A new, highly sophisticated phishing is underway targeting Apple Pay. Cybercriminals are using deceptive emails and phone callsto try to steal sensitive financial information, passwords, and payment data.
This threat stands out because it does not rely solely on malicious links or fake websites, but mainly uses a more insidious technique: the so-called “vishing”, i.e. voice phishing via telephone communication.
The email that seems... too real
The attack usually begins with a legitimate-looking email message. The email includes the official Apple logo, professional formatting, and a layout that resembles real purchase receipts or payment notifications.
See also: German agencies warn about phishing via Signal

The subject line is designed to cause panic: it warns the recipient about a supposed high-amount charge, which was supposedly "frozen" at an Apple Store to prevent financial loss.
The content of the message contains convincing details, such as a case number, timestamp, and strict warnings that the account is at risk.
In many cases, the email even states that an “appointment” has already been scheduled for the user to look into the suspicious activity.
The phone number trap
The most dangerous element is not a link, but the phone number provided for “immediate support.” The message urges the victim to call immediately, especially if the scheduled “appointment” time is not convenient.
The email's formatting mimics purchase receipts, such as a fake MacBook Air 2025 order, making the scam extremely convincing and difficult for unsuspecting users.
See also: Odyssey Stealer: New malware campaign targets Mac computers

Malwarebytes: The scam is based on vishing
Malwarebytes analysts were among the first to spot the campaign, noting that the perpetrators intentionally avoid malicious links. Instead, they seek to lead the victim into a phone conversation , where they can exert greater psychological pressure .
The ultimate goal is clear: stealing logins and payment information, taking advantage of the trust users have in the Apple brand.
What can happen if the fraud succeeds?
The impact of a successful attack is particularly severe. If attackers gain access to a user's Apple ID, they can control:
- photos and files stored in iCloud
- personal data and contacts
- linked credit or debit cards
- access to Apple Pay and App Store services
Essentially, it is a takeover digital identity.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
How fake "Apple support" works
When the victim calls the number, a “representative” introduces himself as a member of Apple’s fraud department. The conversation starts off calmly, with innocuous questions, such as the last four digits of the phone number.

The scammer then explains that the system has "partially blocked" a transaction and needs confirmation to secure the account.
See also: 'DKnife': New malicious framework for AitM attacks
The critical trap is the request for the two-factor authentication (2FA) code. At that moment, the criminal attempts to log into the account in real time.
In fact, it may claim that "someone is in a physical store and trying to use your card," increasing panic.

Apple Pay phishing: How to protect yourself from such scams
Users should remember that Apple does not schedule appointments for fraud cases via email and never asks for 2FA codes or passwords over.
For greater security:
- Always check the sender address (it is not an official Apple domain)
- Never share verification codes
- Change your Apple ID password immediately if you suspect fraud
- Log out of all active devices
- Track your bank transactions for weeks
This particular campaign shows that attacks are becoming more "human" and convincing. Information and composure are the most powerful weapons against cybercriminals.
