Apple users are being targeted in a social engineering campaign that uses unexpected FaceTime calls to impersonate banks and Apple Support, with attackers aiming to steal money and take over accounts. Reports say the scam often starts with urgent text messages claiming there is a problem with a bank or Apple account, then escalates to unsolicited video calls in which fraudsters pressure victims to reveal banking details, Apple ID credentials, and MFA codes, or to install remote-access software.
Security reporting says the tactic exploits the trust created by real-time video interactions to reduce suspicion and speed compliance, enabling account takeover and financial theft. The campaign may also be paired with browser-side flaws and other multi-stage techniques to deepen compromise after credentials are stolen. Apple and financial institutions do not use FaceTime for urgent security remediation, and users are being urged to verify any alerts through official channels, keep iOS and iPadOS updated, and report suspected scams to Apple.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Apple warned iPhone and iPad users that attackers are abusing unexpected FaceTime calls in social engineering scams impersonating banks and Apple Support. The scam uses urgent fake text alerts followed by unsolicited FaceTime calls to pressure victims into revealing banking details, Apple ID credentials, MFA codes, or installing remote-access tools.
Malwarebytes reported on scammers using FaceTime as part of a fraud scheme that can lead to account takeover and financial theft. The reporting described how attackers exploit trust in live video interactions to lower suspicion and empty victims' bank accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
ghacks.net
Open sourcehelpnetsecurity.com
Open sourcetechrepublic.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcemalwarebytes.com
Open sourcesupport.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.