Fake Apple Support: The "Your Apple ID Is Locked" Scam
Free: How to Keep Yourself Safe From Scammers
9 chapters. Reporting checklist. 30-second protection checklist. Read on the site.
Fake Apple Support: The "Your Apple ID Is Locked" Scam
It's 8:14pm on a Wednesday and your phone buzzes with a text: "Your Apple ID has been locked due to unusual activity. Verify your identity to restore access." There's a link. Your Apple ID isn't locked. But you tap it anyway, because what if it actually is, and now your photos and your kid's soccer schedule and every password you've ever saved are locked away from you.
That flinch is the entire scam. Nothing else about the message needs to be true.
How this scam actually works
The setup is almost always the same three moves, whether it lands as a text, an email, or a phone call.
First, the alert. "Your Apple ID has been locked," "unusual sign-in from [country]," "your iCloud storage is full and your photos will be deleted," or "a $149.99 purchase was just made on your account." All four versions exist and rotate depending on what's converting that month. Apple's own scam page confirms the pattern: these alerts arrive by text, email, and even fake phone calls, and they're all built to make you act before you think.
Second, the fake login page. The link goes to a domain built to look like Apple's — something like appleid-verify-account.com or icloud-storage-upgrade.net — hosting a near-perfect clone of the real Apple ID sign-in screen. You type your Apple ID and password. Now they have both.
Third, the part that makes this worse than a normal phishing page: they use your real password immediately, against the real Apple sign-in. That triggers a genuine two-factor prompt on your actual iPhone. If you approve it — because it looks exactly like the prompt you get every time you sign into anything — you've just handed over the account, 2FA and all. This is the same "your own device confirms it" trick that's been beating two-factor authentication on Microsoft and Google accounts all year, and the same family as the fake Amazon verification code text that talks people into reading a real code back to a stranger. Apple ID phishing just runs that same playbook against Apple's own login screen.
There's a newer, uglier variant, too. Security researchers at Malwarebytes documented scammers who open a real Apple Support case — pretending to be you, claiming a lost phone, asking to update the number on file — which generates a genuine, properly-signed email from Apple's actual servers, sent to your real inbox. A separate campaign reported by BleepingComputer abuses Apple's own account-notification system: the scammer edits a field on an account they control, which triggers a real "your Apple account was updated" email, and they redistribute copies of that authentic email to a wider list of targets. Either way, the email you're looking at isn't spoofed. It really did come from Apple. The lie is in what happens next — a follow-up call or message telling you to fix the "problem" by handing over your password or letting a stranger remote into your Mac.
Not sure if your message is real? Paste it into Cautellus and get a risk score before you reply.
Scan it free →Or: Get the Chrome extension to scan pages without leaving your browser.
Why this one is harder to spot than a typical phishing email
Most phishing advice boils down to "check the sender, check the domain, look for typos." This scam breaks that rule on two fronts. The login page you land on is a pixel-perfect copy — no typos, no weird formatting, because they're not trying to write a fake page from scratch, they're screen-scraping the real one. And in the version researchers flagged this year, the email itself isn't even forged; it's a real Apple email, triggered by a real Apple system, just aimed at the wrong person. You can't out-scrutinize a message that's technically genuine. You can only refuse to act on it through the channel it arrived on.
The red flags hiding in plain sight
- It creates a countdown. "Your account will be permanently deleted in 24 hours" is not something Apple does. Real account actions don't run on a scammer's clock.
- The link doesn't go to apple.com or appleid.apple.com. Hover on desktop, long-press on mobile. Any other domain — even one with "apple" or "icloud" buried in it — is fake.
- It asks you to "verify" your password by typing it into a page you reached through a link. Apple never needs your password delivered to it this way.
- A phone number shows up inside the alert itself. Real security prompts from Apple don't come with a number to call. If there's a number in the message, that's the scam's actual delivery mechanism.
- The message pressures you to act during the same conversation — don't hang up, don't check with anyone, do it now. Urgency paired with secrecy is the tell in almost every version of this scam, Apple-branded or not.
- You're asked to install a remote-access app so "support" can look at your device. Apple support does not do this over an inbound call or text you didn't initiate.
- The email is real, but the request inside it isn't. If a legitimate-looking Apple email leads to a phone call demanding your password or a screen-share session, the email's authenticity doesn't make the ask legitimate.
