User Dry_Rich_8111 described a sophisticated phishing attack that began with an Apple ID password change notification on his Mac. After he declined the request, he received a call from his own phone number. An automated voice claimed to be Apple Support and prompted him to press 1 if he hadn't made the request himself. Soon after, a support specialist called back who knew with surprising accuracy exactly which devices were linked to the victim's account.
According to user Dry_Rich_8111, the scammer walked him through several seemingly legitimate security steps to lull his vigilance, and then directed him to a phishing website. There, the victim was asked to sign in with his Apple ID to supposedly close the support ticket. Fortunately, the user suspected something was off and refused to do so.
In the comments, users discussed the red flags of this scheme. According to user Infinite-Grade-4485, the main rule is that Apple never calls customers itself — let alone from your own number, as user tsdguy ironically noted. User chownrootroot suggested that the device information could have leaked due to a hack or because the victim accidentally read out a two-factor authentication code during a verification check. And user Upset-Consideration1 added that the very first password change notification could also have been a phishing attempt, designed to extract data even before the call.
The post's author himself, as a protective measure, set up FIDO2 hardware security keys and filed complaints with the FTC and FCC. However, user tsdguy warned that with hardware keys, account recovery would be impossible if access is lost, so all responsibility for keeping the keys safe falls on the user.
source
https://www.reddit.com/r/Scams/comments/1vyl07v/us_apple_id_spear_phishing_call_using_my_own/
Trust Rating