• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCyber Saturday

Cyber Saturday—Apple iPhone Phishing Trick, Zscaler as Best Tech IPO, Facebook Fails

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
June 9, 2018, 11:53 AM ET

Good morning, Cyber Saturday readers.

A month ago I was milling about a hotel room in New Orleans, procrastinating my prep for on-stage sessions at a tech conference, when I received a startling iMessage. “It’s Alan Murray,” the note said, referring to my boss’ boss’ boss.

Not in the habit of having Mr. Murray text my phone, I sat up straighter. “Please post your latest story here,” he wrote, including a link to a site purporting to be related to Microsoft 365, replete with Microsoft’s official corporate logo and everything. In the header of the iMessage thread, Apple’s virtual assistant Siri offered a suggestion: “Maybe: Alan Murray.”

The sight made me stagger, if momentarily. Then I remembered: A week or so earlier I had granted a cybersecurity startup, Wandera, permission to demonstrate a phishing attack on me. They called it, “Call Me Maybe.”

Screenshot of the iMessage thread
Screenshot of the iMessage thread

Alan Murray had not messaged me. The culprit was James Mack, a wily sales engineer at Wandera. When Mack rang me from a phone number that Siri presented as “Maybe: Bob Marley,” all doubt subsided. Jig, up.

There are two ways to pull off this social engineering trick, Mack told me. The first involves an attacker sending someone a spoofed email from a fake or impersonated account, like “Acme Financial.” This note must include a phone number; say, in the signature of the email. If the target responds—even with an automatic, out-of-office reply—then that contact should appear as “Maybe: Acme Financial” whenever the fraudster texts or calls.

The subterfuge is even simpler via text messaging. If an unknown entity identifies itself as Some Proper Noun in an iMessage, then the iPhone’s suggested contacts feature should show the entity as “Maybe: [Whoever].” Attackers can use this disguise to their advantage when phishing for sensitive information. The next step: either call a target to supposedly “confirm account details,” or send along a phishing link. If a victim takes the bait, the swindler is in.

The tactic apparently does not work with certain phrases, like “bank” or “credit union.” However, other terms, like “Wells Fargo,” “Acme Financial,” the names of various dead celebrities—or my topmost boss—have worked in Wandera’s tests, Mack said. Wandera reported the problem as a security issue to Apple on April 25th. Apple sent a preliminary response a week later, and a few days after that said it did not consider the issue to be a “security vulnerability,” and that it had reclassified the bug as a software issue “to help get it resolved.”

What’s alarming about the ploy is how little effort it takes to pull off. “We didn’t do anything crazy here like jailbreak a phone or a Hollywood style attack—we’re not hacking into cell towers,” said Dan Cuddeford, Wandera’s director of engineering. “But it’s something that your layman hacker or social engineer might be able to do.”

To Cuddeford, the research exposes two bigger issues. The first is that Apple doesn’t reveal enough about how its software works. “This is a huge black box system,” he said. “Unless you work for Apple, no one knows how or why Siri does what it does.”

The second concern is more philosophical. “We’re not Elon Musk saying AI is about to take over the world, but it’s one example of how AI itself is not being evil, but can be abused by someone with malicious intent,” Cuddeford said. As we continue to let machines guide our lives, we should be sure we’re aware how they’re making decisions.

Have a great weekend—and watch out for imposters.

Maybe: Robert Hackett

@rhhackett

robert.hackett@fortune.com

Welcome to the Cyber Saturday edition of Data Sheet, Fortune’sdaily tech newsletter. Fortune reporter Robert Hackett here. You may reach Robert Hackett via Twitter, Cryptocat, Jabber (see OTR fingerprint on my about.me), PGP encrypted email (see public key on my Keybase.io), Wickr, Signal, or however you (securely) prefer. Feedback welcome.

