Ryan Pettit, writing for Time back in July, tells a horrific tale of a device takeover set in motion by a spoofed text message and phone call:
On the afternoon of June 25, 2026, I learned what happens when the lock turns in a stranger’s hand. It began, as these things now do, with a text message. It looked entirely official: a fraud alert about a possible unauthorized charge on my Goldman Sachs Apple Card, the credit card tied to my Apple ID. The message asked only that I reply “yes” or “no” to confirm the transaction. This is a routine, familiar request, the kind your bank sends all the time. I replied no.
A few minutes later, my phone rang. The number, the FBI would later confirm, belonged to the genuine Apple Card support line. It had been spoofed so precisely that the messages accompanying the call arrived in the same gray bubbles, with the same Apple logo, that only real Apple support uses in iMessage. Everything my eyes could check told me this was Apple. The man on the line said he was going to send a code to verify my identity, and that I should read it back to him. It is a request that feels routine in the moment, though I now know that no legitimate institution should ever make it.
Pettit was locked out of his device, his eSIM was hijacked, and thousands of dollars were drained from his accounts. It’s a harrowing story, and must be read as a warning: Never, ever provide any information on a call you didn’t initiate—even when there’s seemingly good reason to trust its legitimacy. As Pettit says in his piece:
No legitimate bank is ever harmed by you hanging up and dialing the number on the back of your card, and none will ever ask you to read a verification code back to them. A criminal riding a spoofed line will. Make the call yourself, every time.
In an uncanny coincidence, a few days before I read this piece, I received a fraud notification from Apple, and separately, my (capable but technically unsophisticated) mother also got one about a questionable purchase on her Apple account.
In my case, Apple had flagged and denied several suspicious Apple Card transactions, then sent notifications via Apple Wallet and email asking if they were legitimate or not. The transactions were visible in Wallet, and responding required only a tap on each. The email contained details, also with instructions to take action in Wallet. (There was also a phone number at the end of the email—877–255–5923—which, if I’d chosen to call Apple, I would have looked up directly in Wallet or online. It’s correct.)
(Fortunately, these were legitimate charges from a recognized vendor who’d neglected to process several monthly payments, and chose to do so all at once. Multiple charges for the same amount over the span of a few minutes (rightly) triggered Apple’s fraud systems.)
In my mother’s case, it was a text message claiming unknown charges to her Apple account, with a number to call—which she did. This one was a scam attempt. The fraudster pretended to be from Apple and spent several minutes trying to get her to provide information about her account. Thankfully, she demurred, but only because, as she told the would-be scammer, she’d “have to talk to my son first, who manages these things.” Thank goodness for her presence of mind.
Back to Pettit’s less fortunate experience:
The reason a single text message could unspool an entire life is that the life hung on a single key. Everything I owned, and much of who I am, could be reached through one account, and once that account was gone, so was the ground under my feet.
The fix is not paranoia. It is diversification. No single credential should be able to open your phone, your money, your photographs, and your identity all at once. Assume the key will one day turn in a stranger’s hand, and build a life that can survive the moment it does.
Pettit’s premise, that a single key (an Apple ID, Google login, or phone number) can lead to compromise, is true as far as it goes, but is not the inherent flaw Pettit makes it out to be.
Pettit’s mistake wasn’t responding to the fraud alert or even answering the phone call (though I’m a big believer in “if it’s important they’ll leave a voicemail”). It was giving a verification code he received in a text message to a caller claiming to be Apple while on a call he didn’t initiate.
This is functionally the same as placing the key to your home in an expensive lockbox, then giving the combination to a caller claiming to be your college buddy.
Yes, the timing of the attack—fraud alert, phone call, verification code in rapid succession—is designed to short-circuit the logical brain and silence any skepticism. But this particular attack fails utterly if you treat all incoming calls as inherently suspicious.
As I read Pettit’s story, I kept asking myself questions not answered by the piece. Pettit is described as a “commercial airline pilot with a background in information technology,” but important technical details were either missing or subtly wrong (or at least confusingly told). I appreciate that many of those details may be elided for the sake of telling a compelling narrative, but I really wanted to understand the exact timing and sequence of the attack, and was left wanting.
To the best of my ability, based on what Pettit describes and how I understand the Apple ecosystem works, I think I’ve reconstructed how the attacker pulled this off. It’s not simple, but a practiced team of scammers can probably compromise the device in a few minutes and complete the takeover within an hour:
- Spoof Apple’s text and phone numbers to initiate contact with the victim. (Alternatively, exploit Apple’s own support structure.)
- Use Apple’s Forgot Password functionality to send a legitimate verification code while on the phone with the victim and convince them to share it. Remember: If you didn’t initiate the call, presume it’s fraud, hang up, and call Apple directly.
- Once the password is reset and the account is compromised, add a “Trusted Device” and a “Trusted Phone Number” to the victim’s account.
- Enable Messages in iCloud and Text Message Forwarding, which allows SMS messages to be sent to multiple devices on the account.
- Log into the victim’s cellular provider using an account saved to Apple Passwords. If the carrier issues an SMS verification challenge, the code arrives on the victim’s real iPhone and is forwarded to the attacker’s newly enrolled device.
- Request a replacement/transfer eSIM for a “new phone.”
- The carrier provisions a new eSIM with the victim’s number for the “new” phone and disables the old eSIM. The attacker can now get text messages directly.
- Restore from an iCloud backup. All apps and data are now accessible.
- Mark the old phone as “lost” and erase it.
At this point, the attacker is effectively the owner of the account. It’s devious and hard to protect against. Your first defense, again: never, ever share information on a call you didn’t initiate.
I can’t stress that enough. It doesn’t matter how legitimate it seems. If it’s a credit card, call the number on your card. If it’s a bank, visit the site directly (don’t do a search—assuming it’s a bank you do business with, you should know its domain name. Type it in directly). If it’s Apple (or Google or Meta or any other company where you have an account), visit their website, find their support number, and contact them directly. Don’t call a number, visit a website, or email an address given to you by the person who contacted you.
I’m relatively confident in my security posture, but Pettit’s experience, and those of my mother and me, have spurred me to further lock down my accounts. I already enable two-factor authentication and passkeys wherever possible. I’ve now enabled SIM Protection and Number Lock on all cellphones on our account. For my Apple Account, I added a second Trusted Phone Number to help recover my account in case of compromise. To help prevent compromise from happening in the first place, I’m adding a FIDO-compliant Security Key to my account, which replaces verification codes completely. I already use a YubiKey for secure access to other accounts, so this represents an extension of my security footprint.
(If you’re considering using Security Keys, YubiKeys are currently 20% off when you buy two through August 16, 2026—today, as I publish this. This is not an affiliate link. I get no benefit from any purchases.)
⚙︎