Skip to main content
LiMP VPN
All news

iPhone 18 Launch Day Phishing: Kaspersky Warns as Pre-Orders Go Live

iPhone 18 Launch Day Phishing: Kaspersky Warns as Pre-Orders Go Live

In short: September 12, 2026 — the day Apple opened iPhone 18 Pro and iPhone 18 Pro Max pre-orders — Kaspersky and BI.ZONE AntiFraud documented a mass phishing wave. Fraudsters are sending fake "Apple Store" emails about a non-existent "iPhone 18 Ultra Pro" model, claiming a $900–$1,000+ payment has already been charged and urging victims to call "support" to cancel. Those calls hand over card details and Apple ID credentials to scammers. The volume of such schemes is running three times higher than it did during the iPhone 16 launch.

Three scam schemes active on pre-order day

Researchers at Kaspersky, reported by SecurityLab.ru, documented three distinct schemes that launched precisely when buyer interest peaks.

Scheme 1 — Fake pre-order confirmation. An email purportedly from Apple Store informs you that you placed a pre-order for an "iPhone 18 Ultra Pro" (a model that does not exist) and that over $1,000 in cryptocurrency has already been charged. To "cancel" the payment, you are asked to call a provided number. The person who answers is a fraudster after your card details or account credentials.

Scheme 2 — Fake payment alert. An email supposedly from a well-known payment platform warns of a login from an unrecognised device and a transfer of $900+ for an "iPhone 18 pre-order." The mechanism is the same: a call to "security" leads to handing over sensitive data.

Scheme 3 — Colour-choice phishing page. An email offers you the chance to be first to receive an iPhone 18 Pro by selecting your preferred colour. The link leads to a fake checkout page designed to harvest payment details. According to WhoisXML API researchers, iPhone 18 phishing sites began appearing at least two weeks before Apple's September 9 announcement — and by pre-order day many had not yet been added to browser blocklists.

Scale: three times worse than the iPhone 16 launch

BI.ZONE AntiFraud analysts forecast a 25–27% rise in fraud campaigns compared with the previous iPhone generation. Reality has already outpaced that estimate: at the iPhone 17 launch, scam incidents came in three times higher than during the iPhone 16 launch. Experts expect the iPhone 18 wave to be at least as large. A compounding factor: pre-orders opened on a Saturday–Sunday (12–13 September), when bank and corporate security teams operate with reduced capacity — and fraudsters plan around that.

This is not the first campaign to exploit product-launch hype. Similar fake payment-notification schemes appear whenever a high-profile event creates urgency and pushes people to act before thinking.

Why the emails look convincing

Apple-launch phishing campaigns are traditionally well-crafted: the design imitates Apple Store or payment-service branding, the amounts look plausible, and the implied error creates a sense of urgency. This round adds an extra detail: the letters mention a model called "iPhone 18 Ultra Pro," which does not exist in Apple's lineup. Recipients who have not memorised the official model list accept it as real — it simply sounds credible.

An important technical note: many iPhone 18 phishing pages are already flagged in threat databases but have not yet been added to browser blocklists. That means a link in the email will load without a warning, even though the site is fraudulent.

How to spot the scam — and what to do if you already received one

A few immediate signals separate phishing from genuine Apple communications.

Apple never requests cryptocurrency payments. If an email mentions crypto, Bitcoin or any other digital asset — it is a scam, without exception.

The sender address is not apple.com. Real Apple emails come only from @apple.com. A long subdomain such as @apple-orders-support.com is not Apple.

Do not call numbers in the email. If you need to check an order, open apple.com manually in your browser and sign in to your account there.

Never enter card details or your Apple ID through email links, even if the page looks authentic.

If you have already followed a link and entered data — change your Apple ID password immediately, block the compromised card through your bank's app, and enable two-factor authentication if it was not already on. You can follow more breakdowns of current scam schemes on our blog.

How to keep mobile data genuinely safe

This phishing wave targets iPhone and Android users who follow new product launches and shop from their phones. A small set of habits blocks the majority of risks.

Buy Apple products only from apple.com or authorised resellers. Verify a seller's authorisation at locate.apple.com/sales. Never follow email or ad links — type the address into your browser directly.

Turn on two-factor authentication for your Apple ID. Even if an attacker obtains your password, they cannot sign in without the second factor.

Encrypt your traffic on untrusted networks. In airports, cafes and shopping centres, your unprotected traffic is visible to anyone on the same network. LiMP VPN for iOS and Android encrypts your connection and replaces your real IP with a server address: the network owner and your ISP cannot see what you open, and the no-logs policy means the service itself keeps no record of your visits. One honest limit: a VPN protects your traffic in transit but cannot stop you from typing a password into a phishing page — that is where the habits above matter. See LiMP VPN plans to add this layer of mobile protection.

Sources

iPhone 18 Launch Day Phishing: Kaspersky Warns as Pre-Orders Go Live