Apple fans deluged with phony password reset requests
(2024/03/27)
- Reference: 1711577169
- News link: https://www.theregister.co.uk/2024/03/27/apple_passcode_attack/
- Source link:
Apple device owners, consider yourselves warned: a targeted multi-factor authentication bombing campaign is under way, with the goal of exhausting iUsers into allowing an unwanted password reset.
First [1]called out on X/Twitter by AI entrepreneur Parth Patel – and [2]confirmed to be happening to others by security blogger Brian Krebs – the campaign appears to be targeting specific individuals, who are flooded with password reset requests. Because the alerts are sent at the system level, Patel reported, every single one had to be cleared before he could use his iPhone, Apple Watch, or MacBook.
Patel had to tap "Don't allow" on more than 100 notifications. Several of his friends – and other victims identified by Krebs – reported similar volumes.
[3]
The attack is similar to other [4]multi-factor fatigue attacks that have popped up over the years. They aim to exhaust users into mistakenly tapping to allow someone to change their password – or doing so to stop the deluge. Microsoft even [5]changed how its MFA codes work as a result of this kind of abuse.
[6]
[7]
Apple has yet to make such a change. Regardless, the attackers in this case were sophisticated enough to go beyond just spamming victims.
Around 15 minutes after clearing the notifications, Patel said he was called by someone spoofing their caller ID to pretend they were calling from Apple's actual support line. The caller informed Patel his account was under attack, and asked him to verify his information and provide a one-time reset code – ostensibly so the attacker could reset his password on their own. Being suspicious about the nature of the call, Patel asked them to verify some of his personal info, and the caller was able to – for the most part.
[8]
"They got a lot right, from date of birth, to email, to phone number, to current address, historic addresses," Patel reported. Luckily for Patel, he regularly checks to see what bits of his personal information are available online, and in this case it appears the data came from PeopleDataLabs – a B2B information firm.
"I distinctly remember [PeopleDataLabs] mixing me up with a midwestern elementary school teacher named Anthony S," Patel said, and that clued him in that the whole thing was a scam.
[9]Russia's Cozy Bear dives into cloud environments with a new bag of tricks
[10]Go ahead, forget that password. Use a passkey instead, says Google
[11]Russia's Cozy Bear caught phishing German politicos with phony dinner invites
[12]Google Workspace weaknesses allow plaintext password theft
The fact the scammer called Patel directly suggests they were able to send password reset requests using Apple's [13]iForgot page , which only asks for an email address and a solved CAPTCHA, in addition to knowing the account's phone number, to send a password reset request.
The sheer volume of requests raises the possibility that Apple may have a rate-limiting flaw in its iForgot system that allows for bombarding users with repeated reset requests. Apple didn't answer those questions, but did point us to a [14]support page for how to recognize scams and phishing attempts targeting its users.
Until Apple addresses the issue in some way, be careful tapping those alerts and ensure you never accidentally give a scammer what they want. If someone claiming to be from Apple support calls, take Apple's advice, which makes it clear: "If you get an unsolicited or suspicious phone call from someone claiming to be from Apple or Apple Support, just hang up." ®
Get our [15]Tech Resources
[1] https://twitter.com/parth220_/status/1771589793123836288
[2] https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZgSlB3sALGpD2vBc@zl8WQAAAAA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2022/11/03/mfa_fatigue_enterprise_threat/
[5] https://www.theregister.com/2023/05/09/microsoft_authenticator_number_matching/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgSlB3sALGpD2vBc@zl8WQAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZgSlB3sALGpD2vBc@zl8WQAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgSlB3sALGpD2vBc@zl8WQAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2024/02/27/russia_cozy_bear_new_ttps/
[10] https://www.theregister.com/2023/05/04/google_passkey/
[11] https://www.theregister.com/2024/03/23/russia_cozy_bear_german_politicians_phishing/
[12] https://www.theregister.com/2023/11/15/google_workspace_weaknesses_allow_plaintext/
[13] https://iforgot.apple.com
[14] https://support.apple.com/en-us/102568
[15] https://whitepapers.theregister.com/
First [1]called out on X/Twitter by AI entrepreneur Parth Patel – and [2]confirmed to be happening to others by security blogger Brian Krebs – the campaign appears to be targeting specific individuals, who are flooded with password reset requests. Because the alerts are sent at the system level, Patel reported, every single one had to be cleared before he could use his iPhone, Apple Watch, or MacBook.
Patel had to tap "Don't allow" on more than 100 notifications. Several of his friends – and other victims identified by Krebs – reported similar volumes.
[3]
The attack is similar to other [4]multi-factor fatigue attacks that have popped up over the years. They aim to exhaust users into mistakenly tapping to allow someone to change their password – or doing so to stop the deluge. Microsoft even [5]changed how its MFA codes work as a result of this kind of abuse.
