Protect.Computer
NEWS

Scammers Abuse Apple's Own Alert Emails to Trick You

· 1 min read · Digital scams Identity theft
Scammers Abuse Apple's Own Alert Emails to Trick You

Scammers have found a clever way to send phishing emails that look completely real — by abusing Apple’s own notification system. A criminal creates an Apple ID, types a fake warning message (“Unauthorized iPhone purchase detected — call us immediately”) into the first and last name fields, then updates the account’s shipping address. Apple’s servers automatically fire off a legitimate security alert email — with the scammer’s phishing text baked right into it. Because the email genuinely comes from Apple’s infrastructure, it passes all standard security checks (SPF, DKIM, DMARC), and the sender address shows a real @apple.com domain.

If you receive one of these messages and call the number in the email, you’re connected directly to scammers posing as Apple support. They will pressure you for your Apple ID password, credit card details, or remote access to your device. The danger is that even careful users who check the sender address — and confirm it says @apple.com — can still be fooled. Apple has not yet announced changes to its notification system to block this abuse.

How to check if you’re affected

Affected devices include any iPhone, iPad, or Mac linked to an Apple ID that receives account change or purchase notification emails. If you get an unexpected Apple email about a new purchase or account update with a phone number to call, treat it as suspicious.

  1. Do NOT call any phone number listed in the email.
  2. Open your browser and manually type appleid.apple.com — do not click any links in the email.
  3. Check Purchase History and Sign-In & Security for anything you don’t recognize.
  4. Forward the suspicious email to reportphishing@apple.com and then delete it.

Sources

Related reading