Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 26, 2026 · 7 min read

AnonyMousKIT Uses AI Calls to Phish iPhone Passcodes

Your phone is stolen. You mark it as lost and leave a number so a good samaritan can reach you. Two days later that number rings, and a calm voice says she is Alice from Apple Support and needs your passcode to confirm ownership. She is not a person, and the number she called is the one you published yourself.

That call is a product. Threat intelligence firm SOCRadar has documented a phishing as a service platform called AnonyMousKIT that automates the sequence from stolen handset to unlocked resale, and the voice on the line is a synthetic agent reading a script. It costs its operators about ten cents a call.

Key Takeaways

  • SOCRadar identified AnonyMousKIT as a phishing as a service platform, active since early 2024, that automates unlocking stolen Apple devices by defeating Activation Lock, as reported by BleepingComputer.
  • The operation is connected to 506 domains and 168 storefront brands acting as resellers.
  • Investigators recovered 200 call records placed between August 2025 and May 2026, driven by a voice AI agent running 55 distinct interaction transcripts across five personas, one of them "Alice from Apple Support."
  • Roughly 90% of those calls went to Brazil, at a cost of about $0.10 per attempt.
  • Victims are contacted by email, SMS, WhatsApp or phone using the details they entered into Lost Mode, then asked for their device passcode, Apple Account credentials and two factor code.
A hand resting on a dark smartphone lying face up on a wooden desk in dim blue window light, a second phone and a pair of headphones beside it

What Is AnonyMousKIT?

AnonyMousKIT is a subscription phishing platform built for one job: getting the credentials that lift Apple's Activation Lock off a stolen iPhone so it can be sold as working hardware. SOCRadar got inside because the operators left bare relative paths exposed, which let researchers enumerate the backends, storefronts and call logs.

BleepingComputer's write up puts the platform at 506 connected domains feeding 168 reseller brands. CyberInsider's account of the same research adds the shape underneath: 30 backend installations, 6,092 phishing emails sent across them, and a panel tracking 5,031 targeted devices of which 1,035 were locked. That ratio is the business model in one line. Four in five phones a customer touches are already usable; the fifth needs a phone call. Access is credit based, spent on emails, SMS, WhatsApp messages, prerecorded calls or the AI agent.

Why Does Lost Mode Make This Possible?

Because Lost Mode takes a phone number and a message that you choose and prints them on the lock screen of a device now in someone else's hands. Apple's guide to using Lost Mode in Find Devices on iCloud.com says you enter a number where "you can be reached" plus a message about how to contact you, and that both appear on the screen.

The feature works as designed, for the stranger who finds your phone on a train seat. But a thief reads the same screen, and what they read is a live contact channel attached to someone anxious, expecting a call about this exact phone, and primed to believe good news. Most coverage describes the fake Apple pages and skips the pivot: the victim supplies the targeting data.

The hardware supplies the rest: model and IMEI are readable from the device, so the message that arrives names the correct handset. Every heuristic people are taught for spotting a scam — vague greeting, no account specifics — inverts here.

How Does the AI Voice Agent Work?

It is a commercial voice AI service given a persona, a language and a goal, dialling a call list. CyberInsider reports the agent was built on VAPI.ai, that the recovered logs held 200 call records and 55 transcripts, and that the lead persona was "Alice from Apple Support" speaking Portuguese, telling victims Apple had recovered their missing phone and asking for their "four- or six-digit passcode."

Then the economics. Two hundred calls across nine months ran at roughly $0.10 per attempt. At that price nobody needs a good conversion rate, and nothing holds the operation to Portuguese — a language swap is a configuration field. Brazil took 179 of the 200 calls, a pilot market rather than a ceiling.

This is the third AI voice phishing service to reach us this year, after the ATHR vishing platform in April and the Bluekit kit that shipped with voice cloning and 40 templates. The synthetic voice is not the innovation; the collapse in the labour cost of a targeted phone call, to about the price of a text message, is.

Why Ask for a Passcode If Activation Lock Needs a Password?

Because the passcode is the shortest route to the password. Apple's page on Activation Lock for iPhone and iPad states that "Your Apple Account password is required before anyone can turn off Find My, erase your device, or reactivate and use your device." Read alone, that makes the six digits the agent asks for sound harmless.

Now read Apple's page on what to do if you forgot your Apple Account password, which instructs you to "Enter your device passcode. Then follow the onscreen instructions to change your Apple Account password." The passcode is a password reset token. That is why the script asks for the passcode, the account credentials and the two factor code in one pass: any one of them is a step, and together they are the whole lock.

The prize is not the handset: a recovered Apple Account opens iCloud backups, synced mail, photos and iCloud Keychain, which for most people is every password they own.

What This Means for Your Inbox

Email is one of four documented delivery channels here, not a footnote to the phone call: 6,092 phishing emails were counted across the backends SOCRadar enumerated. Put an email address in your Lost Mode message and it enters the same funnel the number does, and what lands will carry Apple styling, your device model and your IMEI.

That breaks the filter most of us actually use. We do not read email headers; we pattern match on whether the sender seems to know us. A message naming the exact phone you lost yesterday clears that bar instantly, which is why the flow front loads real device data first. Apple's guidance onrecognizing and avoiding phishing messages still helps: check the sender address against the company, and a link's URL against its website. Those are the checks left once the content itself is accurate.

One habit follows. When a message contains details you believe only the real company could know, slow down rather than relax, because targeted attackers buy or scrape exactly those details, as we argued coveringApple's threat notifications to spyware targets in 110 countries. Specificity is not authentication.

What Should You Do If Your iPhone Is Stolen?

Five things, and the first defeats the entire kit.

  • Never type a device passcode into a web page. A passcode is entered on the lock screen of the device itself and nowhere else. Apple states it plainly: it "will never ask you … to provide your password, device passcode, or two-factor authentication code."
  • Hang up on the call. Apple's same guidance: if a call from someone claiming to be Apple Support is unsolicited or suspicious, "just hang up." A genuine recovery never depends on you staying on the line.
  • Verify only where you started. If a message says your phone has been found, close it and check Find My or account.apple.com directly. Nothing legitimate lives at a link in an unexpected message.
  • Keep the Lost Mode message thin. You are publishing it to whoever holds the phone. Treat any number you put there as public, and expect the first call it attracts to be hostile.
  • Change your Apple Account password from a trusted device you still hold, before anyone uses the passcode route above, then confirm Find My is still on.

The uncomfortable read is that Activation Lock is holding. SOCRadar's panel showed 1,035 locked devices customers could not shift, which is why 168 storefronts exist to talk owners into opening them by hand. The lock did not fail. It was routed around, through the person.

Sources: BleepingComputer: AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes; CyberInsider: AnonyMousKIT service uses AI calls to unlock stolen Apple devices; SOCRadar: Exposing AnonyMousKIT, an AI Powered PhaaS Supply Chain; Apple: Recognize and avoid phishing messages, fake support calls, and other scams; Apple: Activation Lock for iPhone and iPad; Apple: If you forgot your Apple Account password; Apple: Use Lost Mode in Find Devices on iCloud.com. SOCRadar's own research post was unreachable from our network at the time of writing, so the platform figures here are taken from the BleepingComputer and CyberInsider reporting of it.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.