Hackers Locking, Ransoming Macs: How to Protect Yourself

Apple users: If you haven't made your iCloud password strong and unique, today might be a great day to do so.

Credit: Kaspars Grinvalds/Shutterstock

(Image credit: Kaspars Grinvalds/Shutterstock)

We're seeing reports of online ne'er-do-wells taking advantage of a long-existing system-locking tool in iCloud's Find My Mac feature, which isn't locked behind two-factor authentication, to lock up Macs remotely and hold them for ransom.

These reports, first seen by MacRumors, came from Twitter users including @bunandsomesauce. He posted evidence of the lock of his Mac with a photo of the ransom note on his Mac's screen, asking for $50 in Bitcoin. Another Twitter user, @jcaffoe, lost access to his Mac, and he's worried that he won't get it fixed any time soon because his local Genius Bars are booked solid for a week.

These attacks aren't due to a mistake, or a change in how Apple implements two-factor authentication (2FA). The company intentionally makes its Find My iOS and macOS device services — which can place a lock-code on a machine — accessible once you've entered your iCloud password.

The reasoning is because you might have lost access to your trusted device as a result of the theft (your iPhone, for example, could be stolen from you in public). We've argued in the past that Apple needs to find some way to implement 2FA for this service, but to no avail.

Such remote takeovers have plagued iPhone users for years. But now that Apple has extended the same "Find My Device" service to Macs, online criminals are using the same technique to hijack laptops and desktop computers.

What should you do?

First of all, never recycle your passwords for important accounts such as online banking, Google, email services, social networks, or your Apple account.  All should be protected by strong, unique passwords.

But a unique password isn't exactly enough. Make sure it's long and extremely difficult to guess, which disqualifies your mother's maiden name, your birthday, Social Security number or your pet's name.

Breaches of online services servers include the theft of passwords, and they happen increasingly often these days. This results in data dumps existing online that contain troves of email address and password combinations, just waiting to be tested to see if they work for iCloud and other services.

Another common way to get passwords is through phishing attacks. Because of the high value of a stolen Apple account, Mac and iPhone users are frequently lured to fake Apple login pages that may look very much like the real thing.

And if you're already hit?

It's time to contact Apple Support to prove your identity and get their help in unlocking your machine. Click here to see if your local Genius Bar is accepting appointments today or start a chat or phone call with a rep.

TOPICS
Henry T. Casey
Managing Editor (Entertainment, Streaming)

Henry is a managing editor at Tom’s Guide covering streaming media, laptops and all things Apple, reviewing devices and services for the past seven years. Prior to joining Tom's Guide, he reviewed software and hardware for TechRadar Pro, and interviewed artists for Patek Philippe International Magazine. He's also covered the wild world of professional wrestling for Cageside Seats, interviewing athletes and other industry veterans.

Latest in Internet
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Large group of protesters in Turkey following Instanbul mayor's arrest
Turkey sees huge VPN usage spike amid reports of social media crackdown
NordVPN logo on a blue background
NordVPN drops to its lowest price this year – here's what you need to know
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
Latest in News
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #386 (Monday, March 24 2025)
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Sunday, March 23 (#651)
  • edgr69
    Seriously, you're accepting $$ from Kaspersky for advertising on your site. An interesting irony on an article about security.
    Reply
  • henrytcasey
    20197155 said:
    Seriously, you're accepting $$ from Kaspersky for advertising on your site. An interesting irony on an article about security.

    For more on that: https://www.tomsguide.com/us/kaspersky-safe-to-use,news-25516.html
    Reply