I was annoyed by the repeated calls. I was sceptical from the start, as I usually am, but entertained the conversation.

Multiple US numbers had been ringing my phone all morning; I finally picked one up.

It was an automated voice. A robotic tone: “We’ve received a request to change the phone number linked to your Apple account. Press 1 if this wasn’t you so we can cancel the request.” I pressed 1. The recording said an agent would call me back in a few minutes with next steps.

Sure enough, a few minutes later, a real human called. A calm, confident male voice said he was from Apple Support: they’d received a request to change my phone number and wanted to confirm it was me.

I said no, I didn’t request that. Please cancel it. He said sure, then casually added that he could see I was in Singapore and the number trying to link was Russian. Then asked if I’d used any public Wi-Fi in the last three weeks. I said maybe.

He offered to walk me through “authorising the cancellation” and gave me a URL out loud:

“chat hyphen apple dot com”, i.e. chat-apple.com.

That’s when it clicked. Scam.

And it doesn’t matter whether you use an Android or an Apple phone. I use an Android phone with a MacBook, so I have an Apple account. Anyone with an Apple account is the target.

The domain trick everyone should know:

chat.apple.com could be real. “chat” is a subdomain of the real domain apple.com.

chat-apple.com is a completely different site. The whole thing is the domain, owned by whoever registered it. Nothing to do with Apple.

Rule of thumb: reading a URL, the real domain is the segment immediately before .com, back to the previous dot. In chat.apple.com that’s apple.com. In chat-apple.com, that’s chat-apple.com. Different owner entirely.

Why the trick works

How the operation is run

This isn’t a lone fraudster. It’s an assembly line.

Four mistakes I made

  1. Picked up an unknown number.
  2. Pressed 1 on the automated message. That’s the qualifier that tells the gang your number is live and you’re ready to engage.
  3. Talked to a human at all. Apple has publicly stated it *never* makes unsolicited calls. If someone rings claiming to be Apple Support, it’s always a scam. Just hang up.
  4. Spoke more than I needed to. Three seconds of voice is enough for AI to clone it. Silence is safer.

Rules of thumb

Younger me would have given him a mouthful of expletives. Today I just hung up.

Stay sceptical.

About the author

Viren Mantri is a cybersecurity advisor and former senior technology leader across Standard Chartered, UBS, McAfee, and KPMG. After three decades at the intersection of technology, risk, and regulation, he now helps organisations cut through complexity and make better security decisions.

CC-BY Viren Mantri, 2026, licensed under a Creative Commons Attribution 4.0 International License.

Disclaimer: All views expressed here are entirely mine.