A FaceTime call from "Apple Support" is never Apple. It is a script to empty your bank account
Scammers are placing unsolicited FaceTime calls that pose as Apple Support or a bank's fraud department, then talking victims out of card numbers, banking logins, and one-time passcodes. Malwarebytes documented the wave on July 14, 2026. No malware is involved: the call itself is the weapon, because a live call in a trusted app feels too personal to be fake.
Is Apple really calling me on FaceTime?
Verdict: no. An unexpected FaceTime call from "Apple Support" or your bank's "fraud department" is a scam, every time. Apple's own security guidance is to just hang up on unsolicited calls claiming to be Apple or Apple Support, and to report suspicious FaceTime calls to [email protected]. Banks do not run fraud investigations over FaceTime either. Real support conversations start when you contact the company, through apple.com or the number on the back of your card, never with a surprise video call that wants you to "verify" card details, read out a one-time code, or install remote-access software.
7:41 on a Tuesday evening, and the screen says FaceTime
The phone lights up. Not a text, not an email in a spam folder: FaceTime, the app you use for your mother and your best friend, ringing with a caller label that looks like the company itself. One illustrative example of the style victims describe: a support-flavored name such as "Apple Support Advisor". That label is not a real Apple identity, and the exact wording varies from call to call, but the effect is the same: the most personal channel on the phone is suddenly wearing a corporate badge.
You answer. A calm voice with call-center hum behind it says there have been suspicious purchase attempts on your account. He can stop them, but first he must confirm you are the account holder. Card details. Then your online-banking login, "to check whether the fraud reached your bank." Then the finisher: "You will receive a six-digit code. Read it to me and I will reverse the charges." On other calls the close is different: install a small "support tool" so the agent can "secure the device."
The scene is a composite for illustration, but every beat comes from the caller script Malwarebytes documented on July 14, 2026. It is the video-call twin of the Apple security alert text with a callback number: same fraud-department story, except this time the criminal dials you.
What Malwarebytes actually reported
The warning, titled "Warning: Scammers are using FaceTime to empty bank accounts", describes criminals "making unsolicited FaceTime calls that look like they come from 'Apple Support' or a bank," often alongside messages dressed up as urgent account alerts or refund offers. Once the victim answers, the script is standard:
The caller claims there is fraudulent activity or a technical problem. They pressure the victim to "verify" card details, online-banking credentials, or Apple Account (Apple ID) information. In some cases they persuade the victim to install remote-access software or to share one-time passcodes.
The line in the report that matters most: "Nothing in this process requires malware on the device." The exploit is human trust, backed by familiar names and logos and, in Malwarebytes' words, "a real-time call that feels inherently more legitimate than a text message." The company's advice is equally blunt: treat unexpected FaceTime calls claiming to be your bank or Apple with suspicion, because these organizations are unlikely to use FaceTime for serious account issues.
In its 2025 Internet Crime Report, the FBI's IC3 recorded over $2.1 billion in losses to tech-support scams alone, in a record year of more than one million complaints. The FaceTime variant is the same con in a better costume.
Why a live video call cuts through your defenses
The channel carries the trust. Years of awareness training taught people to squint at emails and texts. Almost nobody has a reflex for FaceTime, because until now it was the app where only family and friends showed up. A call there borrows the intimacy of every real call you have ever taken on it.
A live voice removes your thinking time. An email waits while you Google the sender. A live caller keeps talking and walks you through each step before doubt can form. This is the same pressure engine behind every voice-phishing (vishing) scam, now upgraded with a video-grade channel, and it pairs naturally with AI voice cloning when the criminal needs a specific voice.
The name on screen is a claim, not a credential. Apple's own scam guidance warns that fraudsters "use fake Caller ID info to spoof phone numbers of companies like Apple." Whatever the FaceTime banner says, it proves nothing about who is on the other end.
And it can escalate beyond talk. Malwarebytes notes that attackers also combine Apple-branded social engineering with known, already-patched iOS vulnerabilities, profiting from the gap between "patch available" and "patch installed." Chained with a browser-side exploit, a con that started as a phone call can end in full system control; the report points to campaigns like DarkSword as examples of how that chain operates. The unglamorous defense: Settings, General, Software Update, plus Automatic Updates.
