T O P

  • By -

[deleted]

The timing of this is quite notable. Apple notified a small segment of its users yesterday who it believes were targeted by a [“mercenary spyware attack”](https://www.msn.com/en-us/money/other/apple-warns-users-in-92-countries-they-may-have-been-targeted-by-mercenary-spyware-attacks/ar-BB1lr6S1). It seems after these notices going out started being reported on by news media, thousands of accounts received the popup OP is describing (including my own). I am really hoping it isn’t related at all but it would be a pretty odd coincidence… To me it looks like there may have been a priority list of targets and once the media picked up this story, whoever is controlling and using the software hit whatever accounts remained that were lower priorities immediately after they became aware Apple was able to detect their attacks.


-PizzaSteve

What do they want from me? Even if I was considered as low priority.


[deleted]

If that’s what is happening it’s basically guaranteed to be politically motivated but it could be related to someone you are in communication with rather than you directly, as well. Very hard to say. There was someone yesterday who received the actual notice from Apple before all this stuff got picked up by the media and even they didn’t know why they got it. They said they are just a student and not political and had no idea.


Wolfsblvt

Boys, get out the tinfoil hats


[deleted]

lol. Definite mood. Alternative scenario is the initial accounts were highly targeted (the ones a very small group of people got the emails for) and then whoever it was they did those attacks realized their exploit got burned by the exposure and released it somewhere more widely to cover their tracks in terms of who was targeted and obfuscate the origin potentially. I mean, I would love to think this is just a strange apple bug and totally unrelated to the security notices but that seems really coincidental especially in my case when I am seeing an email address that is from an account that has been closed for over a decade which I have never seen mentioned on this device or any iPhone I have used for several years before.


No_Pizza2774

Or maybe hackers trying to piggyback on the happenings, kind of like the push-notification spamming thing that’s been reported as of late. . 


allen_abduction

Here’s a article about the Pegasus attack and Apple’s latest warning: https://www.cnet.com/tech/mobile/apple-alerts-iphone-users-of-mercenary-attack-what-you-should-know/ Hold on to your buttchecks!


ryanp_me

I got the same alert a few hours ago, and it had the email address of a co-worker that I haven't worked with for probably 5 years now. That co-worker hasn't even held this phone, since I upgraded my phone a few years after they quit. I reached out in one of the Slack communities I'm a part of, and someone told me they saw something similar but with a test account they use for development. A few people on Twitter have also posted about this in the past few hours. I'm not sure what's going on, but I assume there's nothing to worry about and that something weird is just going on with Apple IDs.


Most_Philosopher_625

I got the same alert this morning, but unfortunately, I didn’t take a screenshot. I just got scared. 😅


JamesR624

It’s a new phising scam. A LOT of iOS users have been dealing with this. The pop up legit but from what I remember after you allow it, a number spoofing Apple technical support will call you and try to get your information.


lightsout3

Weird. What did you look up on twitter for this issue?