THREATS

Facebook's flops. Facebook had a rough week, as usual. The company has been quietly sharing people's personal data—and those of people's friends—with phone-makers, including Huawei, a Chinese firm that is said to have close ties to the Chinese government. The data included, per a report by the New York Times: people's "religious and political leanings, work and education history and relationship status." Facebook also revealed that a since-fixed "bug" accidentally nudged an estimated 14 million people to make their posts public.

Bonus: The Wall Street Journal has an excellent piece on the clash of cultures between Facebook and WhatsApp, a chat app the social media site acquired for $22-billion.

Apple's antidotes. Apple unveiled data privacy and other updates at its worldwide developers' conference, or WWDC, this week. The company boosted its Safari browser with protections designed to thwart online tracking. It showed off a feature, ScreenTime, for combating phone addiction. And within the code for Apple's new mobile operating system, iOS 12, inquisitive techies found traces of what appear to be Apple's plans to expand its face-scanning technology, FaceID, to the iPad as well as hints of a feature that make it harder for law enforcement to hack iPhones in the course of their investigations.

China's chops. Americans are worried that China is getting very good at targeting prospective defectors who have access to high-value information, and recruiting them to become informants and spies. The Wall Street Journal takes a look at a few recent cases, many of which involved people who struggled with debt. Meanwhile, DEFCON, one of the world's biggest hacking conferences, debuted a Chinese version of the event. The summit could forge closer ties between the U.S. and Chinese hacking communities.

To breach his own. Security researcher Troy Hunt recently confirmed a hacker's claim to have stolen a database containing information on 26 million users of Eventbrite's Ticketfly service. The loot apparently includes email addresses, home and billing addresses, and phone numbers, though no passwords. In the wake of another incident, MyHeritage, an Israeli genetic testing company, is urging its users to change their passwords after it discovered that email addresses and hashed passwords for 92 million users were potentially compromised.

It's good to be king. Cloud security firm Zscaler, which went public earlier this year, has claimed the title of the best performing tech IPO of 2018. The company's shares have zoomed 164% to $40 per share since their stock exchange debut in March.

I simply refuse to believe this is possible.

Share today's Data Sheet with a friend:

http://fortune.com/newsletter/datasheet/

Looking for previous Data Sheets? Click here.

ACCESS GRANTED

Discrimination machinations. The ad-targeting tech of Internet giants exacerbates problems of discrimination that arise as marketers parse populations by age, race, sex, and other personal attributes. The New York Times published a whip-smart op-ed by Alvaro M. Bedoya, former chief counsel to the Senate Judiciary Subcommittee on Privacy, Technology, and the Law, that calls attention to these injustices. "Tech companies can now target—or exclude—you entirely in secret, and often at the precise moment when you are most vulnerable," Bedoya writes. 

People who value their privacy come from all demographic groups, but the impact of consumer tracking varies greatly by race, class and power. When you’re the “right” race, gender and sexual orientation, when you’ve got the right schools and jobs on your profile, marketers use tracking to flatter and include you. When you’re not, tracking is more likely to be used to exclude or exploit you. This disparate impact is a civil rights issue, and it should be treated like one by Congress.

FORTUNE RECON

Google Makes a Vague Pledge to Limit Work on Artificial Intelligence in Weapons, Surveillance by Kevin Kelleher

North Korea Uses Microsoft and Apple Technology for Cyberattacks, Researchers Say by Don Reisinger

MIT Scientists Create 'Psychopath' AI Named Norman by Carson Kessler

Founders Fund Partner Talks Privacy, Facebook, and His Time at Peter Thiel’s Secretive Data Company by Polina Marinova

Palo Alto Networks' New CEO Is Betting $20 Million of His Own Money on the Company by Robert Hackett

Facebook Shared Your Data With Phone Makers Like Apple. Here's Why This Scandal Could Be Huge by David Meyer

Suspected Golden State Killer Was Nabbed by DNA Obtained in Hobby Lobby Parking Lot by Jaclyn Gallucci

