An underground market is supplying criminals with techniques to unlock stolen iPhones and launch phishing attacks against victims' contacts. The ecosystem targets bank accounts and sensitive data.
Thieves now have access to tools and methods that bypass iPhone security, enabling them to access device contents and impersonate owners through their contact lists.
Once unlocked, criminals send phishing messages to the victim's contacts, posing as the device owner to trick recipients into revealing banking credentials and personal information. This two-stage attack multiplies the damage beyond the initial theft.
The criminal ecosystem operates through forums and marketplaces where specialized services are traded. Some vendors offer device unlocking expertise, while others provide phishing templates or buyer lists compiled from previous victims.
Apple's security features have made this process more difficult than in previous years, but determined attackers continue finding workarounds. The vulnerability highlights the danger posed by physical device theft in today's interconnected digital environment.
Security experts recommend enabling two-factor authentication, marking devices as lost in iCloud immediately after theft, and warning contacts about potential phishing attempts.
A massive data breach at an unspecified car rental company exposed customer driver's licenses and personal information within hours of rental. The FBI is investigating the incident as data stolen from customers appears for sale online.
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin exposes WordPress sites to remote code execution and complete takeover by unauthenticated attackers.
An identity theft search site claimed to possess over 150 million driver's license photos stolen from a major ID verification service. The crime site has since been shut down.
Iran-linked hackers have compromised approximately 100 American water utilities in a sustained campaign targeting critical infrastructure. The EPA is allocating $11 million in funding to strengthen cybersecurity defenses across water systems.