Apple Users
Showing Original Post only (View all)New password reset attack targets Apple device users - what to do if it happens to you (ZD-Net) [View all]
Please don't be a victim.... I tried to include the most important bits of the article, but best to read the full link
https://www.msn.com/en-us/money/other/new-password-reset-attack-targets-apple-device-users-what-to-do-if-it-happens-to-you/ar-BB1kE7xL?ocid=msedgdhp&pc=LSJS&cvid=7de468e2bbaf46ba95eecde51e45da20&ei=12
Apple device owners are facing a new phishing hack that uses "multi-factor authentication (MFA) bombing" to steal their data.
Several Apple users in recent days have reported a hacking attempt that appears to take advantage of Apple's password reset feature, KrebsOnSecurity reported, citing people who have been targeted. The scammers have used Apple's password reset tool to spam their targets with dozens, if not hundreds, of notifications, asking the user to reset their Apple ID password. Pressing the "Allow" option gets the scammers one step closer to resetting the user's credentials because that device could then be used to create a new Apple ID password. Unfortunately, tapping "Don't Allow" on all the notifications doesn't solve the problem.
After those targeted by the scam chose to not allow their passwords to be reset, they received phone calls from the scammers claiming they were from Apple's support team, according to the report. Their goal was to send a password reset code to the user's device and have the user tell them the code. Armed with that information, the scammers could simply reset the Apple ID password and get full access to the user's account.
--snip--
Additionally, Apple has made it clear that the company does not call any of its users directly. So, if you receive a number from 1-800-275-2273 (Apple's actual support line that the scammers are spoofing to make their calls seem legitimate), don't pick up and definitely don't provide any information to the caller.