The text says your Apple ID was locked after a sign-in from another country. Unlock within two hours or lose access to photos. Your stomach drops. Then the useful fact: manage Apple ID in Settings or appleid.apple.com — not through a link in a cold SMS.
Why Apple-branded phishing works
Photos, messages, and paid apps live behind that login. Panic is rational. Scammers only need you to type your password and the 2FA code on a page that looks enough like Apple for ten seconds.
6 signs it’s fake
- A verify/unlock link in SMS instead of guidance to open Settings
- Domain isn’t apple.com
- Extreme countdown language — permanent disablement in hours
- Page asks for password + SMS code together on a site you reached from the text
- Cold call from “Apple Support” about viruses or iCloud storage that wants remote access
- Spelling or layout that feels slightly off once you slow down
The safe way to check
On iPhone: Settings → [your name]. Review devices and sign-in security there. In a browser, type appleid.apple.com yourself. If nothing is wrong in those official surfaces, the text was noise — or bait.
What to do instead
- Do not tap the SMS link
- Check Apple ID status in Settings or appleid.apple.com
- Enable two-factor authentication if it’s off
- If you typed a password on a fake page, change it immediately and review devices
- Paste the message into ScamCheck
- Hang up on unsolicited “Apple Support” callers — don’t grant remote access
Related tech traps
Virus pop-ups with a phone number, “Microsoft Support” cold calls, and QR codes on parking meters use the same urgency engine. See our tech support guide and QRCheck if those match what you saw.
Why the “sign-in from another country” story is effective
It implies someone is already inside your account. The fix seems obvious: unlock immediately. That is the trap. Real account security work happens in Settings and on appleid.apple.com after you navigate there yourself — not on a domain you met ten seconds ago in Messages.
After you typed a password on a fake Apple page
- Change your Apple ID password from a device you trust
- Review devices signed into your account and remove strangers
- Check bank cards stored in Apple Pay / subscriptions for surprises
- Enable 2FA if it was off
- Paste the original SMS into ScamCheck so you have a clear record of the lure
Apple vs tech-support pop-ups
Different costumes, same urgency. A full-screen browser page that says “call Apple/Microsoft now” is not your operating system. Force-quit the browser. Do not call the number on the page. Details in our tech support guide.
FAQ
- I got an email and a text. Multi-channel pressure is common. Still use Settings as ground truth.
- What about iCloud storage full messages? Manage storage in Settings — not via SMS checkout links.
- Can Apple employees see my screen? Do not grant remote access to cold contacts claiming to be Apple.