🍪 Privacy & Transparency

We and our partners use cookies to Store and/or access information on a device. We and our partners use data for Personalised ads and content, ad and content measurement, audience insights and product development. An example of data being processed may be a unique identifier stored in a cookie. Some of our partners may process your data as a part of their legitimate business interest without asking for consent. To view the purposes they believe they have legitimate interest for, or to object to this data processing use the vendor list link below. The consent submitted will only be used for data processing originating from this website. If you would like to change your settings or withdraw consent at any time, the link to do so is in our privacy policy accessible from our home page..

Vendor List | Privacy Policy
Ask Dave Taylor
  • Facebook
  • Instagram
  • Linkedin
  • Pinterest
  • Twitter
  • YouTube
  • Home
  • YouTube Videos
  • Top Categories
  • Subscribe via Email
  • Ask A Question
  • Meet Dave
  • Home
  • Computer & Internet Basics
  • Beware the latest Apple ID phishing attack?

Beware the latest Apple ID phishing attack?

September 4, 2015 / Dave Taylor / Computer & Internet Basics, Spam, Scams & Security / 1 Comment

Did you get an email from Apple saying that your Apple ID was used to open an iCloud session from an unauthorized device? Beware, it’s probably a phishing attack from someone trying to steal your account information. Here’s how to tell…

If Sherlock Holmes were alive today, he’d be a great person to have go through your email inbox and spam folder to ascertain which messages are legitimate and which are spam, scams, malware or phishing attacks. For the rest of us, a close examination for tiny clues is all we have to protect ourselves from third party sites poised to cause trouble or even steal your personal information.

A great example is an email I received this evening from Apple stating that my credit card had been declined as part of someone using my Apple ID to open an unauthorized iCloud session. What? Maybe it’s legit, I mean I connect new devices to my Windows, Google, and Apple accounts all the time as devices come in and need to be tested.

But before I click on any link in any email, I put on my deerstalker cap and pull out my pipe. It’s time to have a close look…

To start, here’s the email:

apple id phishing attack email message

Looks legit on first glance, but a few things pop out, including two typos. Can you find them?

The first is “anauthorized” and the second is “autorisation”, in case you’re stuck.

Look at the very bottom too:

small print on phishing email apple id

I’m based in the United States, why would I get an email from Luxembourg with this information?

Highly suspicious.

Where the phishing attempt really reveals, however, is by looking at where the “Verify now” link points. This can easily be done in Apple Mail by putting the cursor over the link and then waiting a second or two:

phishing link in bogus email apple id

I’m quite confident that Apple Computer wouldn’t use nexuswholesalemarketing.com for its logins and verification process. Agreed?

Still, let’s keep looking. Check out the actual email address:

bogus email address used for phishing

Again, Apple’s not going to be sending email from @login.com in my opinion!

Worst case, you click through to “Verify” your Apple ID. What happens? Here, this is what you get:

bogus web site trying to steal phish scam rip off your Apple ID

Look really closely. One of my favorite typos shows up here.

What does the blue button say?

“Sing in”.

Ready to do that? Turn on that mic, let’s click on the button (after having entered any combination of words because of course the site doesn’t check login data to verify it) and see where we get…

your apple id has been disabled for security reasons phishing bogus

It’s rather confusing at this point what actually transpired to get to this point, isn’t it? Did someone add or change an email? Did someone sign in to iCloud with a bad credit card? What’s going on here?? 🙂

What’s for sure is that this is a big, bogus, and poorly executed phishing attack that could still trick people into revealing information that would let someone else hijack their account. And that’s bad.

So my advice remains: be vigilant, suspicious and skeptical. Because that’s all that’s between you and having bad guys steal your data or take over your computer or even identity.

Oh, and to leave things on a positive note, there is this set of options for resetting your security question that I found quite amusing:

weird security questions

No idea where that came from, but if you get to this point, it’s already too late. 🙂

Actually it’s not. If you ever get to a highly suspicious page like this, immediately quit your browser, restart, and log in to the real Apple site by typing in its URL. Then change your password.

