AntiMalwareSeptember 2, 2026🇷🇺Translated from Russian

Unsolicited iPhone 15 Pro Max Delivery to Reddit User Sparks Fears of Targeted Cyber Attack

A Reddit user recently received an unsolicited iPhone 15 Pro Max delivered in a sealed retail box that the recipient had never ordered. The smartphone appeared brand new on the outside, yet verification of its serial number through Apple’s systems immediately raised red flags.

According to Apple’s records, the device had been purchased or activated as early as December 2023, and its warranty coverage had already expired in 2024. This timeline directly contradicts the pristine condition of the packaging, suggesting the phone inside may have been used or handled previously.

The shipment arrived with a FedEx shipping label, but the tracking number printed on the label could not be found in the carrier’s official tracking system. The recipient wisely chose not to power on the device, insert a SIM card, or link it to any personal network or Apple ID.

Community discussion on Reddit quickly turned to the possibility of a targeted cyber attack. Commenters speculated that an adversary might have sent a pre-modified handset as part of a whaling or spear-phishing operation aimed at extracting sensitive data or gaining access to high-value accounts once the phone was activated.

While the scenario resembles techniques sometimes associated with advanced targeted attacks, no definitive proof has emerged that the package was sent by malicious actors. It remains equally plausible that the delivery resulted from a logistics error, return fraud, or another non-security-related mix-up.

Security-conscious recipients of similar unsolicited devices are advised to leave the hardware powered off, avoid any network connections, and either submit it to Apple for forensic examination or recycle it through certified electronic-waste channels.

Related articles

BoletimSecFraud & Social Engineering

Password Spraying Campaign Targets AWS Root Accounts in Over 150 Organizations

A password spraying campaign targeted AWS root accounts across more than 150 organizations between July 24 and August 23, 2026. Attackers performed repeated login attempts against identities holding maximum privileges in the cloud environment. The root account is created with every AWS account and grants full access to resources, configurations, billing, and sensitive administrative functions. Researchers observed a median of two attempts per organization, with some targets receiving up to eight attempts. No successful authentications linked to the campaign have been identified so far. The attacks leveraged distributed proxies across multiple countries and networks, including hosting infrastructure and residential proxies, while using user agents that mimicked older versions of Microsoft Edge and Firefox. Since June 2025, AWS has required MFA for root users, significantly raising the bar for account takeover even if a password is discovered.

AntiMalwareFraud & Social Engineering

Scammers Embed Phishing Inside Telegram Mini Apps After August Update

Cybercriminals are increasingly abusing Telegram's Mini Apps and WebView features to deliver phishing attacks that mimic legitimate banking, payment, and cryptocurrency services. Following the platform update on August 25, attackers can now present fake interfaces for transfers, airdrops, and voting systems directly inside the messenger. Victims are tricked into entering confirmation codes, connecting wallets, or pasting commands into PowerShell under the guise of fixing errors or claiming bonuses. The attacks rely heavily on social engineering rather than automated malware, requiring users to actively authorize actions such as signing transactions or providing phone verification details. Fake voting schemes are used to harvest account credentials, while crypto-related lures prompt users to link wallets to malicious services. Experts emphasize that simply opening a Mini App does not lead to immediate theft, but authorizing or connecting assets does expose users to significant risk.

AntiMalwareFraud & Social Engineering

Google Introduces Multi-Step Verification for Android APK Sideloading to Combat Fraud

Google has begun rolling out an enhanced installation flow for Android apps installed outside of Google Play. Users must first confirm that no one is coercing them to enable unknown sources, then reboot their device and wait 24 hours before the option becomes available. The new process includes explicit warnings about scammers who pressure victims into enabling sideloading, noting that legitimate organizations never require this setting. After the waiting period, users can grant the permission for seven days or indefinitely. The change does not affect ADB installations, preserving a workaround for advanced users. Google states the delay is intended to give people time to reconsider before enabling potentially risky settings. An Android Authority poll showed 88 percent of respondents expect further restrictions in the future.

HabrFraud & Social Engineering

Why 'Be Vigilant' Is Not Enough: Dissecting Human Psychology During Social Engineering Attacks

A cybersecurity expert with years of SOC and pentest experience explains why traditional awareness training fails against social engineering. The article details how attackers exploit psychological levers such as authority, urgency, reciprocity, social proof, and emotion to bypass conscious decision-making. It emphasizes that people who fall for attacks are often the most helpful and diligent employees, not the careless ones. Instead of relying on willpower in stressful moments, organizations must implement procedures that enforce independent verification and protect the right to pause. The piece also highlights how a blame-free culture dramatically reduces incident impact by encouraging early reporting. Technical measures that reduce reliance on a single human decision are presented as effective supplements to policy.