Home Categories Cyberattacks Apple Password Reset Scam Requests 0 0 105 1 Mar 27, 2024 2024-03-27T14:44:26-05:00 Mar 27, 2024 2024-03-27T14:51:31-05:00 Online Threat Alerts (OTA) A potential flaw in Apple's password reset functionality allows attackers to trigger repeated password change approval requests. It is not clear how the attackers are abusing the system to send multiple messages to Apple users, but it appears to be a bug that is being exploited. It is unlikely that Apple's system is meant to be able to be used to send more than 100 requests, so presumably the rate limit is being bypassed. An Apple Password Reset Request ScamMultiple Apple users have been targeted in an attack that bombards them with an endless stream of notifications or multi-factor authentication (MFA) messages in an attempt to cause panic so they'll respond favorably to social engineering.An attacker is able to cause the target's iPhone, Apple Watch, or Mac to display system-level password change approval texts over and over again. Because the password requests target the Apple ID, they pop up on all of a user's devices. The notifications render all linked Apple products unable to be used until the popups are dismissed one by one on each device. Twitter user Parth Patel recently shared his experience being targeted with the attack, and he says he could not use his devices until he clicked on "Don't Allow" for more than 100 notifications.The actual popup can't be used to gain access to an Apple device, and it serves as a front for attackers to incite fear in the target. Following the flood of notifications, the attacker calls using a spoofed number that makes it appear to be coming from Apple. On these calls, the attacker confirms that the victim's account is under attack, and that sensitive information is needed to put a stop to it. It appears that the attacker is after a one-time code to confirm a password reset or login attempt.For more information, please go to www.macrumors.com Check the comment section below for answers or additional information. Share what you know, or ask a question about this article by leaving a comment below. Save + Was this article helpful? (1) (0) ▷Jennifer Davidson Sent You an Invoice P... ◁The 5 Most Popular and Unexpected Job O... "www.Huzlers.com" is a Fake-News Websit... "Apple Account Status Update" Phishing ... Is qunqm.com an Untrustworthy Online St... pickydays.com - Customer Review of the... Is Comereview Life an Untrustworthy Onl... Zimpression Website Scam: See the Revie... Is Watch Whole a Scam or Legit Store at... Comments / Answers Remove sensitive information from your post. Enter comment post here