ladbible homepage
ladbible homepage
  • Home
  • News
    • UK
    • US
    • World
    • Ireland
    • Australia
    • Science
    • Crime
    • Weather
  • Entertainment
    • Celebrity
    • TV
    • Film
    • Music
    • Gaming
    • Netflix
    • Disney
  • Sport
  • Technology
  • Travel
  • Lifestyle
  • Money
  • Originals
    • FFS PRODUCTIONS
    • Say Maaate to a Mate
    • Daily Ladness
    • UOKM8?
    • FreeToBe
    • Citizen Reef
  • Videos
  • Advertise
  • Terms
  • Privacy & Cookies
  • License Our Content
  • About Us & Contact
  • Jobs
  • Latest
  • Archive
  • Topics A-Z
  • Authors
Facebook
Instagram
X
Threads
Snapchat
TikTok
YouTube
Submit Your Content Here
  • GAMINGbible
  • LADbible Group
  • UNILAD
  • SPORTbible
  • Tyla
  • FOODbible
  • UNILAD Tech
iPhone users on alert over 'push bombing' phishing scam
Home>News>Technology
Updated 16:59 2 Apr 2024 GMT+1Published 17:00 2 Apr 2024 GMT+1

iPhone users on alert over 'push bombing' phishing scam

iPhone users could get hacked if they're caught out, according to reports

Tom Earnshaw

Tom Earnshaw

google discoverFollow us on Google Discover

A warning has been issued to iPhone users over a clever scam attack reported via social media.

Security issues are not a new phenomenon in the tech industry, with iOS and Android consistently patched by Apple, Samsung, and Google as hackers focus on new ways to steal your money and identity - including via WhatsApp.

In the past month, Apple has warned iPhone users over a new hacking risk and given some key pointers on how to fix it so you don't fall foul to criminals.

Advert

The company also offers more general tips when it comes to its phones including why you should not put it in rice if you get your iPhone wet.

Now, a new technical issue has been highlighted over on X (formerly Twitter) by those using multi-factor authentication (MFA).

MFA has become a common thing we're all encouraged to get. It's where you need to verify your identity via another pathway when logging in to an account such as your banking app.

iPhone home screen.
Jaap Arriens/NurPhoto via Getty Images

This can be done via an authenticator app if you have it set up. Other methods can be via a text to your personal phone or message to your email account.

Well, bad news. Hackers are now targeting the method we use to keep them out.

According to reports, the new phishing attack involves what at first looks like a bug in Apple's password reset feature, where dozens of notifications are pushed on to your home screen telling you to reset your Apple ID password.

If you click 'don't allow' instead of 'allow' like the hackers want, the scammers then call their victim pretending to be Apple Support, asking you to 'verify' your account by sharing your a one-time code (OTP) with them. This is despite such codes being sent to you from Apple explicitly saying 'don't share with anyone'.

One victim of the attack, businessman Parth Patel, took to X to detail his experience of the new hacking method known as 'MFA bombing' or 'push bombing'.

Man using an iPhone.
Getty Stock Images

Patel told KrebsOnSecurity: "All of my devices started blowing up, my watch, laptop and phone.

"It was like this system notification from Apple to approve [a reset of the account password], but I couldn’t do anything else with my phone. I had to go through and decline 100-plus notifications."

If you give over the OTP to the hackers, they are then able to lock you out of your Apple account and even remotely wipe all of your devices.

iPhone users should remain vigilant in this situation, with Apple never proactively calling you in security incidents. The only time this happens is it you ask Apple to ring you back.

One way to stop yourself falling victim to this is to improve your Apple ID security with a recovery key. This is where Apple will give you a randomly generated 28-character code that helps improve the security of your iPhone or iPad.

The attackers made a led high effort focused attack on me, using OSINT data from People Data Labs and caller ID spoofing.

First, around 6:36pm yesterday all of my Apple devices started blowing up with Reset Password notifications.

Because these are Apple system level alerts,… pic.twitter.com/vX1AZvoVoN

— Parth (@parth220_) March 23, 2024

The Apple website says: "You can generate a recovery key on a trusted device signed in with your Apple ID. After you generate a recovery key, you can also follow these steps to update your recovery key and generate a new one.

"When you generate a recovery key, print a copy or write it down. Keep it in a safe place, so that you always have access to your Apple ID. You can give a copy of your recovery key to a family member, or keep copies in more than one place.

"Before you set up a recovery key, update your device to the latest software version."

LADbible has approached Apple for comment.

Featured Image Credit: Jaap Arriens/NurPhoto via Getty Images/Getty Stock Images

Topics: iPhone, Apple, Technology, Crime, World News, UK News, News, US News

Tom Earnshaw
Tom Earnshaw

Tom joined LADbible Group in 2024, currently working as SEO Lead across all brands including LADbible, UNILAD, SPORTbible, Tyla, UNILAD Tech, and GAMINGbible. He moved to the company from Reach plc where he enjoyed spells as a content editor and senior reporter for one of the country's most-read local news brands, LancsLive. When he's not in work, Tom spends his adult life as a suffering Manchester United supporter after a childhood filled with trebles and Premier League titles. You can't have it all forever, I suppose.

X

@TREarnshaw

Recommended reads

Inside Taylor Swift and Travis Kelce's wedding gift box as guests get diamond-encrusted party favourXNY/Star Max/GC ImagesWee Man reveals the 'most disgusting' Jackass stunt that nearly made him throw upYouTube/David McIntosh JrNurse who died and then came back to life reveals what she saw after her 'heart exploded'YouTube/Jeff Mara podcastPilot shares screenshot of exactly how much they earn and people are gobsmackedKevin Carter/Getty Images

Advert

Choose your content:

2 hours ago
4 hours ago
5 hours ago
  • YouTube/David McIntosh Jr
    2 hours ago

    Wee Man reveals the 'most disgusting' Jackass stunt that nearly made him throw up

    Even the toughest Jackass stars have a limit

    News
  • Kevin Carter/Getty Images
    2 hours ago

    Pilot shares screenshot of exactly how much they earn and people are gobsmacked

    It can vary by airline, but the salary is still very high

    News
  • Johnson's Zoo
    4 hours ago

    Family of boy, 3, thrown into crocodile enclosure issue heartbreaking health update as he undergoes multiple surgeries

    His parents opened up about the 'very uncertain and unsettling time' they are facing as a family

    News
  • Roberto Schmidt / AFP via Getty Images
    5 hours ago

    Chilling reason why FIFA wanted to reschedule England's World Cup clash with Mexico revealed

    The match is now going ahead at the original time, but there had been plans to reschedule it

    News
  • iPhone users furious after claims new iOS 26 update has 'ruined' key feature on phones
  • Warning for all iPhone users as tech experts urge everyone to update their devices
  • What happens if you don’t verify age in new iPhone update as Pornhub unrestricted for users
  • How iPhone users can delay new iOS 26.5 update to stop battery draining faster