Received a strange email in Russian with contents of one of my Notes! Is this a vulnerability issue?

Yesterday, a colleague received a Russian spam email to our product’s support email account. This isn’t unusual but he translated it out of interest and found that it was the majority of one of his notes from Notes on his Mac. We’ve been investigating since but found no explanation or cause so far.


A day or so before, he’d deleted that note from Notes but copied the contents of it into his clipboard to paste it elsewhere.

He’s now changed his passwords, particularly on his iCloud account, email etc and run a virus scan of his Mac which was clean. He’s running the latest MacOS and iOS versions and was prior to copying/deleting the note in question.


The strange things are that the note wasn’t sent to his iCloud email address, it was to a completely unassociated support email, so it seems like this iCloud account wasn’t compromised. The rest of the spam email was genuine spam linked to medical equipment and other random things rather than any threats or ransom-type messages.


It almost feels like he may have inadvertently visited a compromised website after copying his note text which pulled it from his clipboard through Safari. Or maybe used a compromised app in his phone or Mac.


We’re trying to figure out how this could have happened and would appreciate the thoughts of the community. Are there any know vulnerabilities which could cause this? I’ve heard of the universal clipboard causing headaches but I thought it notified if something pasted from it without your knowledge?


Any help or suggestions would be appreciated.

Posted on May 28, 2021 12:47 AM

Reply

Similar questions

1 reply

May 28, 2021 4:00 AM in response to pimmie

The virus scan on associates computer. Firstly, there are no known viruses in the wild that self replicate and affect macOS. There is Malware and Adware that do affect macOS and are often downloaded as Bundled in Applications downloaded from Third Party site and not from the Apple Apps Store or from Trusted and Reputable Developers.


Having said all this - the only Reputable software to remove Malware / Adware are Malwarebytes and / or EtreCheck - both Trusted Developers and Respected ASC Contributors. Both are free or paid for added features.


As for the real issue at hand - the AV Software used by Associate - per chance is software is compromised or Russian in Origin and is really the source of the Notes Issue

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Received a strange email in Russian with contents of one of my Notes! Is this a vulnerability issue?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.