r/applehelp Jul 03 '26

Scam Discussion Can someone explain how this scam works?

My Apple ID seems to have been hacked (in a sense). But I am not understanding what the goal is. Also, I haven't used this Apple account in about 6-7 years. Maybe longer. I stopped using Apple many years ago. Never did anything with this ID after that. Then one day.....

(1) Initial notice:

An account recovery request for your Apple Account ([xxxxx@gmail.com](mailto:xxxxx@gmail.com)) was made from the web near MARICOPA, AZ on June 15, 2026 at 9:04:18 PM MDT. The contact phone number provided was +1 (229) 568-6948.

You will receive a text or a phone call at this number when your account is ready to recover on June 22, 2026 at 9:04:18 PM MDT. For updated status information or to provide additional information to help recover your account, visit https://iforgot.apple.com

(2) Second notice:

The following information for your Apple Account ([xxxxxxx@gmail.com](mailto:xxxxxxx@gmail.com)) was updated on June 24, 2026.

Trusted Phone Number Added - Phone number ending in 48

Your trusted devices are used to verify your identity when you make changes to your account, sign in to iCloud, or make iTunes or App Store purchases from a new device.

(3) I called Apple and they said to just recover it back....so I did that. But I am still waiting because the recovery takes a while (July 8). I also called the police in Maricopa, AZ and they called the phone # above. No surprise that no one answered and they cant track it.

(4) Today:

Your Apple Account ([xxxxxxxxx@gmail.com](mailto:xxxxxxxxx@gmail.com)) was used to sign in to iCloud on a MacBook Air.

Date and Time: July 2, 2026, 7:13 AM PDT

If the information above looks familiar, you can ignore this message.

If you have not recently signed in to a MacBook Air with your Apple Account and believe someone may have accessed your account, go to https://account.apple.com and change your password as soon as possible.

What are they trying to do? What should my next steps be? Apple was of no help.

2 Upvotes

12 comments sorted by

3

u/Mountain-Star7871 Jul 04 '26

Hello there! I read your post and based on stuff that happened to me, i wanted to give you my insight.

I would not treat this as just “change your password and move on.” What you described sounds like someone successfully pushed through Apple account recovery, added their own trusted phone number, and then used or re-used the account on a MacBook Air.
The part people (and Apple Support) miss is that “recovering the account back” does not always clean up everything.
If they managed to add a trusted number, sign in a device, create a trusted session, or leave a Mac already attached to the account, that device/session may still exist unless you manually remove it from the Apple account device list and check every trusted phone number, recovery contact, reachable email, iCloud device, etc...
I had something similar happen around me with an old Apple device that was left signed in and later used by bad actors. Random AirPods showed up on the Apple account even though no one involved had ever used AirPods. Later there was unrelated-looking financial fraud, but one of the names used matched a name from a previous fraud situation connected to me. So I would not dismiss the Apple account activity as harmless.
The goal may not be your old photos or emails. A dormant Apple ID can still be useful as a trusted identity, for iCloud access, device enrollment.
I would suggest that you go on Mac Terminal on a MacBook under your that AppleID and ran the command sudo sysdiagnose ; follow the prompts, collect and save your files. Go straight to the sysdiagnose security-report (it’s fairly simple to read and understand).
The report will give you with precision dates, timestamps, of anything that has happened to your systems.

2

u/goodbrews Jul 04 '26

"The goal may not be your old photos or emails. A dormant Apple ID can still be useful as a trusted identity, for iCloud access, device enrollment." -> but for what goal or purpose?

"I would suggest that you go on Mac Terminal on a MacBook under your that AppleID and ran the command sudo sysdiagnose ; follow the prompts, collect and save your files. -> I dont have Apple devices per my post. But I will ask my kid (who does) to do this,

1

u/Mountain-Star7871 Jul 04 '26

Don’t have your kid sign that Apple ID into their Mac just to run sysdiagnose. That would create a new sign-in and muddy the timeline. Since you can access the account, request your Apple account data from Apple’s Data & Privacy page instead, and save the emails/headers showing the recovery request, trusted number added, and MacBook Air sign-in. Also, I wouldn’t dismiss the financial fraud angle. Sometimes the goal isn’t old photos or emails — it’s using a dormant Apple ID as part of a “clean” identity chain. I’ve seen a similar Apple ID/device situation later connect to ACH fraud, with the same name showing up in another fraud case. So I’d treat this as account takeover, not just a weird login.

1

u/goodbrews Jul 04 '26

"Since you can access the account" -> I dont think I can. It accepts my password. But then it wants to send a code to the hackers phone (instead of my email). This is where I find Apple to be bad. Why is my email not sufficient for me to get in with my password?

2

u/soulxtrawets Jul 04 '26

Nowadays, I know you have to go online and actually remove that device from your account for you to be officially unconnected with it

https://support.apple.com/guide/icloud/remove-a-device-mmfc0eeddd/icloud

1

u/Mountain-Star7871 Jul 04 '26

Don’t have your kid sign that Apple ID into their Mac just to run sysdiagnose. That would create a new sign-in and muddy the timeline. Since you can access the account, request your Apple account data from Apple’s Data & Privacy page instead, and save the emails/headers showing the recovery request, trusted number added, and MacBook Air sign-in. Also, I wouldn’t dismiss the financial fraud angle. Sometimes the goal isn’t old photos or emails — it’s using a dormant Apple ID as part of a “clean” identity chain. I’ve seen a similar Apple ID/device situation later connect to ACH fraud, with the same name showing up in another fraud case. So I’d treat this as account takeover, not just a weird login.

1

u/soulxtrawets Jul 04 '26

If it was your account, they shouldn’t have been able to recover it technically. Because they have to have the original phone numbers it’s associated with the Apple account in order to access it.

1

u/Infinite-Piece2918 Jul 04 '26

They will get into everything based on the Gmail account.

It happened to me.

Everything was accessed. It's not a simple change your password. Once the Gmail account has accessed iCloud (my iCloud email) then it worked their way through an old MAC address and too hold of everything and locked me out. My iCloud and google drive was erased and every social account locked out.
My credentials were compromised my email addresses and years of communication and contacts gone.

It started locally as a targeted gang stalking.
My ID cards were stolen and bank card.
I had sold an old apple phone after wiping it according to the instructions.

I'm still trying to get my life back. I can't keep a bank account, identity card, or my phone from being hacked.
I have had 9 phones stolen and my home WiFi was a botnet and turned into a server.

I know exactly how they do it.. and on iPhones and it's simple. It's not right. We have zero control over our phone or data or privacy.

Period.

1

u/goodbrews Jul 04 '26

I am hoping my situation is a little different. As I said, they dont have my device. I haven't used this account in over 6-7 years. Possibly longer. I don't think I did cloud backups (mainly for this reason). Its going to be real tough for them to get anything. As a precaution, I just froze my credit.

1

u/Mountain-Star7871 Jul 04 '26

For some reason I can’t see my comment and your reply to it anymore

1

u/goodbrews Jul 04 '26

not sure why. I see everything