Hackers Using iCloud's Find My iPhone Feature to Remotely Lock Macs and Demand Ransom Payments

Over the last day or two, several Mac users appear to have been locked out of their machines after hackers signed into their iCloud accounts and initiated a remote lock using Find My iPhone.

With access to an iCloud user's username and password, Find My iPhone on iCloud.com can be used to "lock" a Mac with a passcode even with two-factor authentication turned on, and that's what's going on here.

maclockedfindmyiphone
Apple allows users to access Find My iPhone without requiring two-factor authentication in case a person's only trusted device has gone missing.

2faicloud

2-factor authentication not required to access Find My iPhone and a user's list of devices.

Affected users who have had their iCloud accounts hacked are receiving messages demanding money for the passcode to unlock a locked Mac device.


The usernames and passwords of the iCloud accounts affected by this "hack" were likely found through various site data breaches and have not been acquired through a breach of Apple's servers.

Impacted users likely used the same email addresses, account names, and passwords for multiple accounts, allowing people with malicious intent to figure out their iCloud details.

lockmacfindmyiphone

It's easy to lock a Mac with a passcode in Find My iPhone if you have someone's Apple ID and password.

To prevent an issue like this, Apple users should change their Apple ID passwords, enable two-factor authentication, and never use the same password twice. Products like 1Password, LastPass, and even Apple's own iCloud Keychain are ideal ways to generate and store new passwords for each and every website.


Users who have had their Macs locked will need to get in contact with Apple Support for assistance with removing the Find My iPhone lock.

(Thanks, Eli!)

Popular Stories

AirPods Pro Firmware Feature

Apple Releases New Firmware for AirPods Pro 3, AirPods Pro 2 and AirPods 4

Tuesday October 7, 2025 11:27 am PDT by
Apple today released new firmware designed for the AirPods Pro 3, prior-generation AirPods Pro 2, and the AirPods 4 models. The firmware has a build number of 8A358, up from 8A356. There's no word on what's include in the updated firmware, but the prior 8A356 update added iOS 26 features to the AirPods Pro 2, AirPods Pro 3, and AirPods 4 with ANC. The software introduced better audio quality ...
iOS 26

Everything New in iOS 26.1 Beta 2

Monday October 6, 2025 3:54 pm PDT by
Apple released the second beta of iOS 26.1 and iPadOS 26.1, introducing useful changes to alarms, multitasking on the iPad, and more. There are also subtle tweaks to some of the Liquid Glass design elements as Apple continues to refine iOS 26. Alarms and Timers Alarms set using the Clock app now have a slide to stop button rather than a tap to stop button on the Lock Screen. To snooze an...
john ternus on stage

Gurman: Major Apple Leadership Shakeup Impending With John Ternus as Next CEO

Monday October 6, 2025 6:21 am PDT by
Apple is entering its most significant leadership transition in more than a decade as multiple senior executives prepare to depart and CEO Tim Cook begins to shape the company's next generation of leaders, according to Bloomberg's Mark Gurman. In the latest edition of his "Power On" newsletter, Gurman explained that Jeff Williams, who was viewed as Cook's potential successor for several...
ios 26 1 slide to stop

Apple Fixes Alarms in iOS 26.1

Monday October 6, 2025 11:56 am PDT by
With the second beta of iOS 26.1, Apple updated the design of alarms set on the iPhone, making them harder to dismiss than before. Stopping an alarm in iOS 26.1 beta 2 requires a new Slide to Stop gesture rather than a simple tap. You can continue to tap to snooze an alarm, but if you want to turn it off entirely, you need to use a swipe. Transitioning from a tap to a slide gesture to...
ipad mini 7 feature blue

iPad Mini 8 on the Way: Expected Features and Release Timeline

Monday October 6, 2025 5:05 am PDT by
A new iPad mini is "absolutely" on the way, according to Bloomberg's Mark Gurman. So what should we expect from the successor to the iPad mini 7 that Apple released a year ago? Processor and Performance Apple is working on a next-generation version of the iPad mini (codename J510/J511) that features the A19 Pro chip, according to information found in code that Apple mistakenly shared in...
tag heuer made for iphone

New TAG Heuer Smartwatches Now 'Made for iPhone'

