Connect with us

Technology

Real Apple support emails used in new phishing scam

Published

on

Real Apple support emails used in new phishing scam

NEWYou can now listen to Fox News articles!

A new phishing scam is getting a lot of attention because it uses real Apple Support tickets to trick people into giving up their accounts. Broadcom’s Eric Moret shared how he nearly lost his entire Apple account after trusting what looked like official communication. He described the full experience in a detailed post on Medium, where he walked through the scam step by step.

This scheme stands out because the scammers relied on Apple’s own support system to make their messages look legitimate. They created an experience that felt polished and professional from the first alert to the final phone call. Here’s how the scam unfolded.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter

THE #1 GOOGLE SEARCH SCAM EVERYONE FALLS FOR

Advertisement

Scammers are exploiting real Apple Support tickets to trick users into handing over their accounts, experts warn. (Photo by STR/NurPhoto via Getty Images)

How the scam starts

Moret first received a flood of alerts. These included two-factor authentication notifications that claimed someone was trying to access his iCloud account. Within minutes, he got phone calls from calm, helpful callers who claimed to be Apple agents ready to fix the issue.

The twist is how convincing the entire setup felt. The scammers were able to exploit a flaw in Apple’s Support system that lets anyone create a genuine support ticket without verification. They opened a real Apple Support case in his name, which triggered official emails from an Apple domain. This built instant trust and lowered Moret’s guard.

How scammers gained access to the account

During a 25-minute call, the fake agents guided Moret through what they said would secure his account. They walked him through the steps to reset his iCloud password. They also told him a link would follow so he could close the case.

That link took him to a fake site called appeal apple dot com. The page looked official and claimed his account was being secured. It then told him to enter a six-digit code sent by text to finish the process.

Advertisement

When Moret entered that code, the scammers got exactly what they needed to sign into his account.

He then got an alert that his Apple ID had been used to sign into a Mac mini he did not own. That confirmed the takeover attempt. Even though the scammer on the phone said this was normal, he trusted his instinct. He reset his password again, which kicked them out and stopped the attack.

BEWARE FAKE CREDIT CARD ACCOUNT RESTRICTION SCAMS

A Broadcom executive says he nearly lost access to his Apple ID after trusting a fraudulent support call that looked legitimate. (Photo by Jakub Porzycki/NurPhoto via Getty Images)

How to protect yourself from the Apple Support ticket scam

This type of scam works because it feels real. The messages look official, and the callers sound trained. Still, you can stay safer by watching out for signs that something is off.

Advertisement

1) Verify support tickets inside your Apple account

Scammers created a real-looking ticket to make the entire experience seem legitimate. You can confirm what’s real by checking directly with Apple. Sign in at appleid.apple.com or open the Apple Support app to view your recent cases. If the case number isn’t listed there, the message is fake, even if the email comes from an Apple domain.

2) Hang up and call Apple yourself

Never stay on a call that you did not initiate. Scammers rely on long conversations to build trust and pressure you into quick decisions. Hang up right away and call Apple Support directly at 1-800-275-2273 or through the Support app. A real agent will quickly confirm whether anything is wrong.

3) Check your Apple ID device list

If something feels off, look at the devices signed into your account. Go to Settings, tap your name and scroll to see all devices linked to your Apple ID. Remove anything you don’t recognize. This step can stop attackers fast if they’ve managed to get in.

4) Never share verification codes

No real support agent will ever ask for your two-factor authentication codes. Treat any request for these codes as a major warning.

5) Check every link carefully

Look closely at URLs. Fake sites often add extra words or change formatting to appear real. Apple will never send you to a site like appeal apple dot com.

Advertisement

SCAMMERS ARE ABUSING ICLOUD CALENDAR TO SEND PHISHING EMAILS

Criminals are using Apple’s own support system to generate real case emails that build false confidence with victims. (Photo by Fairfax Media via Getty Images via Getty Images)

6) Use strong antivirus software

Strong antivirus software can spot dangerous links, unsafe sites, and fake support messages before you tap them. Anti-phishing tools are especially important with scams like this one since the attackers used a fake site and real ticket emails to trick victims.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Advertisement

7) Use a data removal service

Data brokers collect your phone number, home address, email, and other details that scammers use to personalize attacks. A data removal service can wipe much of that information from broker sites, which makes you a harder target for social engineering attempts like the one described in this article.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com

8) Turn on strong multi-layer protection

Keep two-factor authentication (2FA) on for every major account.  This creates a barrier that quickly stops attackers.