If this already happened to you
Don't spiral, and don't waste time being embarrassed — these pages are built by people who do this full-time, and some of them fool security professionals too.
- Go straight to appleid.apple.com yourself — not through any link you were sent — and change your Apple ID password immediately.
- Check Settings > [Your Name] on your iPhone or Mac for devices you don't recognize, and remove any you don't own.
- Turn on two-factor authentication if it isn't already on, and review your trusted phone numbers and recovery email for anything added without your knowledge.
- If you shared payment info or approved a purchase, contact your card issuer and dispute the charge.
- If you let someone remote into your Mac or iPhone, disconnect from the internet, and run a malware scan before reconnecting — a factory reset from a clean backup is the safest option if you're not sure what they touched.
- Forward the phishing text or email to Apple at reportphishing@apple.com, then report it to the FTC at reportfraud.ftc.gov. If money changed hands, file with the FBI's IC3 at ic3.gov too.
How to not become the next victim
The single habit that kills this entire scam category: never touch a link in a text, email, or pop-up claiming to be Apple. If you're worried your account might genuinely have a problem, open Settings on your own device or type appleid.apple.com into your browser yourself. Apple's own guidance on recognizing scams confirms scammers spoof Apple's caller ID and use fake urgency about "suspicious activity" to get you moving before you think, and the FTC's guidance on tech support scams makes the same point about any company: legitimate alerts never come with a phone number attached.
A hardware security key is the one upgrade that makes this entire scam category close to pointless — even if a scammer gets your password, they still can't get past a physical key they don't have. If you want that extra layer on your Apple ID and other accounts, YubiKey 5C NFC is the option I'd actually recommend to my own family. And if a message like this lands on your phone and you want a second opinion before you tap anything, run it through the Cautellus scam text checker first — it's built to catch exactly this kind of brand-impersonation link.
This pattern shows up constantly in text message scams generally — Apple is just this month's costume. For the full rundown on what a legitimate Apple communication looks like versus what scammers fake, Apple's own account page lays out every current variant side by side.
Got something like this in your inbox? Drop it into the scanner — it takes 5 seconds and could save you thousands.
Check it now →Already been scammed? See where and how to report it.
FAQ
Is every "Your Apple ID has been locked" message fake? Yes. Apple does not lock your account and notify you by text or email with a link to fix it. If your account ever genuinely needs attention, the prompt appears in Settings on a device you're already signed into — never through an inbound message.
I clicked the link but didn't type anything. Am I okay? Probably — loading a phishing page alone doesn't hand over your credentials. Close the tab, don't enter anything if it's still open, and skip straight to changing your Apple ID password from appleid.apple.com as a precaution.
The email looks completely legitimate, down to the Apple logo and formatting. How is that possible? Because in some current campaigns it genuinely is a real Apple email — scammers have found ways to trigger authentic account-notification emails from Apple's own systems and redistribute them. The email being real doesn't make the follow-up request real. Judge the ask, not the letterhead.
Can they get into my account if I have two-factor authentication turned on? They can, if you approve the 2FA prompt after they've already phished your password — the prompt looks identical to a legitimate one because it's triggered by your real password being entered on Apple's real site. Only approve a 2FA prompt you were expecting because you just tried to sign in yourself.
What's the actual Apple support number if I need to check something? 1-800-275-2273, or use the Apple Support app, or go to support.apple.com directly. Never the number inside an alert someone sent you — dial it yourself, from a source you looked up independently.
Why would someone bother stealing an Apple ID instead of just a password to some random site? Because an Apple ID is a master key — it often unlocks Find My, iCloud backups, stored payment methods, purchase history, and every photo and document synced to it. It's one of the highest-value single accounts most people own, which is exactly why it gets impersonated this often.
Your Apple ID was never actually in danger. The text was the danger. Delete it, and go on with your night.
Think you've been targeted? Paste any text, link, email, or screenshot into Cautellus for instant AI analysis.
Scan something free →Want unlimited scans + the Chrome extension? See pricing.
Courtney
Founder, Cautellus · 20+ years in financial services
Two decades in financial compliance, digital security, and fraud prevention. Built Cautellus because the scam detection tools that exist were made for IT departments, not for real people getting weird texts.
Learn moreKeep reading
Support Our Mission
Cautellus is built to protect people from online fraud. Your contribution helps us keep building security tools and resources.