Substrate
technology

Infoblox Maps Underground Market for iPhone Unlocking Tools and Related Phishing Sites

Researchers identified more than 10,000 phishing websites tied to stolen iPhone unlocking services, with traffic surging 350 percent last year. The pay-per-use tools, costing less than $10 on average, target devices through physical access and social engineering. London police reported 80,000 phones stolen in one year as thieves seek access to financial accounts.

Wired
itsecuritynews.info
2 sources·May 14, 10:00 AM(15 days ago)·3m read
|
Infoblox Maps Underground Market for iPhone Unlocking Tools and Related Phishing Sitesitnews.com.au
Audio version
Tap play to generate a narrated version.
Developing·Limited corroboration so far. This page will refresh as more sources emerge.

Cybersecurity researchers have mapped an underground ecosystem that supplies criminals with tools to unlock stolen iPhones and launch phishing attacks against their owners' contacts. Infoblox researchers started looking into the stolen-phone unlocking economy earlier this year after a law-enforcement-related contact in Asia had their iPhone stolen and received a phishing message after including alternative contact details on the locked device.

The phishing page mimicked an Apple Find My page, showed a false map with the phone’s location, and then showed a pop-up asking for the phone’s PIN code.

Infoblox tracked dozens of groups selling unlocking tools, mostly focused on iPhones, and linked more than 10,000 phishing websites to the stolen iPhone unlocking activity. Traffic to these phishing domains increased 350 percent last year. The average cost of the pay-per-use unlocking software is below $10.

“Reselling is 100 percent what they are going for and people from all around the world appear to be buying access to the pay-per-use software,” Maël Le Touz, a staff threat researcher at Infoblox, stated. ” Around 80,000 devices were taken in London in one year.

“Phone thieves don’t just want the handset—they want access to bank accounts and personal information,” Will Lyne, the head of economic and cybercrime at London’s Metropolitan Police, stated.

Four men were caught handling more than 5,000 stolen phones and spending money from financial accounts on the devices. Dan Guido, the CEO and cofounder of security firm Trail of Bits and a strategic adviser to mobile security firm iVerify, stated that a stolen phone may only be worth $50 to $200 when it is locked but if you unlock it, it’s worth $500, or it’s worth $1,000.

Numerous people online and the Swiss National Cybersecurity Center have reported receiving phishing messages after losing or having their iPhones stolen.

The Swiss National Cybersecurity Center reported in November that to make the messages look convincing, attackers include accurate details of the missing device such as its model, colour, and storage capacity which the scammers can read directly from the phone itself.

The Swiss National Cybersecurity Center stated that as there is no known way to bypass this lock, tricking the owner through social engineering is the only realistic option for criminals. Infoblox researchers created DNS fingerprints for the phishing domain and tracked other related Apple look-alike websites.

Some of the tracked websites exposed their administration login pages and advertised tools to unlock phones. Infoblox researchers identified multiple groups on Telegram pushing unlocking services. The unlocking services commonly feature unlocking tools that claim to jailbreak older iPhones or Android devices and pull owner information from phones, phishing kits referred to as Find My iPhone Off, and scripts and AI voice calling software to run the phishing operations.

“What you need first of all is physical access to the phone and if jailbreaks do not work some of the systems can be used to launch phishing attacks and collect unlocking information,” Maël Le Touz stated. All the tools analyzed wipe the device by default as soon as access is attained.

A video obtained by the researchers shows software called iRealm generating phishing links and pages mimicking Apple services.

After WIRED contacted Telegram about the phone unlocking channels, Telegram removed half a dozen groups linked to the services. A Telegram spokesperson stated that phishing and the promotion of tools that enable it can and does happen through every method of communication from messengers to email to phone calls and that the platform has industry-leading moderation.

Apple did not respond to WIRED’s request for comment by the time of publication.

Wired reported these findings.

Key Facts

Infoblox linked more than 10,000 phishing websites to stolen
Researchers tracked dozens of groups selling pay-per-use tools costing below $10 on average, with traffic to domains rising 350 percent last year
Physical access remains essential for unlocking
Tools jailbreak older devices or trigger phishing; all analyzed tools wipe the device by default once access is gained
London recorded 80,000 stolen phones in one year
Metropolitan Police arrested four men handling over 5,000 stolen devices used to access financial accounts

Story Timeline

5 events
  1. 2025

    Traffic to phishing domains linked to stolen iPhone unlocking increased 350 percent

    1 sourceWired
  2. November 2025

    Swiss National Cybersecurity Center warned about phishing messages containing accurate device details

    1 sourceWired
  3. Early 2026

    Infoblox began investigating after law-enforcement contact in Asia received phishing message on stolen iPhone

    1 sourceWired
  4. 2026

    Infoblox identified dozens of groups, over 10,000 phishing sites, and multiple Telegram channels selling unlocking tools

    1 sourceWired
  5. 2026-05-15

    Telegram removed half a dozen groups after contact from WIRED

    1 sourceWired

Potential Impact

  1. 01

    Law enforcement faces growing challenge as small-scale thieves gain affordable access to professional-grade unlocking and phishing kits

  2. 02

    Unlocked phones increase in resale value from $50-200 to $500-1,000, incentivizing theft and phishing

  3. 03

    Phishing messages now include precise device details read directly from the stolen phone, raising success rates against owners

  4. 04

    Telegram removed multiple selling groups following media inquiry, temporarily disrupting distribution channels

Transparency Panel

Sources cross-referenced2
Confidence score75%
Synthesized bySubstrate AI
Word count597 words
PublishedMay 14, 2026, 10:00 AM
Bias signals removed2 across 1 outlet
Signal Breakdown
Loaded 2

Related Stories

World Urban Forum 2026 Draws 57,000 Participants from 176 CountriesEuronews
technology4 hrs agoDeveloping

World Urban Forum 2026 Draws 57,000 Participants from 176 Countries

The 13th World Urban Forum concluded with discussions on housing, climate resilience and urban governance. Organisers reported that the sessions informed future strategic priorities.

Euronews
1 source
Trump Mobile website still lists T1 phone as American-madetheverge.com
technology4 hrs agoDeveloping

Trump Mobile website still lists T1 phone as American-made

The product page for the T1 phone continues to describe the device as American-made. The Verge reported that the site may conflict with FTC advertising rules. The phone was announced in June 2025.

The Verge
1 source
EU Discusses Readiness for Artificial Intelligence ChangesFrance 24
ai4 hrs agoDeveloping

EU Discusses Readiness for Artificial Intelligence Changes

A France 24 program examined whether European Union policies can address the effects of artificial intelligence. The discussion covered potential impacts across daily life and economic sectors.

France 24
1 source