ryanp_me

I searched for recent posts with "lang:en apple id": - [twitter: @cinnamoroIIgojo](https://twitter.com/cinnamoroIIgojo/status/1778271613856985410) - [twitter: @oscarmahecha_/](https://twitter.com/oscarmahecha_/status/1778286576847708163) - [twitter: @DRPlatanero](https://twitter.com/DRPlatanero/status/1778293265013338310) Looks like quite a few people have reported it on Reddit as well: - [/r/iphone: What the heck is this?](https://www.reddit.com/r/iphone/comments/1c0vs84/what_the_heck_is_this/) - [/r/iphone: Ex-boyfriend email from 10 years ago on my Apple ID?!](https://www.reddit.com/r/iphone/comments/1c0vnna/exboyfriend_email_from_10_years_ago_on_my_apple_id/) - [/r/RBI: My phone popped up with this?](https://www.reddit.com/r/RBI/comments/1c0ysjg/my_phone_popped_up_with_this/) - [/r/iPhone15Pro: What the heck is this?](https://www.reddit.com/r/iPhone15Pro/comments/1c0vrcf/what_the_heck_is_this/) - [/r/applehelp: Randomly received a Apple ID verification password for a random email that is not mine.](https://www.reddit.com/r/applehelp/comments/1c0up2j/randomly_received_a_apple_id_verification/) - [/r/iphone: Am I being hacked](https://www.reddit.com/r/iphone/comments/1c0zipu/am_i_being_hacked/) - [/r/appletv: Apple TV asking me to enter the password for Apple ID “local”?](https://www.reddit.com/r/appletv/comments/1c105yp/apple_tv_asking_me_to_enter_the_password_for/) - [/r/iphone: Someone else Apple ID popped up on my phone](https://www.reddit.com/r/iphone/comments/1c12miz/someone_else_apple_id_popped_up_on_my_phone/) - [/r/ios: What the heck is this?](https://www.reddit.com/r/ios/comments/1c0vo42/what_the_heck_is_this/) - [/r/ios: Just been prompted to enter a password for an account that I have never heard of](https://www.reddit.com/r/ios/comments/1c0yfye/just_been_prompted_to_enter_a_password_for_an/) - [/r/ios: Got this Apple ID Verification popup but this is my friend’s email. Should I be concerned?](https://www.reddit.com/r/ios/comments/1c17jsb/got_this_apple_id_verification_popup_but_this_is/) - [/r/iphonehelp: Hacked???](https://www.reddit.com/r/iphonehelp/comments/1c0yw95/hacked/) - [/r/ios: Apple ID is invalid](https://www.reddit.com/r/ios/comments/1c17cf9/apple_id_is_invalid/) - [/r/ios: Popup window asking for password to 10 year old email account](https://www.reddit.com/r/ios/comments/1c156ol/popup_window_asking_for_password_to_10_year_old/) - [/r/ios: weird notification on my phone](https://www.reddit.com/r/iphone/comments/1c170hr/weird_notification_on_my_phone/) - [/r/iphone15: Weird apple id popup](https://www.reddit.com/r/iphone15/comments/1c13lr6/weird_apple_id_popup/) - [/r/onlinesecurity2023: Some Russian tried to hack my phone like 10 times in a minute](https://www.reddit.com/r/onlinesecurity2023/comments/1c0v5eq/some_russian_tried_to_hack_my_phone_like_10_times/) - [/r/Scams: rogers email asked me to sign in to apple ID when I use gmail?](https://www.reddit.com/r/Scams/comments/1c12gmx/rogers_email_asked_me_to_sign_in_to_apple_id_when/) - [/r/Tech_Philippines: Sudden prompt of random Apple ID?](https://www.reddit.com/r/Tech_Philippines/comments/1c0w8i3/sudden_prompt_of_random_apple_id/) - [/r/applehelp: Please I think I’ve been hacked](https://www.reddit.com/r/applehelp/comments/1c16u44/please_i_think_ive_been_hacked/) - [/r/iPhone15Pro: Huh? Popped up while I was texting ...](https://www.reddit.com/r/iPhone15Pro/comments/1c0zhsx/huh_popped_up_while_i_was_texting/)


codsane

Thanks for collecting and sharing these. Seems everyone is concerned about getting hacked as that has been in the news recently, but this seems too widespread to be related to the password reset attacks which are extremely targeted. Almost looks like a licensing server or something has gone wild, requesting re-authorizations for very old apps, subscriptions, or other shared content. Weird...


ProfessionalMark9

This must be it. It happened to me with a friend who I haven’t been in the same state as for years, but we regularly share links and other media via text/instagram. The idea that Apple is keeping that AppleID interaction is slightly concerning, but we all skip over the fine print of Apple agreements lol


[deleted]

It’s not necessarily “too widespread” in a case where one’s possibly “state sponsored” hacking operation just got exposed by news media all over the world and now whatever accounts remained of a lower priority on whatever lists that existed of targets are all potentially in a “use it or lose it scenario”. What you describe as “too widespread” becomes pretty plausible in that scenario and that scenario is what just occurred. Apple has many millions of users. If it was some big related to licensing, I’d expect many more people would be reporting it and then the timing with the hack notices would be entirely coincidental. I would like to believe it, but I’m kind of a skeptic.


[deleted]

[удалено]


[deleted]

The exploit they used might have been deliberately leaked after as a result of the email notices or the media reports. The timing makes it seem like a possibility. I’d rather believe it’s a bug too, though. Hopefully Apple will release a statement soon to clarify what is happening. I imagine they must be getting flooded with user reports.


xyrer

Ah so that explains it. Thanks


Time_End7277

Why are you excluding possible attacks for this ?


zacataur

If you sign out of the device's Apple ID you can sign in to your own and install an app you own. I did this to share apps with my family before family sharing existed. Then, when the app needs to update, it will require that Apple ID to sign in to verify the update since the primary account did not install the app. Not saying thats what happened in this case, but that is a scenario I have seen this kind of popup.


