I was annoyed by the repeated calls. I was sceptical from the start, as I usually am, but entertained the conversation.
Multiple US numbers had been ringing my phone all morning; I finally picked one up.
It was an automated voice. A robotic tone: “We’ve received a request to change the phone number linked to your Apple account. Press 1 if this wasn’t you so we can cancel the request.” I pressed 1. The recording said an agent would call me back in a few minutes with next steps.
Sure enough, a few minutes later, a real human called. A calm, confident male voice said he was from Apple Support: they’d received a request to change my phone number and wanted to confirm it was me.
I said no, I didn’t request that. Please cancel it. He said sure, then casually added that he could see I was in Singapore and the number trying to link was Russian. Then asked if I’d used any public Wi-Fi in the last three weeks. I said maybe.
He offered to walk me through “authorising the cancellation” and gave me a URL out loud:
“chat hyphen apple dot com”, i.e. chat-apple.com.
That’s when it clicked. Scam.
And it doesn’t matter whether you use an Android or an Apple phone. I use an Android phone with a MacBook, so I have an Apple account. Anyone with an Apple account is the target.
The domain trick everyone should know:
chat.apple.com could be real. “chat” is a subdomain of the real domain apple.com.
chat-apple.com is a completely different site. The whole thing is the domain, owned by whoever registered it. Nothing to do with Apple.
Rule of thumb: reading a URL, the real domain is the segment immediately before .com, back to the previous dot. In chat.apple.com that’s apple.com. In chat-apple.com, that’s chat-apple.com. Different owner entirely.
Why the trick works
- Said out loud, “chat hyphen apple dot com” sounds almost identical to “chat dot apple dot com”.
- A hyphen (-) and a dot (.) look nearly identical on a small screen.
- The caller sounds professional and drops plausible detail (your city, “Russia”, public Wi-Fi) to prime you.
How the operation is run
- Multiple US numbers ringing at once. Block one, another gets through.
- First contact is a bot. Cheap to run at scale.
- Pressing 1 tells the syndicate two things: your number is live, and you’re willing to engage. You’ve just qualified yourself as a target.
- Only then does a real human call, from a different number, to work the actual scam.
This isn’t a lone fraudster. It’s an assembly line.
Four mistakes I made
- Picked up an unknown number.
- Pressed 1 on the automated message. That’s the qualifier that tells the gang your number is live and you’re ready to engage.
- Talked to a human at all. Apple has publicly stated it *never* makes unsolicited calls. If someone rings claiming to be Apple Support, it’s always a scam. Just hang up.
- Spoke more than I needed to. Three seconds of voice is enough for AI to clone it. Silence is safer.
Rules of thumb
- Don’t trust unsolicited calls, however professional they sound.
- Never press any button on an automated message from an unknown caller.
- Never follow links or steps dictated over the phone.
- For Apple support, go directly to the Apple Support app or apple.com.
Younger me would have given him a mouthful of expletives. Today I just hung up.
Stay sceptical.
About the author
Viren Mantri is a cybersecurity advisor and former senior technology leader across Standard Chartered, UBS, McAfee, and KPMG. After three decades at the intersection of technology, risk, and regulation, he now helps organisations cut through complexity and make better security decisions.
CC-BY Viren Mantri, 2026, licensed under a Creative Commons Attribution 4.0 International License.
Disclaimer: All views expressed here are entirely mine.