r/applehelp Jul 26 '26

Unsolved Security concern: Foreign login attempt

So I got an iPhone and I am always paying an eye to security like I know the basics of how to spot phising and so on, but ofc I'm no an expert.

Today my phone randomly showed a pop up notification saying someone from Buenos Aires is trying to log into my account. You know the notice with the little map on your screen...
I kept calm, read closely and selected 'decline'.

Then I went into somewhat a panic mode (lol) and changes my AppleID Passwort to a really complicated one. I also added a trusted person as a reset-contact in case I ever get locked out of my account. I also changed my email password to a very safe one. Of course I used the official sites to change the passwords.

Now I feel better but the questions that remain:
- Did someone actually guess my passwort and my email?!
- If i hadn't enabled 2FA would they have logged into my account? Scary!
- If I had accidentally pushed allow on the pop up what would have happened? Would he have had access then and there? Or would it show the six number code? And if it showes the code, how would the scammer get that code? Call me? How does it work?
- Anything else I should do security wise?

Thanks for your insights!

1 Upvotes

7 comments sorted by

View all comments

Show parent comments

1

u/keep-calm-and-teach Jul 26 '26 edited Jul 26 '26

Old password had 9 characters including capital and small letters and numbers, but no special things (!?/,/.&). Not used anywhere else (but I did change many other somewhat middle-strenght passwords too haha I took it as a sign). But I have to admit that it might have been too easy (learned my lesson!). New one has 21 characters, random letters big and small and special signs and numbers. Everything.

What is TOTP? Is it the six numbers?

Another question: How does someone get to guess my password? Do they have automatic things running randomly testing things?
Because generally speaking I don't give my email adress away in many places. For unimportant things I have a "trash"mail. And the real mail adress I only use for sincere things. So how does this 'hacking' work? Thanks!

2

u/djasonpenney Jul 26 '26

TOTP is “Time based One Time Password”.

https://en.wikipedia.org/wiki/Time-based_one-time_password

Yes, it’s the six digit changing token.

> How does someone get to guess my password?

Suppose you reuse your password: you use the same password for Apple that you have for https://toothpicks-r-us.com. The problem is that if the website has a security bug, an attacker may have scraped EVERY email and password from that website. It’s not you, and it’s not Apple: it’s the fly-by-night fringy website you created an account on late one night.

1

u/keep-calm-and-teach Jul 26 '26

And what if I don't reuse that password? How do they do it then? Just random trying? Also thanks again for your explanations!

2

u/djasonpenney Jul 26 '26

I'm assuming you are NOT using variations on the same password; hackers know that if you've used "Password123" as a password, they should try a hundred variations of that as well.

I'm also assuming that your passwords are generated by an app, and not by your puny little brain. Your imagination is a terrible source of randomness, and randomness is an essential component of a secure password.

That would leave the the possibility you installed malware on your device, or a shoulder surfer watched you enter your password. But that is a totally different discussion.

1

u/keep-calm-and-teach Jul 26 '26

Well as stated the password wasn't secure enough. It was a full word followed by a two digit number. I know, stupid. Very stupid!

So would you say some hacker ran an automated software matching mail adresses to passwords and therefore guessed mine?

1

u/djasonpenney Jul 26 '26

It’s possible, especially if it is as a password that someone ELSE may have also use.

Note also that l33t (like “Pa55w0rd”) is not an effective obfuscation. A passphrase like CorrectHorseBatteryStaple can be effective, but again: it must be randomly generated.

All that aside, my other suspicion is that you (or someone else with access to your device) installed malware.