Security Alerts for Apple Pay Users Against Digital Crime
- Cybercriminals are increasingly targeting Apple Pay users through sophisticated social engineering and phishing schemes to steal funds, according to a security alert from the Secretaría de Seguridad Ciudadana...
- The SSC reports that digital criminals use a variety of tactics to bypass the security layers of the Apple ecosystem.
- Once a user clicks these links, they are often directed to a fake login page designed to capture Apple ID credentials and passwords.
Cybercriminals are increasingly targeting Apple Pay users through sophisticated social engineering and phishing schemes to steal funds, according to a security alert from the Secretaría de Seguridad Ciudadana (SSC) in Mexico City. The agency warns that attackers typically gain access to accounts by manipulating users into revealing sensitive information or by compromising the devices used to authorize payments.
How Apple Pay Fraud Operates
The SSC reports that digital criminals use a variety of tactics to bypass the security layers of the Apple ecosystem. One primary method involves phishing, where attackers send fraudulent messages or emails that appear to be from Apple or a financial institution. These messages often claim there is a problem with the user’s account or a pending payment to lure the victim into clicking a malicious link.
Once a user clicks these links, they are often directed to a fake login page designed to capture Apple ID credentials and passwords. According to the SSC, once the attackers obtain these credentials, they can attempt to add the victim’s stored payment methods to a different device under the attacker’s control.
The agency also notes that some criminals use social engineering to trick users into sharing one-time passwords (OTP) or verification codes sent via SMS. By posing as bank employees or technical support, attackers convince users to provide these codes, which allows the criminal to authorize the addition of a card to a new Apple Wallet.
Security Measures and Prevention
To counter these threats, the SSC recommends that users maintain strict control over their Apple ID and device security. The agency emphasizes that Apple and financial institutions will not request passwords or verification codes through unofficial channels or text messages.
- Enable two-factor authentication (2FA) to ensure that a password alone is not enough to access an account.
- Avoid clicking links in unsolicited emails or messages that request account verification.
- Regularly review transaction history for unauthorized charges.
- Update the device’s operating system to the latest version to ensure current security patches are active.
The SSC suggests that if a user suspects their account has been compromised, they should immediately contact their bank to freeze the affected cards and change their Apple ID password.
Technical Context of Apple Wallet Security
Apple Pay utilizes tokenization to protect card data. Instead of storing the actual card number on the device, it uses a Device Account Number, which is a unique identifier. This means the actual credit or debit card number is not shared with merchants during a transaction.
However, the SSC’s warning highlights that the vulnerability does not lie in the tokenization technology itself, but in the identity management layer. If an attacker gains control of the Apple ID, they can potentially manage the cards associated with that account, regardless of the underlying encryption of the payment tokens.
The agency’s alert follows a broader trend of “account takeover” (ATO) attacks, where the goal is not to hack the payment processor, but to steal the credentials of the user who has already been verified by the system.
