Warning of a scam that allows thieves to steal your money via a locked iPhone!

A technical report published by the American magazine Forbes has warned of a serious security vulnerability that allows criminals to bypass the lock screen on iPhones, withdraw funds from bank accounts and digital payment apps, without needing to know the passcode or use Face ID, by exploiting a feature originally designed for user convenience. The report, authored by tech expert David Filan, explained that this trick relies on exploiting the “Control Center” feature, which can be accessed even when the phone is locked, giving the thief a window to disable cellular connectivity and Wi-Fi networks, isolating the device from the world before the victim can activate the remote Lost Mode.
The report stated that the danger does not lie in the theft of the phone itself, but in the thief’s ability to drain bank accounts after seizing the device, by accessing apps such as Apple Pay and Venmo, which may not require additional verification after the phone is unlocked for the first time, or by exploiting passwords stored in the iCloud Keychain if the thief can guess the passcode by observing the victim beforehand. The report quoted information security experts warning that this method has become common in major cities, where specialized gangs monitor victims in bars and cafes to learn their secret codes before stealing their phones.
The report emphasized that the core weakness is not limited to the technical aspect alone, but extends to user behavior itself, which can be summarized in the following preventive measures:
• Disable access to the Control Center when the phone is locked by going to “Settings,” then “Face ID & Passcode,” scrolling down, and turning off the “Control Center” option, which prevents the thief from putting the phone in Airplane Mode or cutting off internet connectivity.
• Enable the option to automatically erase data after 10 failed passcode attempts, a strict measure that ensures the thief cannot access the content even if they guess the code.
• Avoid entering the passcode in crowded public places, and use Face ID or Touch ID exclusively, covering the screen with your hand when absolutely necessary to enter the code manually.
The report noted that Apple has been aware of this vulnerability for some time, but believes that the solutions currently available within the device settings are sufficient if applied by the user, cautioning that the balance between security and ease of use remains a chronic challenge in the world of smartphones. In this context, the expert advised users to enable two-factor authentication on all financial applications and not to rely solely on device protection, because a thief who succeeds in breaching the first layer of security may find the path paved to other accounts.
Experts stressed that awareness of these tricks is the first line of defense; the phone is not just a communication device, but the key to an individual’s digital and financial identity in the 21st century, and handling it with caution and precaution is no longer a luxury but a necessity. The bottom line is that investing a few minutes in adjusting security settings could be the difference between a catastrophic financial loss and an ordinary day where the incident passes without leaving a trace.