No, a free iPhone 12 is not waiting for you — avoid this scam

iPhone 12
(Image credit: EverythingApplePro)

NOTE: We've been hearing rumors that these "package is waiting for you" text messages are somehow connected to human trafficking. They are not. They're just a regular old phishing scam.

In the most recent chapter in the annals of SMS phishing scams, aka "smishing," we have the saga of the fake Apple iPhone 12 giveaway.

Sophos' Paul Ducklin, an information-security luminary in his own right, wrote about this smishing attempt recently on his employer's Naked Security blog. It seems someone on the Sophos team got a text message stating that a package for them — actually, someone with a different name — was waiting for them to pick it up.

Step 1 of an SMS-text-driven phishing scam.

(Image credit: Future)

Ducklin walks the reader through the scam, from the first click on the link in the SMS message, to a website where a phony chatbot says that you have been selected to get a free Apple iPhone 12, to the survey you have to take, and finally to the point where you can "claim" the iPhone reward.

But of course, you'll have to provide an email address, password and credit-card number first. And, of course, the iPhone 12 doesn't yet officially exist. It likely won't be announced by Apple until mid-October.

Step 2 of an SMS-based phishing scam.

(Image credit: Future)

Sound familiar? We've been getting these texts too, along with a whole lot of others touting fake Viagra and CBD oil. In fact, the screenshots on this page are not from Sophos, but from your correspondent's own phone. (Our particular scammer couldn't seem to decide whether we were supposed to get an iPhone 11, 11 Pro or Xs.)

The lure of a new iPhone isn't that alluring to me, as I'm an Android fan, but going through the steps of this scam is a fun little exercise. Ultimately, this is just a phishing scam that wants to harvest your username, password and credit-card information. 

Step 6 of an SMS-based phishing scam.

(Image credit: Future)

You may wonder for which online service the username and password the username are supposed to be for. The answer is that it doesn't really matter. 

So many people (yes, we've all done it) reuse passwords for so many different websites that almost any username-password combination is bound to be useful to crooks. To avoid becoming the latest victim, be sure to use one of the best password managers.

Step 8 of an SMS-text-driven phishing scam.

(Image credit: Future)

These miscreants feed the phished credentials into automated "credential stuffing" algorithms that hammer websites like Facebook, Google or PayPal with thousands of credentials an hour. They're bound to get into more than a few times. 

So how do you protect yourself from such (frankly obvious) scams? First, remember that if it sounds too good to be true, then by dadgum, it is.

Step 9 of an SMS-text-driven phishing scam.

(Image credit: Future)

Second, never give away any passwords or credit card numbers to any website that you are brought to by a text message or instant message. Would you give the same information to a random stranger who stopped you in the street?

You can't really stop these scam texts, unfortunately. The numbers they're texted from aren't real, and blocking the numbers will do no good. All you can do is not respond to them and hope the scammers move on to greener pastures.

Step 10 of an SMS-text-driven phishing scam.

(Image credit: Future)
TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
iPhone 15 Pro Max shown in hand
iMessage under attack from scammers sending phishing messages — don’t fall for it
A fake text message on a smartphone being held by both hands.
Toll road scams are worse than ever — what to look for and how to stay safe
A hacker typing on a computer
FBI issues serious warning to iPhone and Android users — stop doing this ASAP
A hacker typing quickly on a keyboard
Hackers are posing as Apple and Google to infect Macs with malware — don’t fall for these fake browser updates
A person typing on a computer while hackers use phishing to steal a file from their computer
Phishing: What is it, and how to avoid it
PayPal logo on iPhone
Watch out! Scammers are using this PayPal setting to take over your PC
Latest in iPhones
The iPhone 17 Air next to an iPhone 16 Pro Max
iPhone 17 Air could be this thin — new photo vs iPhone 16 Pro Max
iOS 19 logo on an iPhone
iOS 19 just tipped for 'most dramatic overhaul' in Apple's history
iOS 19 logo on an iPhone
iOS 19 — all the biggest rumors so far
3D printed models of alleged iPhone 17 Air and iPhone 17 Pro design
iPhone 17 Air dummy model shows off Apple’s big design change
iPhone 16 Pro shown held in hand
iOS 19 may bring Apple Intelligence powers to more iPhone apps — but without any big new features
A render of the iPhone 17 Pro Max
iPhone 17 Pro Max — this new rumor could push people towards iPhone 17 Air
Latest in News
Samsung Galaxy S25 Edge back
Samsung Galaxy S25 Edge price comes into focus with latest leak
iPhone 15 Pro Max shown in hand
Apple just released emergency security update for flaw used in ‘extremely sophisticated’ attacks — update your iPhone, iPad and Mac right now
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 12 (#640)
Jean Smart as Deborah Vance and Hannah Einbinder as Ava Daniels in Hacks
Max reveals 'Hacks' season 4 release date and trailer — here's when it's coming
Google Pixel 5 review
Google Pixel 10 lineup leaked in new renderings — here's what they look like
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware