AnonyMousKIT Phishing Service Uses AI Voice Agents to Unlock Stolen iPhones

A phishing-as-a-service platform called AnonyMousKIT, active since early 2024, automates the process of retrieving Activation Lock unlock codes from stolen iPhones by using AI voice agents to impersonate Apple support staff, according to research from SOCRadar reported by BleepingComputer.

How the Scheme Works

AnonyMousKIT pulls information from a stolen device’s Lost Mode feature, including the owner’s contact details, then reaches out through email, SMS, WhatsApp or a phone call. The messages impersonate Apple and claim the missing device has been located, citing the correct model and IMEI details to make the outreach appear legitimate. When a victim engages by phone, a commercial voice AI agent built on the VAPI.ai platform takes over the call, running under a persona — researchers identified one named “Alice from Apple Support” speaking Portuguese — that asks the victim to confirm ownership by dictating their four- or six-digit device passcode before directing them to a fake Find My or Apple login page.

SOCRadar found the operation connected to 506 domains and 168 reseller storefronts, and recovered logs of roughly 200 calls made between August 2025 and May 2026 across 55 interaction transcripts, with call volume concentrated mostly in Brazil alongside activity in South Africa, Indonesia, Italy, India and Kenya. Each AI-driven call reportedly costs the operators only about $0.10.

The Stakes Extend Beyond a Single Stolen Phone

Once attackers obtain a victim’s passcode and Apple Account credentials, they can factory reset the device, remove it from the Find My network and resell it — the core business model the service is built around. But SOCRadar warns the exposure runs deeper than device resale: a compromised Apple ID can expose iCloud backups, Keychain-stored passwords, work email and other corporate data synced to the device, particularly on employer-issued phones enrolled in bring-your-own-device or corporate mobility programs.

The case adds to a growing pattern of cybercrime platforms integrating conversational AI to scale social-engineering operations that previously required human callers, following the earlier emergence of AI-driven voice phishing platforms such as ATHR, reported by Abnormal Security. For security teams, it underscores that mobile device management and lost-device response procedures now need to account for AI-generated voice impersonation as a credible, low-cost attack vector rather than a theoretical one.

Comments

One response to “AnonyMousKIT Phishing Service Uses AI Voice Agents to Unlock Stolen iPhones”

  1. […] LastPass tied the updates to IBM’s 2026 Cost of a Data Breach Report, which found AI-driven attacks rose 56% year over year and added roughly $1 million to average breach costs, with 92% of organizations hit by AI-related breaches lacking adequate AI access controls. The emphasis on visibility and credential hygiene mirrors a broader push across the industry to close the kind of access gaps that groups exploit in AI-assisted phishing and credential-theft campaigns. […]

Leave a Reply

Your email address will not be published. Required fields are marked *