Warning: Scammers are using FaceTime to empty bank accounts. Cybercriminals combine social engineering through apps like FaceTime with unpatched devices to steal credentials and drain money — often without planting malware first.
Malwarebytes highlighted Apple’s July 2026 guidance on July 14. CBS News separately described the same pattern: text or call bait → FaceTime → live screen share while victims log into banking.
This is not a duplicate of any prior EmailMeNow article — we have no earlier FaceTime bank-fraud post. It is also distinct from our ClickLock / CrashStealer Mac malware coverage (those need a malicious installer; this scam starts with a trusted video call).

Snapshot
| Field | Detail |
|---|---|
| Channel | FaceTime (often after a text or audio call) |
| Impersonation | Bank / Apple Support branding and urgency |
| Primary goal | Steal banking passwords, card details, OTPs, Apple ID data |
| Extra asks | Install remote-access tools or share one-time codes |
| Patch angle | Social engineering + known iOS bugs on devices that skip updates |
| Report to Apple | Screenshot call info → reportfacetimefraud@apple.com |
| Malware required? | No for the core theft — trust + live video is enough |
How the scam works
| Step | What happens |
|---|---|
| 1. Bait | Text about “suspicious activity,” or an unsolicited call asking for “extra verification.” |
| 2. Switch to FaceTime | Audio becomes video — a live face feels more legitimate than a text. |
| 3. Pressure | Caller claims fraud, refunds, or a technical lockout and demands urgency. |
| 4. Screen share / login | Victim shares the screen (or types while visible) and opens online banking. |
| 5. Harvest | Scammer watches passwords, account numbers, and one-time codes in real time. |
| 6. Optional deepen | Remote-access apps, Apple ID “verification,” or a malicious link on an unpatched iPhone. |
Malwarebytes notes nothing in the basic flow requires malware on the device — the exploit is human trust. The risk jumps when attackers also abuse the gap between “patch available” and “patch installed,” chaining stolen credentials with browser-side bugs (campaigns in the same class as DarkSword).

What Apple and Malwarebytes advise
| Do | Don’t |
|---|---|
| Hang up on unexpected bank / Apple FaceTime calls | Share passwords, passcodes, or 2FA codes on the call |
| Call your bank using the number on the back of the card | Call back the number in a suspicious text |
| Keep iOS / iPadOS current; enable Automatic Updates | Delay security updates for weeks |
| Email a screenshot of call info to reportfacetimefraud@apple.com | Trust contact details the caller provides |
| Contact firms only through channels you already know | Install remote-access apps because a “banker” asked |

What individuals and staff should do now
- Treat any unexpected FaceTime about money, refunds, or password resets as hostile until proven otherwise.
- Never share your screen with someone who called you out of the blue.
- Update: Settings → General → Software Update, and turn on Automatic Updates.
- If you already shared credentials: freeze cards, change banking + Apple ID passwords from a separate clean device, and review recent transfers.
- Report the FaceTime attempt to Apple and your bank’s fraud team.
Why Texas businesses should care
Partners, bookkeepers, and executives on iPhones are high-value targets for wire fraud and ACH abuse. A FaceTime “bank verification” during a busy week can expose client trust accounts the same way email BEC does — only faster, because OTPs appear live on camera.
Train staff the same way we train for password-manager policy phishing: hang up, verify out-of-band, never share the screen. Pair that with MDM policies that push iOS updates quickly so social engineering cannot be chained to known mobile bugs.
Independent cybersecurity audits
We audited domains tied to this story on July 24, 2026. 100% is the ideal overall score — none of these hosts reach it. Scores reflect public email / transport / website posture, not whether a FaceTime caller is legitimate.
| Organization | Domain | Overall | Identity | Transport | Website | vs 100% ideal |
|---|---|---|---|---|---|---|
| Cloudflare | cloudflare.com | 88% | 90% | 45% | 100% | −12 |
| Malwarebytes | malwarebytes.com | 72% | 90% | 45% | 45% | −28 |
| Apple | apple.com | 70% | 50% | 15% | 100% | −30 |
| CBS News | cbsnews.com | 43% | 25% | 15% | 40% | −57 |
How to read this table
- apple.com at 70% (−30 from ideal) still has soft transport (15%) — scammers abuse Apple’s brand and FaceTime UI, not apple.com’s DNS score.
- malwarebytes.com leads the consumer-security sources here at 72%.
- cbsnews.com at 43% is included as a secondary news source; a weak public audit score does not change the FaceTime advice.
- These audits do not measure FaceTime caller-ID spoofing or bank MFA strength — they frame email/spoofing hygiene around the brands victims trust.
Audit links
Website stack note
Passive website-tech probes on July 24, 2026 completed for story domains (0 notable):
| Domain | Stack signal |
|---|---|
| malwarebytes.com | WordPress (version hidden) |
| apple.com / cloudflare.com / cbsnews.com | No notable public CMS / PHP / short-horizon TLS flags |
A hidden WordPress version on Malwarebytes’ blog is a common hardening choice. It does not relate to FaceTime fraud — that attack abuses live video trust and, on outdated phones, unpatched iOS.
These passive observations are point-in-time public signals. They do not prove exploitability or identify a breach path.
Priority actions for IT teams
- Train the hang-up rule — no bank or Apple FaceTime for credentials, OTPs, or screen share.
- Push iOS updates via MDM — shrink the patch gap attackers chain with social engineering.
- Block consumer remote-access tools on managed phones where policy allows.
- Wire-fraud procedures — dual control for large transfers; verify callbacks on known numbers only.
- Incident playbook — if staff shared banking MFA live: freeze accounts, rotate credentials, preserve FaceTime call screenshots for Apple / bank fraud teams.
Related trackers
- CrashStealer CrashReporter Mac malware
- ClickLock Stealer Mac password coercion
- LastPass / Bitwarden policy phishing
- Breach monitoring resources
Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for mobile MDM, phishing response, and DMARC / MTA-STS work aimed at the 100% ideal.
Sources: Malwarebytes — Warning: Scammers are using FaceTime to empty bank accounts · CBS News — Scammers are using FaceTime to steal bank account passwords · IBTimes UK — Apple FaceTime phishing guidance