Apple

Beware! Hackers Attacking Thousands of Users With Fake iCloud Storage Alert

Since Apple iCloud saves sensitive and personal data like images, emails, and documents, hackers often target Apple iCloud.

Breaching iCloud grants hackers access to sensitive information, allowing them to abuse or sell the data for financial gain and other illicit objectives.

Not only that, but even successful iCloud breaches may also lead to unauthorized access to the connected devices and services.

Cybersecurity analysts at Avast Security recently discovered that hackers actively attack thousands of users with fake iCloud storage alerts.

Document
Free Webinar

Fastrack Compliance: The Path to ZERO-Vulnerability

Compounding the problem are zero-day vulnerabilities like the MOVEit SQLi, Zimbra XSS, and 300+ such vulnerabilities that get discovered each month. Delays in fixing these vulnerabilities lead to compliance issues, these delay can be minimized with a unique feature on AppTrana that helps you to get “Zero vulnerability report” within 72 hours.

Fake iCloud Storage Alert

Avast recently warned of a new scam in which hackers are actively attacking thousands of users with fake iCloud storage email alert which states:-

“Your iCloud storage is nearly full”

In this new scam, threat actors primarily targeted users from the following countries:-

  • United States of America
  • France
  • Australia
  • Italy
  • Spain

The fake email alert contains malicious content like Phishing URLs that the threat actors could exploit to steal sensitive, personal, and financial data from the targeted users.

Hackers exploit phishing methods as they effectively trick individuals into revealing sensitive information.

Fake alert 1 (Source – Twitter)
Fake alert 2 (Source – Twitter)
Fake alert 3 (Source – Twitter)

Phishing often involves tricky emails or websites that appear legitimate, and by manipulating human psychology, the threat actors gain unauthorized access to accounts and conduct illicit activities.

As a recommendation, security experts strongly urged users to remain vigilant and beware of emails received from unknown sources.

IoCs

  • skystarsfavouritetra4ffic[.]top
  • orchardgroove[.]com
  • outdoor-garden[.]club

Try Kelltron’s cost-effective penetration testing services to evaluate digital systems security. available.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

18 seconds ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

6 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

17 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago