Skip to Content

Phishing Attacks Use This Simple Trick to Defeat iPhone Message Security

A new social engineering tactic is being used by cybercriminals to trick iPhone users into disabling iMessage's built-in phishing protection, in a bid to expose them to malicious links and scams, according to BleepingComputer.

General Apps Messages Redux
The scam exploits a security feature in iMessage that automatically disables links from unknown senders. Apple told the outlet that when users reply to these messages or add the sender to their contacts, the links become clickable – a behavior that scammers are now actively exploiting, according to the report. The deceptive messages often masquerade as notifications from trusted organizations like USPS or toll road authorities.

Scammers are apparently looking to exploit the familiar "reply STOP" or "reply NO" that often appears at the end of messages from authentic businesses or services, as there's been a surge in SMS phishing (smishing) attacks that specifically ask recipients to reply "Y" to "activate" supposedly legitimate links.

By getting users to respond, attackers not only enable the previously disabled links but also identify active phone numbers that are more likely to engage with future scams.

Tech-savvy users are likely to easily identify these as phishing attempts, but the main concern is that older or less experienced users will be particularly vulnerable to the tactic. Needless to say, the best way to ensure that you never fall for the scam is to never reply to suspicious messages from unknown senders.

phishing scam

SMS phishing attacks with disabled links (Image credit: BleepingComputer)

Another line of defense is to enable message filtering on your iPhone or iPad. Message filtering sorts messages from people who are not in your contacts into a separate list, where you can more easily view them in the Messages app. To filter messages from unknown senders, open Settings and go to Apps ➝ Messages, then toggle on the switch next to Filter Unknown Senders.

Bear in mind that the feature can filter legitimate messages – from couriers or your bank, for example – so don't automatically assume that a filtered message is dodgy. And, as mentioned above, you can't open links in a message from an unknown sender until you add them to your contacts or reply to the message, but that's by design.

Popular Stories

MacBook Neo Feature Pastel 1

First MacBook Neo Benchmarks Are In: Here's How It Compares to the M1 MacBook Air

Thursday March 5, 2026 4:07 pm PST by
Benchmarks for the new MacBook Neo surfaced today, and unsurprisingly, CPU performance is almost identical to the iPhone 16 Pro. The MacBook Neo uses the same 6-core A18 Pro chip that was first introduced in the iPhone 16 Pro, but it has one fewer GPU core. The MacBook Neo earned a single-core score of 3461 and a multi-core score of 8668, along with a Metal score of 31286. Here's how the...
HomePod mini and Apple TV Sage

New Apple TV and HomePod Mini Are Still Missing, Here's Why

Thursday March 5, 2026 6:11 am PST by
Apple this week unveiled seven products, ranging from the iPhone 17e to the MacBook Neo, but new Apple TV and HomePod mini models were not among them. Given that there have been rumors about the next-generation Apple TV and HomePod mini since all the way back in late 2024, some customers are wondering why the devices have yet to launch, and the answer likely relates to Siri. In September, ...
MacBook Neo Feature Pastel 1

Apple Announces $599 'MacBook Neo' With A18 Pro Chip

Wednesday March 4, 2026 6:15 am PST by
Apple today announced the "MacBook Neo," an all-new kind of low-cost Mac featuring the A18 Pro chip for $599. The MacBook Neo is the first Mac to be powered by an iPhone chip; the A18 Pro debuted in 2024's iPhone 16 Pro models. Apple says it is up to 50% faster for everyday tasks than the bestselling PC with the latest shipping Intel Core Ultra 5, up to 3x faster for on-device AI workloads,...

Top Rated Comments

vertsix Avatar
15 months ago
Why doesn't Apple use Apple Intelligence to detect and remove these things?

Genuine question, I know Apple Intelligence sucks at this time but I'm sure it can be easily trained to detect these samples?
Score: 27 Votes (Like | Disagree)
McWetty Avatar
15 months ago
“iPhone users hate this one trick…” is the only way this article could be more clickbait. /s

Snark aside… I eliminated this spamming by removing all my personal data from data brokers. It took me an entire Saturday, but I managed to remove my email/phone/address from over 40 online sources and I haven’t gotten a single SMS spam since. Not even during the US election season.
Score: 9 Votes (Like | Disagree)
15 months ago
The faster we leave SMS behind the better.
I have had the same phone number for 20+ years and it must be part of an active list scammers use because at this point I receive phishing SMS's at least 2-3 times a week and regularly use TrueCaller to filter out this garbage.
Score: 6 Votes (Like | Disagree)
15 months ago

I eliminated this spamming by removing all my personal data from data brokers. It took me an entire Saturday, but I managed to remove my email/phone/address from over 40 online sources
Would be very interested to hear specifics on how you (or anyone else) did this. Did you pay for some service that automates it, or manually go through and fill out forms? Thanks!
Score: 6 Votes (Like | Disagree)
spazzcat Avatar
15 months ago
Don't reply to messages from pepole you don't know or don't make any sense because they have no context.
Score: 5 Votes (Like | Disagree)
dynamojoe Avatar
15 months ago
Can I just block all SMS from the Philippines?
Score: 4 Votes (Like | Disagree)