everyday mac tools

Phishing that targets Mac users specifically

· 5 min read

Phishing aimed at Mac users concentrates on one target: the Apple Account. It holds purchases, photos, files, device locations and, through iCloud Keychain, potentially every other password you own.

That makes it worth more effort than most accounts, and the attempts are correspondingly good.

What the messages look like

A receipt for something you did not buy. An app, a subscription, an in-app purchase. There is a link to dispute it. The link is the attack; the receipt is the bait, and the emotional response it produces is the mechanism.

A security alert. Your account was accessed from an unfamiliar location. Verify now, or it will be locked.

iCloud storage full. Your photos will be deleted. Update your payment details.

Find My. Your lost device has been located. Sign in to see where. This one is nastier: it targets people who have actually lost a device and are anxious, and the credentials go straight to whoever has the phone so they can remove Activation Lock.

Apple support text messages, often after a device is stolen, for the same purpose.

The checks that work

Look at the sender address, not the display name. The display name is whatever the sender typed. Expand the actual address and look at the domain after the @. Apple’s mail comes from apple.com domains.

Hover the link before clicking. The destination appears at the bottom of the window, or on long-press on a phone. Look at the domain, and read it from the right: the part immediately before the first single slash is the real host. apple.com.secure-verify.example.net is not Apple.

Check for real receipts elsewhere. Genuine purchases appear in your account. Open the App Store, click your name, and look at Purchased. Or reportaproblem.apple.com, typed directly. If it is not there, the receipt is fake.

Note what it does not know. Genuine Apple mail usually addresses you by name and can reference the actual device. Generic greetings are a signal, though good attempts include your name too.

Beware urgency. Anything with a deadline is trying to stop you checking.

The one thing that makes all of this unnecessary

Never sign in from a link in a message.

Not because you cannot tell the difference, but because you do not have to. Open the app or type the address yourself. If your account genuinely needs attention, you will see it there.

That habit makes every phishing email harmless regardless of how convincing it is, and it costs nothing. All the checks above are for the cases where you want to know; this is the rule that protects you when you are tired and distracted, which is when people get caught.

Passkeys and why they help

A passkey cannot be phished in the way a password can. It is tied to the site it was created for, so a lookalike domain cannot use it: the browser simply will not offer it.

Where a service supports passkeys, using them removes this whole category of risk for that account. Passkeys on a Mac covers setting them up.

If you entered your details

Move quickly.

  1. Change your Apple Account password immediately, from a device you trust, at account.apple.com typed directly.
  2. Check trusted devices and phone numbers in Sign-In & Security. Remove anything you do not recognise, and confirm the numbers listed are yours.
  3. Check for a recovery contact or key you did not add.
  4. Change the password on the email account attached to it, which is the route back in for an attacker.
  5. Check your payment methods for anything unfamiliar.
  6. Forward the message to Apple at reportphishing@apple.com, then delete it.

If you also gave a verification code, treat the account as compromised and work through the same list urgently, since the code let them past two-factor.

Questions

Apple emailed me about a sign-in. Is it real? Possibly. Do not use the link. Open Settings on a device and look at the device list, or sign in at account.apple.com typed directly.

Can they get in with just my email address? No. They need the password and a second factor. Which is why the messages are designed to obtain both.

Why do I get these after losing a phone? Because the person who has it wants your credentials to remove Activation Lock. Never sign in from a message claiming to have found your device. Your Mac was stolen covers the right sequence.

Does Apple ever ask for my password by email? No. Nor by phone, nor by text.