Abuse of Apple Account Change Notifications to Deliver Callback Phishing from appleid@id.apple.com (Operation iPhone Purchase Scam, April 2026) — Threadlinqs Intelligence
As of 2026-05-30, Abuse of Apple Account Change Notifications to Deliver Callback Phishing from appleid@id.apple.com (Operation iPhone Purchase Scam, April 2026) is a high-severity phishing threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-0393 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: N/A · FINANCIAL
Threat actors are weaponizing Apple's legitimate Apple Account change notification system to deliver callback phishing (TOAD) lures from appleid@id.apple.com. By embedding a fake $899 iPhone/PayPal
In April 2026, BleepingComputer reported and independently reproduced an active phishing campaign in which threat actors abuse Apple's transactional 'Apple Account change' notification system to deliver callback phishing (Telephone-Oriented Attack Delivery, TOAD) lures inside fully legitimate, authenticated email messages sent from Apple's own infrastructure. Because the messages originate from appleid@id.apple.com, are sent through Apple's outbound relay outbound.mr.icloud.com from Apple-owned IP 17.111.110.47, and pass SPF, DKIM (header.d=id.apple.com), and DMARC authentication checks, most secure email gateways (SEG), O365/Exchange Online Protection, Google Workspace Gmail filters, and Proofpoint/Mimecast/Abnormal solutions treat the message as trustworthy and deliver it directly to the user's inbox.
The abuse chain is simple and requires only a free Apple ID: (1) The attacker registers or hijacks an Apple ID using a disposable iCloud address (observed example: hxfedna24005@icloud.com); (2) the attacker inserts their callback phishing content into the account's 'First name' and 'Last name' personal information fields, splitting the message across both because neither field accepts the full payload in isolation (observed lure text: 'Dear User 899 USD iPhone Purchase Via Pay-Pal To Cancel 18023530761'); (3) the attacker modifies the shipping address on the account, which causes Apple to automatically generate and send an 'account information update' security notice; (4) because Apple's template renders the attacker-controlled first/last name fields verbatim into the email body, the phishing payload is delivered inside a legitimate-looking Apple security alert; (5) the email is sent first to the attacker's own Apple ID inbox, but header analysis (rn2-txn-msbadger01107.apple.com -> outbound.mr.icloud.com) shows the final delivery address is a distributed list of targets, indicating the attacker uses a mailing list or forwarding to fan the single Apple-originated notification out to many victims. The original recipient field (the attacker-owned iCloud address) is preserved inside the message, which reinforces the social engineering lure because the victim sees an unfamiliar iCloud address and believes their account has been taken over.
The lure itself is a callback/TOAD scam: victims are instructed to call the embedded number (18023530761 observed) to dispute a fraudulent $899 iPhone/PayPal purchase. A live human on the other end of the call, typically operating from a call center, walks the victim through installing remote access software (AnyDesk, TeamViewer, ScreenConnect, UltraViewer), through which the attacker drains bank accounts, captures MFA codes, installs persistence/RMM malware, and/or extracts further PII. The pattern mirrors prior 2024-2026 callback phishing campaigns observed from PayPal, Geek Squad, and Norton/McAfee scams, and it is a direct evolution of earlier 2022 and 2025 abuse of iCloud Calendar invitations and Apple Event RSVPs that likewise exploited Apple's trusted sending infrastructure. The same trust abuse primitive has been observed in Microsoft Azure Monitor alert abuse and Google Drive/Docs share-notification abuse — all rely on the premise that content user-controllable at the source will be rendered verbatim into an outbound notification signed by a trusted brand.
Impact is significant because (a) Apple's sending IP reputation is effectively unblockable for any organization whose users have personal Apple IDs, (b) SEG content filters struggle to distinguish legitimate Apple notifications from abusive ones when the only difference is a few tokens inside the name fields, and (c) the lure exploits the strongest possible authority/urgency signal (unauthorized account change alert + unauthorized $899 purchase). BleepingComputer reported the abuse to Apple on Friday, 2026-04-18, and at time of publication received no response; abuse remains possible. Defenders should add detection logic that parses
Weaknesses (CWE)
CWE-20, CWE-79, CWE-451, CWE-290
Target sectors: consumer, technology, financial, healthcare, government, education, retail
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1585, T1587, T1588, T1589, T1598, T1598, T1566, T1566