Connect with us

Technology

New cyberattack targets iPhone, Apple IDs. Here's how to stay safe

Published

on

New cyberattack targets iPhone, Apple IDs. Here's how to stay safe

Join Fox News for access to this content

You have reached your maximum number of articles. Log in or create an account FREE of charge to continue reading.

By entering your email and pushing continue, you are agreeing to Fox News’ Terms of Use and Privacy Policy, which includes our Notice of Financial Incentive.

Please enter a valid email address.

Having trouble? Click here.

Attention iPhone owners: A serious cyberthreat is targeting Apple IDs, and it’s more crucial than ever to be on your guard. Security experts from Symantec have uncovered a sophisticated SMS phishing campaign designed to trick you into giving up your valuable Apple ID credentials.

GET SECURITY ALERTS, EXPERT TIPS – SIGN UP FOR KURT’S NEWSLETTER – THE CYBERGUY REPORT HERE

Advertisement

The mechanics of the attack

Here’s how the scam works: hackers send out text messages that look like they’re from Apple. These messages urgently request that you click on a link for an important iCloud update or verification. Symantec’s research shows these links lead to cleverly designed fake websites that ask for your Apple ID and password. To make the site seem legitimate, the attackers have even included a CAPTCHA.

Once you complete the CAPTCHA, you’re taken to what looks like an outdated iCloud login page, where you’re prompted to enter your credentials. This information is gold for cybercriminals because it grants them access to your personal and financial data and control over your devices.

Below is an email version of this same scam to avoid. Note the strange email return address originating from a non-Apple account, riddled with dashes and strange characters.

The email scam can claim that a user’s iCloud storage is full. (Kurt “CyberGuy” Knutsson)

Apple’s response and protective measures

Apple is aware of these tactics and has guidelines to help you stay protected. First and foremost, enable two-factor authentication on your Apple ID. This adds an extra layer of security by requiring a password and a six-digit verification code whenever you log in from a new device.

Advertisement

Remember, Apple will never ask you to disable security features like two-factor authentication or Stolen Device Protection. Scammers might claim this is necessary to resolve an issue, but it’s a trap designed to lower your defenses.

An iPhone scam uses text messages.  (Kurt “CyberGuy” Knutsson)

Spotting phishing attempts

Phishing scams can be sneaky, but there are ways to identify them. Look closely at the URLs in any suspicious messages. Although the message might appear legitimate, the web address usually won’t match Apple’s official site. Also, be wary of any text that deviates from Apple’s typical communication style.

Symantec highlighted a specific phishing message as part of their warning on July 2. The fraudulent SMS read: “Apple important request iCloud: Visit signin[.]authen-connexion[.]info/iCloud to continue using your services.” Odd characters and unfamiliar domains are clear indicators of a scam.

iPhone users should enable two-factor authentication on their Apple ID. (Kurt “CyberGuy” Knutsson)

Advertisement

Broader scam tactics and how to avoid them

These phishing attempts aren’t just targeting Apple users. People have reported receiving messages similar to those from companies like Netflix and Amazon, claiming account issues or expired credit cards. These messages also direct you to click a link and enter your personal information.

The Federal Trade Commission advises that legitimate companies will never request sensitive information via text. If you receive a message like this, contact the company directly using a verified number or website, not the information provided in the text.

7 SIGNS YOU’VE BEEN HACKED

How to protect yourself from Apple text and email scams

1) Always use strong antivirus protection on all your devices

This is perhaps one of the best investments you can make for yourself to protect yourself from phishing scams. Having antivirus software actively running on your devices will make sure you are stopped from clicking on any malicious links or from downloading any files that will release malware into your device and potentially have your private information stolen. Read my review of my best antivirus picks here.

2) Don’t take the bait

Scammers often use alarming language to provoke immediate action. Phrases like “act now” or “important” are red flags. Stay calm and skeptical of any unsolicited messages.

Advertisement

3) Enable two-factor authentication on your Apple devices

Implementing multifactor authentication on your Apple ID can greatly enhance your security. Always verify the source of messages that claim to be from Apple. If you’re unsure, manually log into your account through the official Apple website or your iPhone settings instead of clicking any links.