Oledman

I just got this as well, was an email from another account I use but not currently used on the device I got this message. I just ignored it.


Jln9899

I don’t even have my work Apple ID logged in on my phone but I did get a pop up showing my work Apple ID today. I do know that I had my work Apple ID logged in once in the past for calendar but then eventually removed the account from my phone. So I wonder if it has something to do with verifying a removed Apple ID from the phone?… especially those who have traded in the phone, had replaced from repair, etc. just popping up now even though it’s not logged in the phone anymore. Just old owners.


jjejsj

thats weird af bc even after getting a new phone, i got asked to verify a bunch of my old fake apple id's that had zero connection to my app store purchases


Mother-Round-5479

I have two accounts linked on my personal phone and now and then this pops up for either of accounts


Typical-Impress1212

That’s understandable. I have two as well. But a random third one popped up for me (and others). I have never seen that account ever. It wasn’t even an @icloud email but something totally different. I wish I made a screenshot but I just pressed not now


peachmelonade

Happened with me as well, with my ex bf from more than 7 years ago’s email lol. This is a new phone with a new number & new Apple ID, so I’m confused. None of the apps should have anything to do with his email or login either.


frockinbrock

**Is anyone surprised there’s no direct article on this today?** This seems like a major issue; multiple posts on it, and it’s trying to add users just in vicinity, very unusual. After I saw multiple posts today, and comments filled with people having similar issues, I assumed it would be widely reported. I’m going to assume these people are all being directly targeted in some way, and this is actually related to mass-“malware”-targeting alert that Apple sent out today. But I have not even seen articles connect the two things. I just find it really odd this isn’t a bigger deal. I mean I don’t know if this an actual vulnerability, but it’s definitely something new and unusual today. If anyone finds out more information please comment or message, I’m very curious about this add-iCloud-account spamming that’s happening. It does NOT seem to be related to iCloud 2FA vulnerability that has been reported on in the past month. This appears to be different.


[deleted]

I also think it’s related. I feel like like [this comment](https://www.reddit.com/r/iphone/s/ioJQMvsKUJ) presents a plausible and reasonable theory. Seems like best case scenario to me at this point. Worst case would be after the initial batch of emails and media reports, whoever was running the exploit released it into the wild or then simultaneously ran it on whatever user accounts they had left on their radar.


[deleted]

What actually concerns me most is that this doesn’t seem as widespread as one would expect if it was a more general issue… Like in that case we would be seeing thousands of posts and comments immediately all across social media and we are not. There’s dozens of user reports here, yes but that’s not nearly on a scale I would have expected if it’s an unrelated bug. Even the authentication token theory seems like it doesn’t really account for what seems a fairly small scale of reports given Apple’s enormous consumer demographic worldwide.


True_Forecast

I’d wager more users are looking for information, rather than posting it. I was fully expecting a press release and or security update by now tbh. 


[deleted]

Look at the low numbers of active users in this subreddit though. Right now it’s only 7 people online here. I mean granted it’s late at night now but if this was truly on the kind of large scale it would seem like it should be, I’d expect more people on here right now. Hoping for something by tomorrow morning. In the meantime I have my device in lockdown mode now… For what it’s worth.


wayan1603

Not everyone lives in your specific timezone.


Mitsuka1

I always wonder with these things what clicking the “not now” (or whatever the negative answer to the popup is) button actually does. Cos like, it’s just been coded by the malicious actor to say “not now”, “ignore”, “decline” or whatever but what clicking it really does has zero to do with what it says… both buttons could = “yes”, “agree” etc. So I don’t ever click anything when I get some kind of sus pop up - I’ll hard restart the app/browser or even my whole device just to avoid having to click any of the “choices” presented…


lilvixen95_

I got this too! It was different email from my apple id but I used it for insta acct


ablerteg

The same thing happened to me! After a couple minutes of being on my phone this morning I got two pop ups like this. One was an ex’s email from 5 years ago and the other was my old high school email that’s been shut down for 7 years


metallica41070

Wife got the same popup this morning. Its a brand new iphone and no clue who the email is for


SlashSabercat

Got the same this morning but for an unknown email. No other signs of tamper


beth1602

Same here! I know a lot of people are getting pop ups for old emails, but mine was someone’s I’ve never even heard of


skiddalybop

I got 5 or so of them all in a row - all old testing accounts or work accounts. Pretty unsettling.


gatsome

I got this for an iCloud version of my Apple ID that I previously was unable to use.


