Apple and Meta allegedly handed over data to hackers posing as law enforcement officers in mid-2021, with the two companies being duped by fake requests into providing information about users' IP addresses, phone numbers, and home addresses.
See also: Russian hackers target NATO networks and European military forces

Law enforcement officials often request data from social platforms as part of criminal investigations to obtain information about the owner of a specific online account. While these requests normally require a subpoena or search warrant signed by a judge, emergency requests do not and are reserved for cases involving life-threatening situations.
Fake emergency requests are becoming increasingly common, as explained in a recent report by Krebs on Security. During an attack, hackers must first gain access to a police department’s email systems. They are then able to forge an emergency data request that requests the requested data, while appearing to come from a law enforcement official. According to Krebs, some hackers are selling access to government emails over the internet, with the aim of targeting social platforms with fake emergency data requests.
The fake requests to Apple and Meta are believed to have been sent through hacked email domains belonging to law enforcement agencies in multiple countries. A person familiar with the matter told Bloomberg that the data obtained was used for harassment, while three sources said it may be used primarily for financial fraud schemes that bypass account security.
See also: Apple will not repair iPhones that have been reported lost or stolen

The majority of the malicious users carrying out these fake requests are actually teenagers. London police have since arrested seven teenagers in connection with the group.
However, last year's series of attacks may have been carried out by members of a cybercriminal group called Recursion Team. Although the group has since disbanded, some of them have joined Lapsus$ under different names.
Meta and Apple aren’t the only well-known companies to have fallen victim to fake emergency data requests. According to Bloomberg, hackers also contacted Snap via a fake request, but it’s unclear whether the company was fooled. Krebs on Security’s report also includes confirmation from Discord that the platform provided information in response to one of those fake requests.
See also: Meta's stock plunge pushes employees to look for work
“This tactic poses a significant threat to the entire technology industry,” said Peter Day, director of corporate communications for Discord Group. “We are continually investing in our trust and security capabilities to address emerging issues like this.”