Advertisement

9) Slow down before reacting

Scammers want you to panic. Pause before you act. Trust your instinct when something feels rushed or strange. A short delay could save your entire account.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Kurt’s key takeaways

This scam shows how convincing criminals can be when they exploit real systems. Even careful users can fall for messages that look official and calls that sound professional. The best defense is to stay alert and take a moment before responding to anything unexpected. When you slow down, double-check support tickets, and never share verification codes, you make yourself far harder to fool. Adding layers like antivirus protection and data removal services also gives you more control over what attackers can access. These simple habits can stop even the most polished scams before they get to your accounts.

What would you do if you got a support call that felt real but didn’t seem right? Let us know by writing to us at Cyberguy.com

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter 

Advertisement

Copyright 2025 CyberGuy.com.  All rights reserved.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

The FCC’s foreign drone ban is here

Published

on

The FCC’s foreign drone ban is here

The Federal Communications Commission has banned new drones made in foreign countries from being imported into the US unless the Department of Defense or the Department of Homeland Security recommends them. Monday’s action added drones to the FCC’s Covered List, qualifying foreign-made drones and drone parts, like those from DJI, as communications equipment representing “unacceptable risks to the national security of the United States and to the safety and security of U.S. persons.”

DJI is “disappointed” by today’s action, Adam Welsh, DJI’s head of global policy, says in a statement. “While DJI was not singled out, no information has been released regarding what information was used by the Executive Branch in reaching its determination.” Welsh adds that DJI “remains committed to the U.S. market” and noted that existing products can continue operation as usual. Other items on the FCC’s list include Kaspersky anti-virus software (added in 2024) and telecommunications equipment from Huawei and ZTE (added in 2021).

The FCC says it received a National Security Determination on December 21st from an interagency body saying that “uncrewed aircraft systems” (UAS) and critical UAS components produced in a foreign country could “enable persistent surveillance, data exfiltration, and destructive operations over U.S. territory” and that “U.S. cybersecurity and critical‑infrastructure guidance has repeatedly highlighted how foreign‑manufactured UAS can be used to harvest sensitive data, used to enable remote unauthorized access, or disabled at will via software updates.”

If you already own a drone made outside the US, you will still be able to use it, according to the FCC’s fact sheet. Drones or drone components can be removed from the Covered List if the DoD or DHS “makes a specific determination to the FCC” that it does not pose unacceptable risks.

“Unmanned aircraft systems (UAS), also known as drones, offer the potential to enhance public safety as well as cement America’s leadership in global innovation,” FCC chairman Brendan Carr says.

Advertisement
Continue Reading

Technology

Netflix suspension scam targets your inbox

Published

on

Netflix suspension scam targets your inbox

NEWYou can now listen to Fox News articles!

Holiday phishing attempts surge every year, and scammers know people juggle subscriptions, gifts and billing changes. That makes a fake alert feel real for a split second. Stacey P. emailed to tell us that he received one of these messages and wrote:

“I thought I should forward this message to you that I received today that was ostensibly from Netflix. Without clicking on any links, I called Netflix and they advised me that my account is in good standing. They asked me to forward this to them.”

— Stacey P.

Stacey’s experience shows how convincing these emails can appear and why taking a moment to verify can make all the difference. These Netflix suspension emails look polished at first glance. When you look closer, however, the warning signs jump out.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

HOLIDAY DELIVERIES AND FAKE TRACKING TEXTS: HOW SCAMMERS TRACK YOU

Holiday phishing scams spike as fake Netflix suspension emails exploit seasonal billing confusion and urgency. (Zeng Hui/Xinhua via Getty Images)

Why scammers use this approach

People expect billing reminders during the holidays. When you see a familiar logo during a busy day, your guard drops for a moment. Scammers build templates that look clean, simple and trustworthy because it increases their odds of success.

Red flags inside the fake Netflix message

The Netflix scam email attempts to mimic Netflix’s branding, but several details reveal it is fraudulent.

Spelling and grammar issues

The email includes mistakes real companies would never send. It uses valldate instead of validateCommunicication instead of communication and even writes “sent to yo” with the u missing from you. Errors like these are major signs of a scam.