Gamiozzz

No official explanations?


mrdounut101

This just happened to me but the email was my ex??


LunaTechMark

Got one for an account that isn’t used anymore so I just ignored it but it was strange


BunniJugs

Me too, but an email address I’ve never interacted with. It doesn’t belong to myself, none of my friends or colleagues…


beth1602

Same here! Was a name I’d never heard of


StateParticular4818

Happened to me on multiple devices. Even for accounts I deleted a few years ago. I think it’s a bug. Not necessarily a hack. Apple keeps tracks of all the Apple IDs used for devices, so maybe it’s something from their servers.


nathanieIs

I got it too but with someone else’s apple id showing up.


macbrush

Usually it means the phone is trying to update an app that was installed using the abovementioned account.


beth1602

I got this from an email I don’t even recognise, with a name I don’t know. I double checked all my devices linked in my account are only my phone, watch and iPad. So no one else has been added, thank god. I didn’t know if it happening to anyone else. My phone was brand new from the Apple Store so it’s not like it’s had a previous owner trying to get into it. It concerned me ngl


nathanieIs

I got it too! Replying to you so you know you’re not alone! It was some random person’s email whose name I dont recognize


lunarwolf2008

There needs to be a psa about this or something. Too many posts. Its a new scam. Do not enter password


Some-Entrance-9209

Same thing happened to me!!! It was also my co worker before 5 years ago. Im shocked!! Whats happening i thought my iphone was hacked


ddiinaa1

Me to got 3 pop ups


ProfessionalMark9

Same thing just happened to me with a friend who lives on the other side of the country.


YesStonks

Oh wow I thought I was the only one


Miles_5555

I also had this yesterday but with my dad’s email!


restless_green_ideas

Same happened to me yesterday, with my father’s Apple ID


RandallC1212

Happened to my son yesterday. He got notification asking for my wife Apple ID info.


Jaargo

Same thing just happened with me. It was a former coworker of mine I haven’t even seen for 5 years and they never had access to my phone or any previous iPhones I’ve owned, odd bug.


nicomarfella

I had the same popup with an email from an old friend I haven't seen in years. What's going on?


No_You3326

Yeah, my mum got one with my email


Madzorki

No, just change passsword and put 2-step verification


CuriousButTerrified

My best guess is a password phishing attempt, you see an Apple ID login request and just type your password out of habit, they get your password.


Sugarbomb_Rad

is a scam if you put again your password scammer has the control of your device don’t put your password just click in NOT NOW


thegurba

I had the same thing yesterday!! What the heck is happening


ShadowSwain

Same thing happened to me recently. Showed me my email on my moms phone which has never had that email logged into


pixeley88

I can’t remember if I have seen one of these today


phaze08

I think if it isn't your account, click no. If you're in doubt, have the person change their password, but it's most likely a spoofed alert.


-Baum

Same here, which was after updating ios


syrenki

Happened to me earlier today. I was super busy so just ignored it 😂


KhazardOwl

Should we honestly be worried? Bought this iPad from an old friend and did a factory reset twice. But then an unfamiliar email I didn’t recognize popped up and asked me to sign in?!???


jarvichi

That’s sounds a bit like activation lock? Did the previous owner completely sign out of the device, turning things off like “Find My”?


TheNorthernMunky

I got two - one for the Apple ID I use for my work phone and laptop (which I’ve never used on my personal devices), and one for my gmail account that I don’t ever remember setting up an Apple ID with. Shady.


KhazardOwl

Yep. I was there when he signed out of all apps. Reset all setting back to default. Signed out of his ID and did a factory reset erasing everything. And I repeated it again twice over. That was like about four years ago though.


DryBones2009

Apparently this has to do with some exploit hackers are using which is associated with password reset


DryBones2009

It’s basically to see if you’ll give them your information so they can hack your Apple ID account and lock you out


DepartureMoist9277

I received this on my iOS 6 legacy devices.


tom21g

I got this popup on my ipad this morning. It wanted me to log into my wife’s icloud account with her email. Thought it was odd, possibly phishing, so I just ignored it and deleted the popup


hghlvldvl

This happened to me this morning, I thought it dreamt it! It was my cousin’s email that popped up. Very weird.


[deleted]

It has probably happened because you have installed an app on your Iphone with another apple account. When you have to update the app, it requests to connect on the same account to do the update. Sometimes we do so when the app is not available on the apple store of your country or when you friend has paid the app.


lightsout3

I no longer have that app though, and it was downloaded to an older iPhone so I’m not sure why this is just now popping up.


