Apple users targeted by incredibly annoying 'Reset Password' attack

Those requests just keep on coming.
By Stan Schroeder  on 
Apple ID
If the hackers have your email and phone, that might be enough to initiate this attack. Credit: Apple

Some Apple users are reportedly being targeted by a sophisticated attack, requesting them to hand over their Apple ID credentials over and over again.

According to KrebsonSecurity, the attack starts with unsuspecting Apple device owners getting dozens of system-level messages, prompting them to reset their Apple ID password. If that fails, a person pretending to be an Apple employee will call the victim and try to convince them into handing over their password.

This is exactly what happened to entrepreneur Parth Patel, who described their experience on Twitter/X. First, all of Patel's Apple devices, including their iPhone, Watch, and MacBook, started displaying the "Reset Password" notifications. After Patel clicked "Don't Allow" to more than one hundred requests, the fake Apple Support called, spoofing the caller ID of Apple's official Apple Support line. The fraudster Apple employee actually knew a lot of Patel's real data, including email, address, and phone number, but they got their name wrong, which had confirmed Patel's suspicions that they were under attack.

While the attack was ultimately unsuccessful in this example, it's easy to imagine it working. The victim might accidentally allow the password reset (mistakes are easy to happen when you have to click on something hundreds of times), or they could fall for the fairly convincing, fake Apple Support call.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

Patel's example isn't isolated, either; KrebsonSecurity has details on a very similar attack that happened to a crypto hedge fund owner identified by his first name, Chris, as well as a security researcher identified as Ken. In Chris' example, the attack persisted for several days, and also ended with a fake Apple Support call.

How did the attackers know all the data needed to perform the attack, and how did they manage to send system-level alerts to the victims' phones? According to KrebsonSecurity, the hackers likely had to get a hold of the victim's email address and phone number, associated with their Apple ID. Then they used an Apple ID password reset form, that requires an email or phone number, alongside a CAPTCHA, to send the system-level, password reset prompts. They also likely used a website called PeopleDataLabs to get information on both the victim and Apple employees they impersonated.

But there could also be a bug in Apple's systems, which should in theory be designed not to allow someone to abuse the password reset form and send dozens of requests in a short period of time (Apple did not respond to KrebsonSecurity's request for comment).

It appears that there's no easy or foolproof way to protect oneself from such an attack at this time, save from changing one's Apple ID credentials and tying them to a new number and email. It's hard to tell how widespread this attack is, but Apple users should be vigilant and triple-check the authenticity of any password reset request, even if it appears to come from Apple itself.


For on spammers and scammers, check out Mashable's series Scammed, where we help you navigate a connected world that’s out for your money, your information, or just your attention.

Stan Schroeder
Stan Schroeder
Senior Editor

Stan is a Senior Editor at Mashable, where he has worked since 2007. He's got more battery-powered gadgets and band t-shirts than you. He writes about the next groundbreaking thing. Typically, this is a phone, a coin, or a car. His ultimate goal is to know something about everything.


Recommended For You
Google Password Manager now lets you share your passwords with family
Google logo

Apple to launch Passwords, a dedicated password manager, report claims
Apple WWDC

Move over LastPass! Apple announces new password manager at WWDC 2024
MacBook showing Passwords app

Replace your annoying Apple TV Remote with a $24 one with actual buttons
Apple tv remote

Apple issues yet another 'spyware' iPhone warning to users in nearly 100 countries
iPhone 15

More in Tech
How to watch USA vs. South Sudan at Paris 2024 online for free
Lebron James of Team United States

How to watch the women's 200m final at Paris 2024 online for free
Shericka Jackson shows off a gold medal

Switch to select Verizon mobile or internet plans, get free NFL Sunday Ticket
Six NFL football players in composite with large Verizon logo with yellow stripes in background

How to watch the artistic gymnastics men’s team final at Paris 2024 online for free
Athletes of Team United States enter the arena

How to watch Simone Biles at Paris 2024 online for free
Simone Biles competes in the floor exercise on Day Two of the 2024 U.S. Olympic Team Gymnastics Trials

Trending on Mashable

Wordle today: Here's the answer hints for July 31
a phone displaying Wordle

NYT Connections today: See hints and answers for July 31
A phone displaying the New York Times game 'Connections.'


NYT Strands hints, answers for July 31
A game being played on a smartphone.
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!