← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

AnonyMousKIT PhaaS uses AI voice agents to phish iPhone passcodes and disable Activation Lock

🔄 Updated 37d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • AnonyMousKIT is a PhaaS platform active since early 2024.
  • It uses AI voice agents to phish iPhone passcodes from victims.
  • The service is linked to 506 domains and 168 reseller storefronts.
  • It helps unlock stolen iPhones and access sensitive user data.
  • AnonyMousKIT uses rented AI voice agents.
  • The platform is credit-metered.
  • AnonyMousKIT drives lures across five channels from a single victim record.
  • Email costs 1.50 credits, recorded voice call 1 credit, and AI voice agent 2 credits.
  • The platform asks for 4- or 6-digit device passcode, Apple ID credentials, and 2FA code.
  • Apple never asks for a password, device passcode, or 2FA code for support.
  • AnonyMousKIT is a software business with a criminal customer base.
  • It features credit bundles, pricing, tiered subscriptions, customer support, status tracking, and infrastructure replacement.

AnonyMousKIT: A New Phishing-as-a-Service Platform

AnonyMousKIT is a newly identified phishing-as-a-service (PhaaS) platform that automates the process of obtaining codes to unlock stolen Apple devices and bypass the Activation Lock feature. This platform has been operational since early 2024 and supports a structured criminal network involved in selling stolen iPhones, collecting Apple IDs, and accessing iCloud backups and Keychain credentials.

Operational Scale and Methodology

Researchers at SOCRadar uncovered details about AnonyMousKIT's operations, identifying its connection to 506 domains and 168 reseller storefronts. The platform utilizes AI voice agents to conduct phishing calls, with SOCRadar recovering records of 200 calls made to victims between August 2025 and May 2026. These calls used 55 distinct interaction transcripts and five different AI agent personas, costing approximately $0.10 per attempt, with 90% of calls directed to Brazil.

Bypassing Apple's Activation Lock

Apple's Activation Lock automatically links an iPhone to its owner's Apple Account when Find My is enabled, preventing unauthorized use even after a factory reset. AnonyMousKIT circumvents this by retrieving owner contact information via the Lost Mode feature and sending phishing messages through email, SMS, WhatsApp, or phone calls. These messages impersonate Apple, providing accurate device details to appear legitimate, and direct victims to fake Apple pages to input their passcodes, Apple Account credentials, and two-factor authentication codes. In some cases, AI agents, such as one posing as 'Alice from Apple Support,' directly ask victims to dictate their passcodes.

Updates

🕒 2026-08-26 · new reporting from The Hacker News
  • AnonyMousKIT uses rented AI voice agents.
  • The platform is credit-metered.
  • AnonyMousKIT drives lures across five channels from a single victim record.
  • Email costs 1.50 credits, recorded voice call 1 credit, and AI voice agent 2 credits.
  • The platform asks for 4- or 6-digit device passcode, Apple ID credentials, and 2FA code.
  • Apple never asks for a password, device passcode, or 2FA code for support.
  • AnonyMousKIT is a software business with a criminal customer base.
  • It features credit bundles, pricing, tiered subscriptions, customer support, status tracking, and infrastructure replacement.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A phishing-as-a-service (PhaaS) platform named AnonyMousKIT is using rented AI voice agents to impersonate Apple Support and trick owners of stolen devices into revealing passcodes and 2FA codes. This platform aims to bypass Apple's Activation Lock, enabling the resale of stolen hardware, and represents an evolution in phishing tactics by integrating AI voice technology.

A new phishing-as-a-service (PhaaS) platform named AnonyMousKIT automates the retrieval of iPhone passcodes and disables Apple's Activation Lock feature. This service facilitates a criminal ecosystem for selling stolen iPhones, harvesting Apple IDs, and accessing iCloud backups and Keychain credentials.