4) Keep software up to date

Regularly update your operating system, web browsers and antivirus software to ensure they are equipped to detect and prevent the latest threats. You can regularly check for these updates on your device’s settings app for software updates, and you can go to your App Store or Google Play Store (depending on the device you have) to check for updates on individual apps. Follow these steps here.

2 BULLETPROOF STEPS TO HACK-PROOF YOUR MAC

What should you do if you’ve clicked a link and installed malware on your device? 

If you’ve been hacked, it’s not too late. There are several ways you can protect yourself from hackers, even when they have access to your information.

1) Scan your device for malware

First, you’ll want to scan your computer with a reputable and legitimate antivirus program. See my expert review of the best antivirus protection for your Windows, Mac, Android and iOS devices.

Advertisement

2) Change your passwords immediately

If you’ve inadvertently given your information to hackers or malicious actors, they could have access to your social media or banking accounts. To prevent this, you should change your passwords for all your important accounts as soon as possible. However, you should not do this on your infected device, because the hacker might see your new passwords. Instead, you should use ANOTHER DEVICE, such as your laptop or desktop, to change your passwords. Make sure you use strong and unique passwords that are difficult to guess or break. You can also use a password manager to generate and store your passwords securely.

3) Monitor your accounts and transactions

You should check your online accounts and transactions regularly for suspicious or unauthorized activity. If you notice anything unusual, report it to the service provider or the authorities as soon as possible. You should also review your credit reports and scores to see signs of identity theft or fraud.

4) Use identity theft protection

Phishing emails target your personal information. Hackers can use this information to create fake accounts in your name, access your existing accounts and pretend to be you online. This can cause serious damage to your identity and credit score.

To avoid this, you should use identity theft protection services. These services can track your personal information, such as your home title, Social Security Number, phone number and email address, and notify you if they detect any suspicious activity. They can also help you freeze your bank and credit card accounts to stop hackers from using them.

One of the best parts of using some services is that they might include identity theft insurance of up to $1 million to cover losses and legal fees and a white-glove fraud resolution team where a U.S.-based case manager helps you recover any losses. Read more of my review of the best identity theft protection services here.

Advertisement

5) Contact your bank and credit card companies

If hackers have obtained your bank or credit card information, they could use it to make purchases or withdrawals without your consent. You should contact your bank and credit card companies and inform them of the situation. They can help you freeze or cancel your cards, dispute any fraudulent charges and issue new cards for you.

6) Alert your contacts

If hackers have accessed your email or social media accounts, they could use them to send spam or phishing messages to your contacts. They could also impersonate you and ask for money or personal information. You should alert your contacts and warn them not to open or respond to any messages from you that seem suspicious or unusual.

7) Restore your device to factory settings

If you want to make sure that your device is completely free of any malware or spyware, you can restore it to factory settings. This will erase all your data and settings and reinstall the original version. You should back up your important data before doing this and only restore it from a trusted source.

HOW TO REMOVE YOUR PRIVATE DATA FROM THE INTERNET 

Kurt’s takeaways

As cyberattacks become increasingly sophisticated, staying informed and cautious is crucial. Protect your Apple ID and personal information by following Apple’s security guidelines and being wary of unsolicited messages. By taking these precautions, you can safeguard your devices and data from malicious actors.

Advertisement

Have you ever been a victim of a cyberscam? If so, what happened and how did you recover? Let us know by writing us at Cyberguy.com/Contact.

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Answers to the most asked CyberGuy questions:

Advertisement

Copyright 2024 CyberGuy.com. All rights reserved.

Technology

Amazon’s smart shopping cart for Whole Foods gets bigger, lighter, and adds tap-to-pay

Published

on

Amazon’s smart shopping cart for Whole Foods gets bigger, lighter, and adds tap-to-pay

Amazon is launching a revamped version of its smart shopping cart, which it plans to bring to dozens of Whole Foods locations by the end of this year, according to an announcement on Wednesday. The new Dash Cart features a “more responsive” item scanner that’s now located next to the built-in display, along with a new NFC reader that lets you tap to pay with your credit card or phone.

