How to keep your Apple account safe from scams

By Malcolm Owen

Keeping yourself safe online can be hard, with scams becoming more sophisticated over time. Here's how you should protect yourself, and your Apple account.

A scam caller or email could be a risk to your personal information.

Cybercrime is a growing problem, with online denizens often at risk of account hacks, data breaches, and scams. With the continuing rise of data breaches, it's now becoming very easy for a scammer to get snippets of information that they can use against you.

The criminals are only going to escalate, so users need to learn how to protect themselves.

Even with the best password management apps and the highest levels of encryption available to consumers, the users themselves continue to be the biggest weak point. Criminals don't need to break an account's security, they only have to convince you to help them.

As a privacy and security-focused company, Apple has moved to release more resources to help users become safer online. These documents, in the support pages, outline many of the ways that users can do something to prevent bad things from happening to their accounts.

What follows is a summary of some of the more important things to keep in mind when dealing with potential scams online.

Social Engineering and Phishing

A high-class way of saying "Telling lies that seem truthful to get something valuable," social engineering refers to a very common attack vendor. One that relies on an attacker impersonating others, such as Apple support staff or those calls from "Microsoft Support" that frequently annoy people.

Often, the attacker pretends to be a legitimate representative of a company that you may have dealings with, such as Apple. They will then try to do various things to con you into offering up information that could be used to access your accounts, such as sign-in credentials or security codes.

In some cases, the hackers will use data scraped from major data breaches as a starting point. For example, in January, a Trello data breach exposed over 15 million accounts, including names, user names, and email addresses.

If someone calling you is able to tell you your own name, address, date of birth, or other credentials, victims may be convinced that the caller is legitimate. The caller then may willingly offer more information to the fraudster, since they have seemingly proved they are "legitimate."

Another type of attack is phishing, which is basically the same sort of thing, but performed over email or messaging services. Aside from supposed emails from Nigerian royalty, phishing attacks can look like vaguely legitimate emails from real companies.

These messages often insist that the user could benefit from something, that something has gone wrong, or be as trivial as a fake warning that someone has requested a password reset.

If you get a call or a message from a seemingly legitimate company and you're not sure if it's a scam to get your credentials, you should contact the company directly through official channels instead.

You don't have to go this far, though, as there are often clues in messages and emails that they are not legitimate.

How to identify fraudulent emails and messages

Apple accounts

While Apple does have a lot of protective measures on accounts, it cannot defend against every threat. That's especially true if Apple users are convinced to hand over their information.

This is what Apple says you should do to protect your Apple account and devices:

How to protect your Apple accounts from scammers

Reporting suspicious contacts

In the instance that you're getting contacted by someone who claims to be Apple but isn't, you can do a few things to help the company thwart their efforts.

Also, remember that Apple has a list of other resources to help keep your personal data and accounts safe.

  翻译: