A phishing-as-a-service operation called AnonyMousKIT is automating attempts to obtain the codes and credentials needed to unlock stolen Apple devices, according to BleepingComputer, citing research from threat-intelligence firm SOCRadar. The service targets Apple’s Activation Lock protection, which ties an iPhone to the owner’s Apple Account when Find My is enabled. BleepingComputer reports that AnonyMousKIT has been active since early 2024 and supports a broader stolen-device economy. SOCRadar found links to 506 domains and 168 storefront brands acting as resellers, according to the report. The operation is described as supporting the sale of stolen iPhones, the harvesting of Apple IDs, and attempts to reach iCloud backups and Keychain credentials. The mechanism starts with information already available from the stolen device. BleepingComputer says AnonyMousKIT can use owner contact details supplied through Lost Mode, then reach the victim by email, SMS, WhatsApp, or phone call. The messages impersonate Apple, claim the missing device has been found, and include details such as the model and International Mobile Equipment Identity number to make the lure appear more credible. Victims are then directed to fake Find My or Apple pages and prompted to enter a device passcode, Apple Account credentials, and two-factor authentication code, according to the report. In some cases reviewed by SOCRadar, a voice AI agent using an “Alice from Apple Support” persona told victims that someone had brought the phone to an Apple store while trying to unlock it. The agent then asked the owner to confirm ownership by dictating the passcode before sending them to the phishing page. SOCRadar recovered records of 200 calls to victims between August 2025 and May 2026, BleepingComputer reports. Those calls used 55 distinct interaction transcripts and were handled by a voice AI agent operating under five personas. SOCRadar also said the calls cost the operator about $0.10 per attempt, and that 90% of the calls were made to Brazil. The target is the economic value locked inside and around a stolen iPhone. Apple’s Activation Lock remains in place even after a factory reset, requiring valid authorization during setup before the device can be used. BleepingComputer notes that many stolen iPhones are otherwise sold for parts, while their value rises if attackers can unlock them and recover owner data. Once attackers obtain the relevant codes, BleepingComputer reports, they can access the victim’s personal data, factory-reset the phone, and remove it from the Find My app before resale. SOCRadar warned that a compromised Apple ID could also expose iCloud backups, Keychain passwords, work email, and other corporate information stored on personal or employer-issued Apple devices. The campaign is described as global, with concentrations in South Africa, Indonesia, Italy, India, Kenya, and Brazil. SOCRadar also found that a small percentage of emails from the platform were sent to government and corporate organizations, according to BleepingComputer. Who benefits: Stolen-device resellers and phishing operators benefit if they can convert locked iPhones from parts inventory into usable devices. The reported use of low-cost voice AI calls also reduces the cost of scaling social-engineering attempts. Who's exposed: Owners of stolen Apple devices are directly exposed, especially if they respond to messages claiming the device has been found. Organizations may also be exposed when employees use personal or employer-issued Apple devices that contain work email or credentials.