Search

Apple warns users to stay alert to FaceTime scams

Apple is urging users to be cautious of unexpected FaceTime calls, following a rise in scams where cybercriminals impersonate Apple Support.

According to KnowBe4, referencing reporting from Malwarebytes, scammers are contacting users via FaceTime and claiming there’s suspicious activity or a technical issue with their Apple account. Their aim is to create a sense of urgency, convincing victims to share sensitive information such as payment card details, online banking credentials or Apple ID login information.

Unlike many cyberattacks, these scams don’t rely on malware. Instead, they exploit something far more common: trust.

As Malwarebytes explains, “Nothing in this process requires malware on the device. The ‘exploit’ is human trust, backed by familiar names, logos, and a real-time call that feels inherently more legitimate than a text message.”

Social engineering remains one of the biggest cyber threats

FaceTime is becoming another channel for social engineering attacks because users naturally associate it with Apple’s trusted ecosystem. Criminals take advantage of this familiarity, making fraudulent calls appear more convincing than traditional phishing emails or text messages.

Malwarebytes also warns that attackers may combine these scams with vulnerabilities on unpatched Apple devices. While social engineering is used to steal usernames and passwords, software vulnerabilities can potentially allow attackers to execute malicious code, increasing the impact of an attack.

How to protect yourself

Apple recommends taking the following precautions:

  • Be wary of unsolicited FaceTime or phone calls claiming to be from Apple or Apple Support.
  • Never share passwords, Apple ID credentials, banking details or payment information during an unexpected call.
  • If you’re unsure whether a call is genuine, hang up and contact Apple directly using official support channels.
  • Keep your Apple devices updated with the latest security patches to help protect against known vulnerabilities.
  • Be cautious of callers creating a sense of urgency or pressuring you to act immediately.

Staying one step ahead

Cybercriminals are constantly evolving their tactics, and social engineering remains one of the most effective ways to gain access to sensitive information. Taking a moment to verify unexpected requests can make all the difference.

Source: This article is based on reporting from KnowBe4, referencing research and guidance published by Malwarebytes and Apple.