Catch the fake "verification" page before you type
SafeBrowz is a free browser extension for Chrome, Firefox, and Edge, with Safari pending, plus an Android app. It cannot answer or screen a FaceTime call, but the theft almost always needs your browser: the "verification" link the caller texts you mid-call, the fake banking portal, the download page for a remote-access "support tool." SafeBrowz checks that link the second it opens and flags Apple and bank lookalikes drawn from its 550+ brand database. The AI deep scan (Premium, $14.99/year) reads brand-new scam pages the same day they go live.
On a call right now and they sent you a link? Scan it free here first →
What Apple itself says about these calls
Apple's official page on recognizing and avoiding social engineering scams settles the "but what if it really is Apple?" doubt in one sentence: "If you get an unsolicited or suspicious phone call from someone claiming to be from Apple or Apple Support, just hang up." The same page tells users not to answer suspicious calls or messages claiming to be from Apple, and to contact Apple directly through official support channels, which are support.apple.com, getsupport.apple.com, and the Apple Support app.
Apple also draws hard lines that instantly unmask an impostor: it will never ask you to provide your password, device passcode, or two-factor authentication code, never ask you to enter them into a website, never ask you to tap Accept in a two-factor dialog, and never ask you to disable a security feature. "Apple never asks for this information to provide support." The moment a caller requests any of those, the identity question is settled.
For FaceTime specifically, Apple has a dedicated reporting path: take a screenshot of the call information (open FaceTime and tap the More Info button next to the suspicious call) and email it to [email protected]. A suspicious FaceTime link arriving in Messages or Mail goes to the same address, with the sender visible in the screenshot. In the US, scam calls can also be reported to the FTC at reportfraud.ftc.gov.
The same impersonation playbook has browser-based siblings we have covered: the fake "compromised iCloud" popup tech-support scam and the "Apple ID locked" phishing email. Different doors, same house.
Red flags that unmask the caller in the first minute
- The call arrived out of nowhere. You did not schedule a callback or open a support case. Apple and banks do not open fraud cases by surprise FaceTime call.
- The story is fraud, refunds, or a "technical problem" with a countdown. Manufactured urgency exists to stop you from hanging up and dialing the real number.
- They ask you to "verify" things they should already have. A real fraud department does not need you to read out your full card number or your banking password. It already knows who you are.
- Any request for a one-time passcode. That code approves a login or a payment. The only person who needs it is the one typing it into your account, and that is the scammer.
- "Install this tool so I can help you." Remote-access software hands the caller your screen and your sessions. No legitimate first-contact support call requires it.
- The name on the screen is doing all the work. Nothing else about the call proves identity. A caller ID can be dressed up; a hang-up-and-call-back cannot.
You answered. Maybe you talked. Do this, in this order.
Hang up first. Mid-sentence is fine. Every extra minute of politeness is scripted to extract one more detail.
If you shared card details: call the number on the back of the card, have it blocked and reissued, and watch the next statements for small "test" charges.
If you shared your online-banking login: change the password immediately by typing your bank's address yourself or using its official app, then tell the bank's fraud team what happened. Our bank phone-scam guide walks through the full callback-and-freeze sequence.
If you read out a one-time passcode: assume the transaction or login it protected has already gone through. Call the bank now and ask them to review the most recent activity and block further transfers.
If you installed anything: disconnect the device from the internet, delete the remote-access app, and change your important passwords from a different device before reconnecting.
If your Apple Account credentials went out: change the password right away in Settings or at account.apple.com, and review your trusted devices.
Then report it: the FaceTime screenshot to [email protected], the incident to reportfraud.ftc.gov, and, if money actually moved, a complaint to the FBI's IC3. Reports are what turn one victim's bad evening into a takedown.
