowdStrike partnership

Commvault and CrowdStrike expand partnership to offer integrated cyber recovery and incident response services for stronger cyber resilience.

ASUS and JustCo introduce experience zones for business travellers and professionals in Singapore

ASUS and JustCo open new tech-enabled workspace zones in Singapore, featuring premium monitors and chairs for modern professionals.

Microsoft report reveals Singapore’s workforce is embracing AI to overcome productivity limits

Microsoft's latest report finds Singapore businesses turning to AI agents to scale workforce capacity and drive organisational change.

Related Articles

Popular Categories