Scammers Pose as Employers to Remotely Lock iPhones and Demand Ransom
Russian law enforcement has identified a new fraud campaign in which scammers impersonate employers to seize control of Apple devices belonging to job seekers.
According to Vladimir Vasenin, head of the press service of the Moscow Main Directorate of the Ministry of Internal Affairs, the attackers first offer the victim employment. They then request that the individual sign out of their personal Apple account and sign in using credentials provided by the supposed employer.
After authentication, the device becomes linked to the fraudster’s account. The attackers can then remotely activate Activation Lock, rendering the iPhone, iPad, or other Apple hardware unusable to its owner.
The criminals subsequently contact the victim, announce that the gadget is under their control, and demand payment for its release. Police stress that transferring funds does not ensure the device will be returned and may result in repeated extortion attempts.
Prevention and Response Recommendations
- Never sign out of your personal Apple account or enter credentials supplied by an employer, technical support representative, or any other party on a privately owned device.
- Legitimate companies do not require job applicants to bind personal hardware to an unknown account.
- If a device is already locked, do not pay any ransom. Instead, contact Apple Support with proof of purchase and file a police report.
Related articles
Scammers Target Remote Workers with Fake Compensation for Home Internet and Devices
Russian remote employees are being targeted by fraudsters impersonating employers, government agencies, and corporate IT departments. Attackers lure victims with promises of compensation for home internet costs and personal computers, directing them to fake sites for identity verification or SMS code submission. Instead of receiving payments, victims risk handing over account credentials or banking details to criminals. Another tactic involves urgent messages from supposed IT services demanding immediate access renewal or software updates via malicious links. The pressure of urgency aims to bypass caution, leading users to click links, enter passwords, or execute files before verifying the sender. Home networks present additional risks because users manage their own routers and connected devices, unlike secured office environments. Experts from Yandex recommend changing default router passwords, updating firmware, disabling quick device pairing, and isolating smart devices on a separate guest network.
Phishing Reports Fall 42.6% in June While Abused URLs Rise 3.2%
The Phishing Countermeasures Council recorded 72,370 phishing reports in June 2026, a 42.6% drop from 126,061 reports the previous month. Despite the decline in reports, the number of malicious URLs increased to 42,241, up 3.2% from the prior month. More than 90% of the phishing emails received by the council's monitoring addresses used unique domains. The largest share of attacks targeted the EC sector at 42.7%, followed by credit and finance services at 27.4%. The council noted that this marks the second consecutive month of declining reports after a peak in April.
WhatsApp Begins Limited Beta Testing of On-Device Scam Alert to Detect Fraud While Preserving End-to-End Encryption
WhatsApp has started limited beta testing of its Scam Alert feature, which uses an on-device machine learning model to analyze message patterns and linguistic indicators of fraud. The system runs entirely locally on the user's smartphone, ensuring that conversation content is never sent to WhatsApp or Meta. Users receive warnings about suspicious messages from unknown contacts and can choose to block, report, ignore, or mark the chat as trusted. To maintain transparency, each model release is logged in an immutable journal managed by Cloudflare with Ed25519 signatures and SHA-256 hashes. The company receives only anonymized statistics on detections and user actions. In parallel, Signal has introduced automatic key verification using a cryptographically verifiable log audited by Cloudflare and Trail of Bits.
Google Chrome Blocks Over 7 Billion Unwanted Notifications Daily on Android
Google reported that its Chrome protection systems blocked more than 7 billion unwanted notifications every day on Android during the first quarter of 2026. Websites increasingly use browser notifications to deliver phishing attempts, fraudulent payment requests, and malware. Chrome applies a multi-layer "Swiss cheese" defense model where several overlapping filters compensate for each other's weaknesses. The browser automatically revokes notification permissions from sites that have not been visited recently or that trigger repeated security warnings, and it can also cancel associated subscriptions. For particularly noisy resources, Chrome enforces a hard limit of 1,000 messages per minute and returns HTTP 429 responses to excess traffic. Google also made permission prompts less intrusive on Android, which reduced background activity and improved battery life. Users can review and manage notification permissions through Safety Hub on both desktop and mobile versions of Chrome.