Amazon’s previous Dash Cart design put scanners beneath and in front of the handle, potentially making them harder to spot. It also only let you pay with the credit card attached to your Amazon account.

With the upgraded Dash Cart, you’ll find a new scale alongside the cart’s handle, which Amazon says “works in tandem with on-cart cameras, weight sensors, and deep learning models to ensure accurate pricing for every item.” The upgraded Dash Cart eliminates the large sensors facing inside the cart as well, offering a 40 percent larger capacity and a 25 percent lighter weight.

The Dash Cart shows an interactive map of the store on its display, similar to Instacart’s smart Caper Cart. You can sync your shopping list created with Alexa, too, and see how much you’re spending as you add more items to your cart. The cart uses built-in sensors and computer vision to detect when you’ve removed an item, allowing it to automatically update your total. When you’re done shopping, you can skip the checkout line and leave the store in a designated Dash Cart lane.

Amazon is launching its new Dash Cart as the company shakes up its grocery business, which has tied Whole Foods more closely to the Amazon brand. The company has already brought its new Dash Cart to three Whole Foods stores in McKinney, Texas; Reston, Virginia; and Westford, Massachusetts, along with two Amazon Fresh stores.

Advertisement
Continue Reading

Technology

Fake error popups are spreading malware fast

Published

on

Fake error popups are spreading malware fast

NEWYou can now listen to Fox News articles!

A dangerous cybercrime tool has surfaced in underground forums, making it far easier for attackers to spread malware. 

Instead of relying on hidden downloads, this tool pushes fake error messages that pressure you into fixing problems that never existed. Security researchers say this method is spreading quickly because it feels legitimate. The page looks broken. The warning feels urgent. The fix sounds simple. 

That combination is proving alarmingly effective for cybercriminals.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

How fake error malware attacks actually work

These attacks begin with a compromised website. When a visitor lands on the page, something looks wrong right away. Text appears broken. Fonts look scrambled. Visual elements seem corrupted. A pop-up then appears claiming the issue can be fixed with a browser update or a missing system font. A button offers to repair the problem instantly. 

Clicking that button copies a command to the clipboard and displays instructions to paste it into PowerShell or a system terminal. That single step launches the infection.

MALICIOUS CHROME EXTENSIONS CAUGHT STEALING SENSITIVE DATA

Fake error popups make a website look broken by scrambling text or fonts to create urgency and panic. (Jens Büttner/picture alliance via Getty Images)

Why this new tool changes the threat landscape

The tool behind these attacks is called ErrTraffic. It automates the entire process and removes the technical barriers that once limited cybercrime operations. For about $800, attackers get a full package with a control panel and scripted payload delivery. Analysts at the Hudson Rock Threat Intelligence Team identified the tool after tracking its promotion on Russian-language forums in early December 2025. 

Advertisement

ErrTraffic works through a simple JavaScript injection. A single line of code connects a hacked site to the attacker’s dashboard. From there, everything adapts automatically. The script detects the operating system and browser. It then displays a customized fake error message in the correct language. The attack works across Windows, Android, macOS and Linux.

MOST PARKED DOMAINS NOW PUSH SCAMS AND MALWARE

The popups often claim a browser update or missing system font is needed to fix the problem. (Daniel Acker/Bloomberg via Getty Images)

Why security software struggles to stop it

Traditional malware defenses look for suspicious downloads or unauthorized installations. ErrTraffic avoids both. Browsers see normal text copying. Security tools see a legitimate system utility being opened manually. Nothing appears out of place. That design allows the attack to slip through protections that would normally stop malware in its tracks.

The success rate is deeply concerning

Data pulled from active ErrTraffic campaigns shows conversion rates approaching 60%. That means more than half of the visitors who see the fake error message follow the instructions and install malware. Once active, the tool can deliver infostealers like Lumma or Vidar on Windows devices. Android targets often receive banking trojans instead. The control panel even includes geographic filtering, with built-in blocks for Russia and neighboring regions to avoid drawing attention from local authorities.