Advertisement

Strange tone and pressure tactics

The message claims your billing info failed and says your membership will be suspended within 48 hours unless you act. Criminals rely on urgency because it stops people from thinking clearly.

Fake login buttons

The bold red Restart Membership button aims to lure you into entering your credentials on a phishing page. Once you type your password and payment details, you hand them over to attackers.

Generic greeting

The message uses Dear User instead of your name. Netflix includes your account name in official communications.

Suspicious footer and address

The footer contains off wording about inbox preferences and a Scottsdale address not tied to Netflix. Real subscription providers use consistent company details.

FACEBOOK SETTLEMENT SCAM EMAILS TO AVOID NOW

Advertisement

A reader narrowly avoided a Netflix phishing scam by calling the company instead of clicking the email link. (Luis Boza/NurPhoto via Getty Images)

How to stay safe from the Netflix suspension scam

A few habits can protect your account even when a phishing attempt looks convincing.

1) Check your account on Netflix.com

Open Netflix on your browser or app instead of clicking any link in the email. Your account status there is always accurate.

2) Avoid entering payment details through email links

Phishing pages often copy real sites. Instead of clicking the link in the message, open your browser and type the official website address yourself. This keeps you in control and away from fake pages.

3) Use a data removal service

Scammers often pull email addresses and personal details from data broker sites. These lists fuel subscription scams that look like the Netflix alert Stacey received. A trusted data removal service can pull your information off those sites and cut down on future phishing attempts.

Advertisement

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

4) Hover over links to reveal the true URL

On a computer, hovering over a link shows where it really goes. If the address looks strange, delete the message.

5) Report the scam

Forward suspicious Netflix emails to phishing@netflix.com. This helps the fraud team block similar messages.

Advertisement

6) Strengthen your device security

Use two-factor authentication (2FA) for your email and install strong antivirus software to catch malicious pages. The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

THE FAKE REFUND SCAM: WHY SCAMMERS LOVE HOLIDAY SHOPPERS

Scammers use polished branding and urgent language to trick users into giving up login and payment details. (Gabby Jones/Bloomberg via Getty Images)

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com.

7) Consider an identity theft protection service

If you ever enter your billing info into a fake login page, attackers can use that data for much more than streaming fraud. Identity Theft companies can monitor personal information like your Social Security number (SSN), phone number and email address, and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.

Advertisement

See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Kurt’s key takeaways

Stacey’s caution prevented him from becoming another victim of this email scam. These messages keep getting more believable, so spotting the red flags and using the steps above can save you time, money and frustration.

Have you seen a fake subscription alert recently that nearly fooled you? Let us know by writing to us at Cyberguy.com.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

Copyright 2025 CyberGuy.com.  All rights reserved.

Continue Reading

Technology

Samsung ‘Wide Fold’ rumored to rival Apple’s foldable next year

Published

on

Samsung ‘Wide Fold’ rumored to rival Apple’s foldable next year

Apple’s long-rumored foldable iPhone is set to arrive next year, and already faces some preemptive competition from Samsung. Korea’s ET News reports that Samsung’s upcoming “Wide Fold” is also set to launch in 2026, and will closely mirror the display size and 4:3 aspect ratio of Apple’s first foldable.

The machine-translated report says the Wide Fold is expected to feature an OLED display that measures 5.4 inches in its folded position, and 7.6 inches when unfolded. “It will be a ‘passport’ type with a 4:3 screen ratio when unfolded,” according to an unnamed industry source cited by ET News.

Last week, The Information reported that Apple’s upcoming foldable will feature a 5.3-inch display that increases to 7.7 inches when open, and will have an aspect ratio “similar to that of Apple’s largest iPads when viewed in landscape mode,” and will be “more wide than tall when unfolded.” Most iPad models sport a near 4:3 aspect ratio. This was the latest rumor that pointed to Apple’s first foldable iPhone having a wide aspect ratio in portrait mode, though Bloomberg’s Mark Gurman said in September that the device would look like two iPhone Airs stuck together.

Both Samsung and Apple’s upcoming foldables are expected to launch in Fall 2026. The 4:3 aspect ratio is better for reading e-books and documents, viewing photographs, or creative tasks like design and image editing, but would result in traditional landscape and portrait videos having ugly black bars at the top and bottom of the screen. This is something that’s already noticeable on Samsung’s squarish Z Fold 7.

Advertisement
Continue Reading

Trending