:

STOLEN IPHONES BECOME HACKING TOOLS FOR CRIMINALS

SECURITY DESK1 MIN READ
THU, MAY 14, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

An underground market is supplying criminals with techniques to unlock stolen iPhones and launch phishing attacks against victims' contacts. The ecosystem targets bank accounts and sensitive data.

Thieves now have access to tools and methods that bypass iPhone security, enabling them to access device contents and impersonate owners through their contact lists. Once unlocked, criminals send phishing messages to the victim's contacts, posing as the device owner to trick recipients into revealing banking credentials and personal information. This two-stage attack multiplies the damage beyond the initial theft. The criminal ecosystem operates through forums and marketplaces where specialized services are traded. Some vendors offer device unlocking expertise, while others provide phishing templates or buyer lists compiled from previous victims. Apple's security features have made this process more difficult than in previous years, but determined attackers continue finding workarounds. The vulnerability highlights the danger posed by physical device theft in today's interconnected digital environment. Security experts recommend enabling two-factor authentication, marking devices as lost in iCloud immediately after theft, and warning contacts about potential phishing attempts.

■ SOURCES

Wired

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.

YESTERDAYIndustry Desk

Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.

YESTERDAYSecurity Desk

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

YESTERDAYIndustry Desk

Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.

YESTERDAYSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.