[6]
[7]
Apple has yet to make such a change. Regardless, the attackers in this case were sophisticated enough to go beyond just spamming victims.
Around 15 minutes after clearing the notifications, Patel said he was called by someone spoofing their caller ID to pretend they were calling from Apple's actual support line. The caller informed Patel his account was under attack, and asked him to verify his information and provide a one-time reset code – ostensibly so the attacker could reset his password on their own. Being suspicious about the nature of the call, Patel asked them to verify some of his personal info, and the caller was able to – for the most part.
[8]
"They got a lot right, from date of birth, to email, to phone number, to current address, historic addresses," Patel reported. Luckily for Patel, he regularly checks to see what bits of his personal information are available online, and in this case it appears the data came from PeopleDataLabs – a B2B information firm.
"I distinctly remember [PeopleDataLabs] mixing me up with a midwestern elementary school teacher named Anthony S," Patel said, and that clued him in that the whole thing was a scam.
[9]Russia's Cozy Bear dives into cloud environments with a new bag of tricks
[10]Go ahead, forget that password. Use a passkey instead, says Google
[11]Russia's Cozy Bear caught phishing German politicos with phony dinner invites
[12]Google Workspace weaknesses allow plaintext password theft
The fact the scammer called Patel directly suggests they were able to send password reset requests using Apple's [13]iForgot page , which only asks for an email address and a solved CAPTCHA, in addition to knowing the account's phone number, to send a password reset request.
The sheer volume of requests raises the possibility that Apple may have a rate-limiting flaw in its iForgot system that allows for bombarding users with repeated reset requests. Apple didn't answer those questions, but did point us to a [14]support page for how to recognize scams and phishing attempts targeting its users.
Until Apple addresses the issue in some way, be careful tapping those alerts and ensure you never accidentally give a scammer what they want. If someone claiming to be from Apple support calls, take Apple's advice, which makes it clear: "If you get an unsolicited or suspicious phone call from someone claiming to be from Apple or Apple Support, just hang up." ®
Get our [15]Tech Resources
[1] https://twitter.com/parth220_/status/1771589793123836288
[2] https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZgSlB3sALGpD2vBc@zl8WQAAAAA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2022/11/03/mfa_fatigue_enterprise_threat/
[5] https://www.theregister.com/2023/05/09/microsoft_authenticator_number_matching/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgSlB3sALGpD2vBc@zl8WQAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZgSlB3sALGpD2vBc@zl8WQAAAAA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgSlB3sALGpD2vBc@zl8WQAAAAA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2024/02/27/russia_cozy_bear_new_ttps/
[10] https://www.theregister.com/2023/05/04/google_passkey/
[11] https://www.theregister.com/2024/03/23/russia_cozy_bear_german_politicians_phishing/
[12] https://www.theregister.com/2023/11/15/google_workspace_weaknesses_allow_plaintext/
[13] https://iforgot.apple.com
[14] https://support.apple.com/en-us/102568
[15] https://whitepapers.theregister.com/
ecofeco
I see bad UX design everywhere.
It is out of control.
Apple still has atrocious user interfaces for such things. I manage school deployments, and there were some real doozies before they got wise to proper enrolment and forced everyone to Apple School Manager (which means buying iPads brand-new at full price, no choice) many years later.
There was a point where I took over a batch of pre-purchased iPads that had had an app installed as a previous user, and then the iTunes account was changed. Whenever that app updated, it would decide to reprompt for the (long gone) user's iTunes password to update the app.
'
Again - system level, unskippable, recurring, the only thing to do was to concede and take over that account and sign in repeatedly to clear the warnings until we could wipe all the iPads on site (several hundred).
Then there's their setup dialog which used to let you set up an iTunes account on a new iPad without entering a credit card number... at first it was literally a click, then they got increasing obfuscated and would only allow you to select the option the first time on that iPad and not ever again, and then it became a running battle of stupendous workarounds where you had to cancel the "Sign in with iTunes" dialog some 50+ times to get into the iPad, change the setting to a particular account that had been set up with no credit card, and then you were able to sort things out. But to get there - system-modal dialogs every few seconds, that take an age to clear and then you had to quickly progress a tiny amount to get into the settings dialogs in between more system-model dialogs, etc. etc. etc.
After setting up 200 iPads that way, I banned iPad purchases from the site and they've not added one in 10 years. And that was one of the least of the issues we had with Apple.
Everyone tells me that Apple products/software are so expensive and different because of the superior "design", and I have yet to find a single design feature in any Apple device, hardware or software, that I actually even like, let alone prefer. Some of their design is fecking atrocious.
But, hey, I hear the next iOS will allow you to MOVE ICONS AROUND wherever you want (so long as you want them in a grid still, because we can't let you have too much control, but at least now they won't form a linear arrangement where you can have NO GAPS because Apple said no all those years).