Wednesday October 8, 2025 8:41 am PDT by
TAG Heuer today announced the Connected Calibre E5 smartwatch, now featuring "Made for iPhone" certification as the watchmaker abandons Google's Wear OS. Three years after launching the Calibre E4, the Connected Calibre E5 comes in two case sizes: 45mm and a new, more compact 40mm. They are powered by the Qualcomm Snapdragon 5100+. The 45mm model features a 1.39-inch AMOLED display, while ...
macbook pro pink

M5 MacBook Pro Could Launch in October as M4 Model Faces Supply Constraints

Monday October 6, 2025 3:23 pm PDT by
Supplies of the 14-inch M4 MacBook Pro model appear to be constrained amid rumors that an upgraded M5 model could launch as soon as this year. As noted by Bloomberg's Mark Gurman, custom configurations of the M4 MacBook Pro model have a delayed shipping date and will not be delivered to customers until October 23 to 28. The restricted supply could be an indication that Apple is planning to...
iphone 17 magsafe silicon rings 1

Apple Modifies In-Store MagSafe Stands to Prevent iPhone 17 Marks

Wednesday October 8, 2025 4:41 am PDT by
Apple has quietly added a protective silicone ring to its in-store MagSafe charging stands following reports of marks appearing on some iPhone 17 series display models, according to Consomac. The apparent move comes after Apple last month confirmed that worn MagSafe chargers in retail stores were causing what appeared to be scratches on the iPhone 17 Pro and iPhone 17 Pro Max. There have...
iOS 26 Feature

iOS 26.1 to iOS 26.4 Will Add These New Features to Your iPhone

Wednesday October 1, 2025 1:26 pm PDT by
iOS 26 was released last month, but the software train never stops, and iOS 26.1 beta testing is already underway. So far, iOS 26.1 makes both Apple Intelligence and Live Translation on compatible AirPods available in additional languages, and it includes some other minor changes across Apple Music, Calendar, Photos, and Safari. More features and changes will follow in future versions,...

Top Rated Comments

miketcool Avatar
105 months ago
Meh, this is why things live on external drives. If I lost or had my laptop stolen, I'd wipe it and be back up and running in 25 minutes without the hassle.
Score: 19 Votes (Like | Disagree)
I Need a Drink Avatar
105 months ago
Nice job MR. I only emailed them about this 4 weeks ago and asked that they run a story to inform people that this was going on.

I also emailed Apple about the issue with a simple suggestion. What they need to do is to require the device password when you try to lock a device from Find My iPhone on the web. When you go to remote lock a device you enter a lock passcode and the device's password or passcode. When that is sent to the Mac, iPhone, whatever, if the device password doesn't match, it won't lock the device. That way, even if a hacker guesses your Apple ID and password using hacked credentials, they still can't lock the device without the Mac's login.
Score: 17 Votes (Like | Disagree)
44267547 Avatar
105 months ago
Macurmors quote:

"Impacted users likely used the same email addresses, account names, and passwords for multiple accounts, allowing people with malicious intent to figure out their iCloud details."

And this is exactly why I reconfigure all my passwords for my accounts on a regular basis. Stagnancy can be part of the problem.
Score: 12 Votes (Like | Disagree)
Vol7ron Avatar
105 months ago
Yup, this happened to me back in June when I installed beta 1 of MacOS High Sierra. Frustrating and embarrassing when your an IT engineer and your own device gets hacked! Had to bring it to Apple and provide proof of ownership before they would remove the lock.

And always use 2Factor. I don’t buy the second tweet about someone getting hacked with having 2FA enabled. Even if they could guess your password and the security code, your trusted device would still get a notification and you could block access.
I had 2 factor enabled, saw that someone was trying to access my account, denied them, and still had my account locked.
Score: 11 Votes (Like | Disagree)
busyscott Avatar
105 months ago
MacRumors, why are you recommending two-factor authentication if you then go onto say you can access Find My iPhone without needing 2FA??

Here's a better recommendation: turn off Find My Mac until Apple correct course and Find My iPhone requires 2FA.
Score: 10 Votes (Like | Disagree)
Born Again Avatar
105 months ago
I liked how he said "y'all"

"y'all come back now ! yah hear?!"
Score: 7 Votes (Like | Disagree)