Apple has issued a security advisory warning iPhone and iPad users about a surge in FaceTime-based social engineering attacks. Scammers spoof caller IDs to make incoming calls appear to come from trusted organizations such as Apple support or the victim’s bank, then pressure targets into handing over account credentials, security codes, and financial information.
According to Apple, the callers often bring up personal details like the victim’s home address, employer, or Social Security number early in the conversation to establish credibility. Once trust is built, the scammers push for urgency, warning that hanging up and calling back will not help since the fraud will continue in the meantime. This claim is false and exists only to keep the victim on the line.
Some scammers go further, asking victims to disable two-factor authentication or Stolen Device Protection, framing it as necessary to stop an ongoing attack. In reality, disabling those features is exactly what the scammer needs to complete the theft.
“Apple will never ask you to log in to any website, or to tap Accept in the two-factor authentication dialog, or to provide your password, device passcode, or two-factor authentication code,” the company stated. Apple urges users to report suspicious FaceTime calls by sending a screenshot to reportfacetimefraud@apple.com.