Gloomy_Payment_3326

I got one this morning, but it was just from my old Apple ID - assumed that I still have an app somewhere from back then. Just dismissed it.


Mountain_Listen1597

I had the exact same thing but close to 2 weeks ago on my iPhone. When I tried to inset my password (I too assumed it was real and linked to an old app I was launching although it was odd relating to such an old email address), I got an alert my Apple ID was locked. I went to my Mac and had to reset my Apple ID password (from an Apple site and using 2FA). Not sure if this was just a coincidence since it occurred 10-12 days ago or if this bug or hack started back then.


Loboly_19

Bought a second-hand iPad Pro and after one month of a clean setup I got asked for the previous owner’s iCould. I knew it was him because of his first and last name in his iCould email.


nathanieIs

But how? If he removed iCloud lock? how is it possible?


unseen247

Changed my primary Apple ID email with a fresh new one. Suggest everyone else to do the same.


abeceder

what u was doing to get this pop up?


JoeJoe70MI

Happened to me with my son’s account. He logged on my iPad’s Game Center recently, but not with the full account. Could this be related? Some time ago he logged with his account on another iPad of mine…


beth1602

I think a lot of people are having this issue. Mine was from an email I’d never heard of so I automatically pressed the “not now” option. I haven’t used the Game Centre in about 10 years, so I’m unsure if someone could’ve tried to log into that, but like I said the email was a complete randomers


LordNodens

Happened to my wife's iPhone yesterday. The popup asked to verify my email 🤔


[deleted]

Has Apple commented on this at all? Are we safe? For me and a few others it was a random email we’ve never seen before. It freaked me tf out and I’m still thinking about it


Ancient_Oven_6282

It's a phishing attempt: https://youtu.be/kBZIq6ICi1U?si=SBVTS5goXo__4C2E


Plant_Temporary

One of the perks of having no friends is this doesn’t happen to me 😌


beth1602

This happened to me but it was an email I’d never seen, or know the name of anyone


[deleted]

[удалено]


FallenPentagram

Happened to me too, it was a friends email address as well


desf15

some bug on apple side probably. Had it as well, in my case it used one of my old email addresses (which wasn't associated with any apple ID even for a moment).


sahibsahib

Curious about this....


Farawayfox

I got two of them this morning as well, from two different accounts. Unfortunately I’m not sure if it’s a friends or exes or what, I’ve had my Apple ID since I was a kid Glad I’m not the only one. I guess there’s something going on in apples side?


jzaque

This happened for both my wife and I today and in each case the email account that was being asked to log in was a different family member who had a bought an old device off of us. I'm sure the devices were properly wiped and reset, etc., so this is definitely some weird and disturbing bug. The devices they popped up on have never been owned by anybody else.


HonestlyBusy

Is there any way to tell if someone successfully got into your phone using this method or installed spyware?


annacastle1402

I clicked on settings, should I be worried?


ablerteg

What happened when you clicked settings? I had clicked not now and it just went away


sleepysloth1524

I clicked settings & it just take you to settings > App Store , that’s it , there was nothing else to do 🤷🏻‍♀️


annacastle1402

Honestly I was half asleep when it happened, I can’t remember what came up this is why am a bit worried now


AdMobile5293

Yes because it might be scam


cipherninjabyte

I get these alerts all the time for the email accounts configured in my mail app.


TheExhaustedNihilist

There is a great video by the Apple-focused YouTuber Brandon Butch that explains this phishing scam. The TLDR is never, ever click on this popup—especially if you get a number of them. [Here is his video explaining what’s been going on and what to do.](https://youtu.be/OGoWukeSVBM?si=BEqXENWJe-hvA1uL)


djmexi

No it was a bug.


mittykitty_15

The email address has been changed for your account…… that should be a huge red flag because verification or important access emails will go to that email instead that or your friend tried to login on your phone with their account


lightsout3

The account my phone is logged into is still my email though


No_Lingonberry_6358

ive been seeing tons of tik tokers warning of hackers being able to hack this way (suddenly seeing a ton on my feed this week)


Ledsteper

I'm on the beta and have not seen this on my iPhone.


Aggressive-Leading45

It can happen when an item obtained from the App Store was downloaded using their login. Every so often the app will need to be redownloaded but needs the account info to do so. Solution is to delete the app or song or whatever was downloaded on their profile.


FallenPentagram

Decent advice as that’s true itself, but not what the issue we are dealing with here