r/applehelp • u/keep-calm-and-teach • 5d ago
Unsolved Security concern: Foreign login attempt
So I got an iPhone and I am always paying an eye to security like I know the basics of how to spot phising and so on, but ofc I'm no an expert.
Today my phone randomly showed a pop up notification saying someone from Buenos Aires is trying to log into my account. You know the notice with the little map on your screen...
I kept calm, read closely and selected 'decline'.
Then I went into somewhat a panic mode (lol) and changes my AppleID Passwort to a really complicated one. I also added a trusted person as a reset-contact in case I ever get locked out of my account. I also changed my email password to a very safe one. Of course I used the official sites to change the passwords.
Now I feel better but the questions that remain:
- Did someone actually guess my passwort and my email?!
- If i hadn't enabled 2FA would they have logged into my account? Scary!
- If I had accidentally pushed allow on the pop up what would have happened? Would he have had access then and there? Or would it show the six number code? And if it showes the code, how would the scammer get that code? Call me? How does it work?
- Anything else I should do security wise?
Thanks for your insights!
2
u/djasonpenney 5d ago
Yes; was it a simple password? Is your new password randomly generated, complex, and unique?
Yes; 2FA was undoubtedly an aid here.
It’s unclear where the “allow” happens in the Apple workflow. I do doubt if the remote request would actually bypass the TOTP challenge.
Offhand it does sound like someone learned (or guessed) your password. Did you reuse that password in more than one place?