When the call itself is the phish, catch what it sends next
Honest scope first: SafeBrowz protects in the browser, so it cannot see, screen, or block a FaceTime call. No browser tool can. What it can catch is the part of this scam that lives outside the call, and almost every version of the script eventually goes there: the "secure verification" link sent by text mid-call, the fake bank fraud portal, the download page for the remote-access "support tool." SafeBrowz runs its 3-layer detection (Local + APIs + AI) on exactly those pages.
- Layer 1 - Local detection: 60+ URL patterns and a 550+ brand database, including Apple and the major banks these callers impersonate, run in the extension before the page renders. An "Apple verification" or bank-branded page sitting on a domain neither company owns trips the brand-on-wrong-domain signal instantly.
- Layer 2 - API checks: Google Safe Browsing, PhishTank, URLhaus, ScamAdviser, and 30+ scam TLD lists, aggregated server-side. Support-scam portals are usually days old, and a freshly registered domain with no history is itself a weighted signal even before the feeds list it.
- Layer 3 - AI deep scan (Premium): AI content analysis (via our proxy, 100+ languages) reads the page the way a fraud analyst would: the fake fraud-alert layout, the passcode-entry box, the "download this tool so an agent can assist you" framing, and returns a danger verdict in seconds.
The division of labor is clean: your job is the call (hang up), SafeBrowz's job is the link.
Detection signatures are derived from threat-intelligence research and our internal brand database, not from user browsing data. SafeBrowz does not store per-user browsing history.
Test a suspicious link right now
Did a "support" caller send you a link to verify your account? Paste it here before you open it. Our 3-layer engine (Local + APIs + AI) returns a verdict in ~3 seconds. Free, no signup. Whatever the verdict says, never read a one-time passcode to anyone on a call.
Frequently asked questions
Is a FaceTime call from Apple Support real?
No. Apple's security guidance tells users to hang up on unsolicited calls from anyone claiming to be Apple or Apple Support, and it asks users to report suspicious FaceTime calls to [email protected]. Malwarebytes documented in July 2026 that criminals are placing unsolicited FaceTime calls posing as Apple Support or a bank to pressure victims into sharing card details, banking credentials, and one-time passcodes. Treat any unexpected FaceTime call from a company as hostile: hang up, then contact the company yourself through its official app or website.
Does Apple ever call customers on FaceTime or by phone?
Apple support conversations start with you. You request help through the Apple Support app, support.apple.com, or by scheduling a callback yourself, and Apple's guidance for anything unsolicited is simply to hang up and use official channels instead. Whatever the channel, Apple says it will never ask for your password, device passcode, or two-factor authentication code, never ask you to enter them into a website, and never ask you to disable a security feature. If a caller does any of those things, you already know it is not Apple.
Why are scammers using FaceTime instead of a normal phone call?
Because the channel itself carries trust. People have learned to be suspicious of emails and texts, but FaceTime has always been the app where only family and friends appear, so a corporate-looking call there feels verified even though it is not. Malwarebytes put it plainly: a real-time call "feels inherently more legitimate than a text message," and nothing in the scam requires malware, because the exploit is human trust. A live caller also removes your thinking time: no pause to check anything while a voice keeps walking you to the next step.
I gave the caller a code, card details, or my banking login. What now?
Act in this order. Hang up. Call the number on the back of your card and have compromised cards blocked and reissued. Change any password you revealed by typing the official site yourself or using the official app, never a link you were sent. Treat a shared one-time passcode as an approved transaction and ask the bank to review the latest activity immediately. If you installed a remote-access tool, disconnect the device, delete the app, and change passwords from a different device. Then report: [email protected] with a screenshot of the call, reportfraud.ftc.gov, and FBI IC3 at ic3.gov if money was taken.
How do I report and block a scam FaceTime call?
Open FaceTime, tap the More Info button next to the suspicious call, and take a screenshot of the call information, then email that screenshot to [email protected]. If a suspicious FaceTime link arrived in Messages or Mail, screenshot it with the sender's number or email address visible and send it to the same address. From the same call-info screen you can also block the caller. In the US, report scam calls to the FTC at reportfraud.ftc.gov, and file with the FBI's IC3 if you lost money.
Last updated 2026-07-20