About the Author: Dave Taylor has been involved with the online world since the early days of the Internet. Author of over 20 technical books, he runs the popular AskDaveTaylor.com tech help site. You can also find his gadget reviews on YouTube and chat with him on Twitter as @DaveTaylor.

Let’s Stay In Touch!

Never miss a single article, review or tutorial here on AskDaveTaylor, sign up for my fun weekly newsletter!
Name: 
Your email address:*
Please enter all required fields
Correct invalid entries
No spam, ever. Promise. Powered by FeedBlitz
Please choose a color:
Starbucks coffee cup I do have a lot to say, and questions of my own for that matter, but first I'd like to say thank you, Dave, for all your helpful information by buying you a cup of coffee!
apple id, apple phishing attack, iCloud account, identity theft, phishing attack

One comment on “Beware the latest Apple ID phishing attack?”

  1. Fred Milenovich says:
    September 10, 2015 at 5:16 am

    Another clue: grammatical mistakes, as in “and remove limit from your account Apple account” instead of “and remove THE limit from your Apple account”. Usually a very good clue if present. Your clues all excellent.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

Recent Posts

  • How to Check Out eBooks from the Library on a Kobo eReader
  • How Do I Delete Apps from my Chromebook?
  • Cool Ways to Shop for a Book with your Android Phone
  • How Can I Have My MacBook Stop Auto-Connecting to xfinitywifi?
  • How to Copy a DVD onto Your Windows PC with WinXDVD Ripper

On Our YouTube Channel

Which Is Better? EMEET HS20 vs LOGITECH H390 - Computer Headset Challenge

Mitchell Acoustics TT2 Phonograph Turntable -- DEMO & REVIEW

Categories

  • AdSense, AdWords, and PPC Help (106)
  • Alexa, Kindle, and Nook Help (102)
  • Amazon, eBay, and Online Shopping Help (166)
  • Android Help (235)
  • Apple iPad Help (151)
  • Apple Watch & Smartwatch Help (55)
  • Articles, Tutorials, and Reviews (346)
  • Auto Tech Help (20)
  • Business Advice (201)
  • Chromebook & ChromeOS Help (41)
  • Computer & Internet Basics (791)
  • d) None of the Above (166)
  • Facebook Help (385)
  • Google, Chrome & Gmail Help (193)
  • HTML & Web Page Design (248)
  • Instagram Help (49)
  • iPhone & iOS Help (634)
  • iPod & MP3 Player Help (173)
  • LinkedIn Help (90)
  • Linux Help (178)
  • Linux Shell Script Programming (90)
  • Mac & MacOS Help (922)
  • Most Popular (16)
  • Outlook & Office 365 Help (35)
  • PayPal Help (68)
  • Pinterest Help (54)
  • Reddit Help (21)
  • SEO & Marketing (82)
  • Spam, Scams & Security (100)
  • Trade Show News & Updates (23)
  • Twitter Help (225)
  • Video Game Tips (66)
  • Web Site Traffic Tips (62)
  • Windows PC Help (966)
  • Wordpress Help (206)
  • Writing and Publishing (72)
  • YouTube Help (47)
  • YouTube Video Reviews (159)
  • Zoom, Skype & Video Chat Help (65)

Archives

Social Connections:

Ask Dave Taylor


Follow Me on Pinterest
Follow me on Twitter
Follow me on LinkedIn
Follow me on Instagram


AskDaveTaylor on Facebook



microsoft insider mvp


This web site is for the purpose of disseminating information for educational purposes, free of charge, for the benefit of all visitors. We take great care to provide quality information. However, we do not guarantee, and accept no legal liability whatsoever arising from or connected to, the accuracy, reliability, currency or completeness of any material contained on this site or on any linked site. Further, please note that by submitting a question or comment you're agreeing to our terms of service, which are: you relinquish any subsequent rights of ownership to your material by submitting it on this site. Our lawyer says "Thanks for your cooperation."
© 2023 by Dave Taylor. "Ask Dave Taylor®" is a registered trademark of Intuitive Systems, LLC.
Privacy Policy - Terms and Conditions - Accessibility Policy