Fake Email from AT

I keep getting emails from Apple team that are obviously fakes but they know when I changed my password, how is it possible

Posted on Nov 13, 2018 7:00 AM

Reply
Question marked as Top-ranking reply

Posted on Nov 13, 2018 8:12 AM

It is possible that this person has access to your email account that you use for your Apple ID credential.

If they do, they would ALSO get an email notification whe you change your Apple ID password -


Change your password to your EMAIL account - actually change every password for everywhere there are logins

29 replies

Nov 13, 2018 10:27 AM in response to Pinucciore

OK

It appears that your badoo account was compromised

Nothing to do with your Apple ID

You can TRY to get badoo to help with that issue

Your badoo account had your phone number as a detail in the account information - if they were IN your account, then the badoo system assumed that they were YOU


The phishing attempt - Apple "purchase" that you did not make - was a good guess that you used the same email address for badoo as for your Apple ID


IF you are using a password ANYWHERE that was provided by the "criminal" you need to change it = NOW.


To secure your Apple ID - and any other "membership" that has this feature - you need to enable

Get a verification code and sign in with two-factor authentication - Apple Support

OR

Switch from two-step verification to two-factor authentication - Apple Support


Read these CAREFULLY - then take action

Nov 13, 2018 9:57 AM in response to Pinucciore

Pinucciore wrote:


Re: [info new statement] new notification updated, new statement and account updated, your account has changed password, 10 Nov 2018 [FWD] [MCD]


Apple support <***@kambinmabok .***>


A: support@apple.com


this is the mail

No possible way that this is APPLE


IF

indeed you changed your Apple ID password at

https://appleid.apple.com/account/manage

THEN

this person has your email account password so that they can access your email account INBOX to SEE the notification FROM Apple about the password change

OR

they are guessing


[Email Edited by Host]

Nov 13, 2018 8:43 AM in response to Pinucciore

Ah. Okay, that makes more sense.


The two fake emails are just that. Fakes with no connection to your account.


The one you received after changing the password was indeed from Apple. It's an automatically generated message to let the owner of the account know the password was changed. For the obvious reason if you didn't change it, you would want to be notified.


The message from Apple also should have also included a line that says something like, "Your account password was recently changed. If you are aware of this, you can disregard this message."

Nov 13, 2018 9:55 AM in response to ChitlinsCC

As Chitlins noted, the first is clearly not from Apple. Not with that return address. But, you already guessed that much.


The second is from Apple. As I noted earlier, it's nothing more than an automatically generated message to let the owner of the account know someone changed the password. You already know it was changed and the person who did it was you.


The person sending the fake messages from kambinmabok.biz knows nothing about the password change.

Nov 13, 2018 10:26 AM in response to ChitlinsCC

The second APPEARS to be from Apple - BUT - "support" is not a mailbox account that Apple would use…

No, it's from Apple. What's in front of the @ symbol isn't part of the domain. In this case, it's apple.com, which can only be from Apple. If you do a whois on the address, it resolves to Apple.


Queried whois.internic.net with "dom apple.com"...

Domain Name: APPLE.COM

Registry Domain ID: 1225976_DOMAIN_COM-VRSN

Registrar WHOIS Server: whois.corporatedomains.com

Registrar URL: http://www.cscglobal.com/global/web/csc/digital-brand-services.html

Updated Date: 2017-07-06T03:10:21Z

Creation Date: 1987-02-19T05:00:00Z

Registry Expiry Date: 2021-02-20T05:00:00Z

Registrar: CSC Corporate Domains, Inc.

Registrar IANA ID: 299

Registrar Abuse Contact Email: domainabuse@cscglobal.com

Registrar Abuse Contact Phone: 8887802723

Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited

Name Server: A.NS.APPLE.COM

Name Server: B.NS.APPLE.COM

Name Server: C.NS.APPLE.COM

Name Server: D.NS.APPLE.COM

Name Server: E.NS.APPLE.COM

Name Server: F.NS.APPLE.COM

DNSSEC: unsigned

URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/

>>> Last update of whois database: 2018-11-13T13:20:11Z <<<

Queried whois.corporatedomains.com with "apple.com"...

Domain Name: apple.com

Registry Domain ID: 1225976_DOMAIN_COM-VRSN

Registrar WHOIS Server: whois.corporatedomains.com

Registrar URL: www.cscprotectsbrands.com

Updated Date: 2018-09-27T20:53:12Z

Creation Date: 1987-02-19T05:00:00Z

Registrar Registration Expiration Date: 2021-02-20T05:00:00Z

Registrar: CSC CORPORATE DOMAINS, INC.

Registrar IANA ID: 299

Registrar Abuse Contact Email: domainabuse@cscglobal.com

Registrar Abuse Contact Phone: +1.8887802723

Domain Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited

Registry Registrant ID:

Registrant Name: Domain Administrator

Registrant Organization: Apple Inc.

Registrant Street: One Apple Park Way

Registrant City: Cupertino

Registrant State/Province: CA

Registrant Postal Code: 95014

Registrant Country: US

Registrant Phone: +1.4089961010

Registrant Phone Ext:

Registrant Fax: +1.4089741560

Registrant Fax Ext:

Registrant Email: domains@apple.com

Registry Admin ID:

Admin Name: Domain Administrator

Admin Organization: Apple Inc.

Admin Street: One Apple Park Way

Admin City: Cupertino

Admin State/Province: CA

Admin Postal Code: 95014

Admin Country: US

Admin Phone: +1.4089961010

Admin Phone Ext:

Admin Fax: +1.4089741560

Admin Fax Ext:

Admin Email: domains@apple.com

Registry Tech ID:

Tech Name: Domain Administrator

Tech Organization: Apple Inc.

Tech Street: One Apple Park Way

Tech City: Cupertino

Tech State/Province: CA

Tech Postal Code: 95014

Tech Country: US

Tech Phone: +1.4089961010

Tech Phone Ext:

Tech Fax: +1.4089741560

Tech Fax Ext:

Tech Email: apple-noc@apple.com

Name Server: a.ns.apple.com

Name Server: f.ns.apple.com

Name Server: e.ns.apple.com

Name Server: d.ns.apple.com

Name Server: c.ns.apple.com

Name Server: b.ns.apple.com

DNSSEC: unsigned

URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/

>>> Last update of WHOIS database: 2018-09-27T20:53:12Z <<<

Nov 13, 2018 9:27 AM in response to Pinucciore

Then we can do nothing but guess about the information you've provided. Your last post on who sent what said:

the problem is that was also a fake from the same person;

So far, that makes sense since you said you received two fake emails from the same person. But then you confuse that statement with:

that's why I am asking how did he know that i changed the pass

Then we're back to, "How does who know?" We can't read your mind. If it's nothing more than a genuine email from Apple informing you your password has been changed, then then the crook sent nothing and knows nothing about the password change.


Post just the sender's address on the one noting the password change.

Nov 13, 2018 10:13 AM in response to ChitlinsCC

last few days quite a few strange things happened: I realised that on a chat (badoo) my profile had been hackered by someone who put some photos ( òf him, or stolen, I don`t know) and mine finished in a private album, he also changed the pass a send me the new pass by message on my phone (I had phone number a email adress that only me and the amministrators could see)so I deleted (?) my profile. Than I received another message with a code of something i bought; so I cecked my card but there were no new transaction; than I get those mail …. I don`t really knowwhat is happening

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Fake Email from AT

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.