Advertisement

What happens after infection?

Once malware is installed, credentials and session data are stolen. Those compromised logins are then used to breach additional websites. Each newly hacked site becomes another delivery vehicle for the same attack. That cycle allows the campaign to grow without direct involvement from the original operator.

FAKE WINDOWS UPDATE PUSHES MALWARE IN NEW CLICKFIX ATTACK

Following the on-screen instructions can quietly trigger malware that steals passwords and personal data. (Kurt Knutsson)

Ways to stay safe from fake error malware

A few smart habits can significantly reduce risk when facing fake error pop-ups and browser-based traps.

1) Never run commands suggested by a website

Legitimate websites never ask you to copy and paste commands into PowerShell or a system terminal. Fake error malware relies on convincing messages that pressure you into doing exactly that. If a page instructs you to run code to fix a problem, close it immediately.

Advertisement

2) Close pages that claim your system is corrupted

Fake error campaigns often use broken text, scrambled fonts or warnings about missing files to grab attention. As a result, these visuals create urgency and trigger fear. In reality, a real system problem never announces itself through a random website, so close the page right away.

3) Install updates only through official system settings

Real browser and operating system updates come from built-in update tools, not pop-ups on websites. If an update is needed, your device will notify you directly through system settings or trusted app stores.

4) Install strong antivirus software on every device

Strong antivirus software can help block malicious scripts, detect infostealers and stop suspicious behavior before damage spreads. This is especially important since fake error malware targets Windows, Android, macOS and Linux systems.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

Advertisement

5) Use a data removal service to reduce exposure

Stolen credentials fuel the spread of fake error malware. Removing personal information from data broker sites can reduce the impact if login details are compromised and limit how far an attack can spread.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

6) Treat font and browser update pop-ups with suspicion

Claims about missing fonts or outdated browsers are a hallmark of these attacks. Modern systems manage fonts automatically, and browsers update themselves. A webpage has no reason to request manual fixes.

Advertisement

If a real update is needed, the operating system will request it directly. A random webpage never should.

Kurt’s key takeaways 

Fake error malware works because it plays on a very human reaction. When something on a screen suddenly looks broken, most people want to fix it fast and move on. That split-second decision is exactly what attackers are counting on. Tools like ErrTraffic show how polished these scams have become. The messages look professional. The instructions feel routine. Nothing about the moment screams danger. But behind the scenes, one click can quietly hand over passwords, banking access and personal data. The good news is that slowing down makes a real difference. Closing a suspicious page and trusting built-in system updates can stop these attacks cold. When it comes to pop-ups claiming your device is broken, walking away is often the smartest fix.

Have you ever seen a pop-up or error message that made you stop and wonder if it was real? Tell us what it looked like and how you handled it by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter. 

Advertisement

Copyright 2025 CyberGuy.com. All rights reserved.

Continue Reading

Technology

Intel is planning a custom Panther Lake CPU for handheld PCs

Published

on

Intel is planning a custom Panther Lake CPU for handheld PCs

Intel announced yesterday that it’s developing an entire “handheld gaming platform” powered by its new Panther Lake chips, and joining an increasingly competitive field. Qualcomm is hinting about potential Windows gaming handhelds showing up at the Game Developers Conference in March, and AMD’s new Strix Halo chips could lead to more powerful handhelds.

According to IGN and TechCrunch, sources say Intel is going to compete by developing a custom Intel Core G3 “variant or variants” just for handhelds that could outperform the Arc B390 GPU on the chips it just announced. IGN reports that by using the new 18A process, Intel can cut different die slices, and “spec the chips to offer better performance on the GPU where you want it.”

As for concrete details about the gaming platform, we’re going to have to wait. According to Intel’s Dan Rogers yesterday, the company will have “more news to share on that from our hardware and software partners later this year.” The Intel-based MSI Claw saw a marked improvement when it jumped to Lunar Lake, and hopefully the new platform keeps up that positive trend.

Continue Reading

Trending