ONE MORE THING

'X' marks the spot. In the 19th century, an adventurer named Thomas J. Beale supposedly deposited millions of dollars worth of precious metals and gemstones in a Virginian forest. He left behind three ciphers detailing the fortune's location, only one of which has been solved to date. Many people have tried to decode the wealth's exact whereabouts; all have failed. As a weekend read, I recommend this account of the hunt for Beale's buried treasure by Mental Floss. It's a gripping, albeit lengthy, tale.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Jeremy Renner
AIHealth
Exclusive: Jeremy Renner bets on the tech that could have saved his life faster: ‘There’s 150 people that are responsible for me not dying’
By Catherina GioinoApril 15, 2026
18 minutes ago
The hidden menace behind Big Tech’s AI arms race: Meta, Amazon and others are spending billions on hardware that’s worthless in 3 years
AIFinance
The hidden menace behind Big Tech’s AI arms race: Meta, Amazon and others are spending billions on hardware that’s worthless in 3 years
By Shawn TullyApril 15, 2026
2 hours ago
The billionaire Anthropic cofounder who majored in literature says knowing how to ask the right questions beats knowing how to code
SuccessTech
The billionaire Anthropic cofounder who majored in literature says knowing how to ask the right questions beats knowing how to code
By Marco Quiroz-GutierrezApril 14, 2026
13 hours ago
TOKYO, JAPAN - FEBRUARY 3: Open AI CEO Sam Altman speaks during a talk session with SoftBank Group CEO Masayoshi Son at an event titled "Transforming Business through AI" in Tokyo, Japan, on February 03, 2025. SoftBank and OpenAI announced that they have agreed a partnership to set up a joint venture for artificial intelligence services in Japan today. (Photo by Tomohiro Oh
CybersecuritySam Altman
From Molotov cocktails to data center shutdowns, the AI backlash is turning revolutionary
By Eva RoytburgApril 14, 2026
13 hours ago
Dow COO Karen Carter wearing a white lab coat and sitting while smiling
C-SuiteNext to Lead
Dow’s CEO pick elevates a seasoned insider at a pivotal moment for the chemical giant
By Ruth UmohApril 14, 2026
15 hours ago
Anthropic’s Mythos reveals a growing security gap: AI finds flaws far faster than companies can patch them
AIEye on AI
Anthropic’s Mythos reveals a growing security gap: AI finds flaws far faster than companies can patch them
By Sharon GoldmanApril 14, 2026
16 hours ago

Most Popular

Billionaire philanthropist MacKenzie Scott has donated again—a week after gifting millions to a college, she's just given $70 million to Meals on Wheels America
Success
Billionaire philanthropist MacKenzie Scott has donated again—a week after gifting millions to a college, she's just given $70 million to Meals on Wheels America
By Fortune EditorsApril 13, 2026
2 days ago
Retirees are facing a $345,000 bill they never saw coming — and most aren't prepared
Commentary
Retirees are facing a $345,000 bill they never saw coming — and most aren't prepared
By Fortune EditorsApril 14, 2026
23 hours ago
He was coding at 12 like Elon Musk and became one of Google’s youngest-ever CMOs—but now says Gen Z is better off ice skating than learning to code
Success
He was coding at 12 like Elon Musk and became one of Google’s youngest-ever CMOs—but now says Gen Z is better off ice skating than learning to code
By Fortune EditorsApril 14, 2026
1 day ago
Anthropic is facing a wave of user backlash over reports of performance issues with its Claude AI chatbot
AI
Anthropic is facing a wave of user backlash over reports of performance issues with its Claude AI chatbot
By Fortune EditorsApril 14, 2026
1 day ago
Current price of gold as of April 13, 2026
Personal Finance
Current price of gold as of April 13, 2026
By Fortune EditorsApril 13, 2026
2 days ago
Current price of oil as of April 14, 2026
Personal Finance
Current price of oil as of April 14, 2026
By Fortune EditorsApril 14, 2026
21 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.