Skip to content

Companies

Apple scams: how the fake messages work

Apple brand impersonation scams involve fraudsters posing as Apple Support or security representatives via phishing emails, fake App Store receipts, SMS texts, and spoofed phone calls to claim your iCloud or Apple Account has been compromised. Scammers utilize urgent warnings and fake security alerts to trick victims into surrendering Apple ID credentials, passwords, two-factor authentication codes, or financial information, or granting remote computer access.

Last reviewed: August 9, 2026  ·  Drafted with AI assistance. Every figure on this page was checked against the source cited for it. Not yet reviewed by a human editor.

ScamPreventionGuide is an independent consumer-protection resource. We are not affiliated with, endorsed by, or sponsored by Apple. Company names and trademarks are the property of their respective owners and are used here only to identify the companies that scammers impersonate.

01

Is the Apple message real?

How the brand actually contacts customers (sender domains, whether they call, whether they SMS, whether they ever ask for payment or remote access): Apple genuine emails originate from Apple domains (such as @apple.com). Apple does not initiate unsolicited phone calls or SMS text messages regarding compromised Apple Accounts, iCloud security breaches, or unauthorized App Store/iTunes charges. Apple customer support representatives will never ask for your Apple Account password, device passcode, two-factor authentication verification code, or request that you enter credentials on a website directed by support. Apple never asks customers to disable security features (such as two-factor authentication or Stolen Device Protection) or to make payments using gift cards or wire transfers.

According to Federal Trade Commission data published in June 2026, consumers reported losing a staggering $3.5 billion to imposter scams in 2025, with reported fraud losses increasing nearly three times since 2020 ( Source: FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025.

02

Which versions are in circulation?

The versions in circulation, and what each one is after:

VersionHow it reaches youWhat it wants
Compromised Apple ID / Locked Account PhishingEmailHarvest Apple ID credentials, passwords, and two-factor authentication codes to hijack user accounts and device backups.
Phishing App Store / iTunes Fake ReceiptEmailCapture payment card numbers, billing addresses, Social Security numbers, and login credentials via phishing landing pages.
Spoofed Apple Support Phone Call (Tech Support Scam)Phone / VoiceScare the victim into granting remote access to their computer, purchasing gift cards, or wiring money to "protect" funds.
Fake Security Alert Browser Pop-UpPop-upTrick the victim into downloading malicious software, installing unauthorized configuration profiles, or paying for fake tech support.
Malicious Calendar Event / Subscription SpamCalendar / MailLure victims to phishing or malware download websites to steal personal data or install intrusive calendar configurations.
Spoofed FaceTime Fraud CallSocial / VideoEstablish false trust and manipulate the victim into revealing financial credentials, authentication codes, or authorizing fraudulent wire transfers.
03

What do the fake messages actually say?

We are not quoting example wording on this page. On 16 August 2026 we checked the quoted messages against the sources they were credited to, and the sources did not contain them — so the quotes were removed rather than reworded. We would rather show you nothing than show you an invented example of a real crime.

The exact wording changes constantly anyway. What does not change is the shape: a message you did not ask for, about a problem you cannot verify, with a link or a phone number supplied for you to use. Do not use either — reach the company the way you normally would.

04

How can you tell a real message from a fake one?

The differences you can check yourself:

  • The genuine Apple email or SMS comes strictly from official Apple domains (such as @apple.com), whereas fake messages originate from generic webmail addresses or lookalike domains (e.g., @apple-support-auth.com).
  • Genuine Apple Store and App Store purchase receipts always display your current billing address on file, whereas fraudulent receipts omit billing addresses or display incorrect placeholder information.
  • Scammers demand immediate action within 24 hours or threaten immediate account termination and legal action, whereas legitimate Apple support channels never threaten users or create panic to force compliance.
  • Fraudsters instruct you to enter your Apple ID password, device passcode, or two-factor authentication verification code into a website link, whereas Apple support will never ask for your password or verification codes.
  • Scammers instruct you to turn off Two-Factor Authentication or Stolen Device Protection under the guise of fixing a glitch, whereas Apple never asks users to lower their security protections.
  • Imposters demand payment using Apple Gift Cards, cryptocurrency, or wire transfers, whereas Apple never accepts gift cards or wire transfers for service fees or account restoration.
05

What should you do in the first hour?

It depends on how far it got. Find your situation:

  • Immediately hang up the phone call or close the browser tab/window displaying the fake alert.
  • Do not click any further links and do not reply to suspicious emails or text messages.
  • Forward suspicious emails or screenshots of texts to reportphishing@apple.com (
  • If you gave information (credentials, passwords, or personal details):
  • Immediately change your Apple Account password by navigating directly to Settings on your trusted Apple device or visiting https://account.apple.com (
06

Where do you report it?

Phishing and suspicious message/email reports: reportphishing@apple.com (for emails and screenshots of text messages); FaceTime fraud: reportfacetimefraud@apple.com; iCloud spam/abuse: abuse@icloud.com; Federal Trade Commission (U.S.): https://reportfraud.ftc.gov · June 15, 2026 · 2026.

Whatever the brand, two official channels take the report. File with the US Federal Trade Commission at reportfraud.ftc.gov, and — if money was lost or a computer was accessed — with the FBI's Internet Crime Complaint Center at ic3.gov. Reporting rarely recovers money on its own; it is what makes the next person's warning possible.

07