# Fake e-mail from Apple

**URL:** <https://boards.straightdope.com/t/fake-e-mail-from-apple/795408>\
**Category:** Factual Questions\
**Created:** [September 3, 2017, 3:51pm UTC](https://boards.straightdope.com/t/fake-e-mail-from-apple/795408 "2017-09-03T15:51:13Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Acsenray](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/acsenray/32/4519_2.png) [@Acsenray](https://boards.straightdope.com/u/Acsenray)\
**Post date:** [September 3, 2017, 3:51pm UTC](https://boards.straightdope.com/t/fake-e-mail-from-apple/795408/1 "2017-09-03T15:51:13Z")

</div>

I just got an e-mail message supposedly from “Apple ID” that said it was confirming an Apple iTunes purchase. It had a PDF that had a receipt with a bunch of items I had never heard of. I then clicked on the “Apple ID” sender and saw that it had a random e-mail address. I deleted the e-mail, but I’m wondering whether I might have done something risky by opening the PDF on my iPhone. Should I do anything more?

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [September 3, 2017, 4:20pm UTC](https://boards.straightdope.com/t/fake-e-mail-from-apple/795408/2 "2017-09-03T16:20:56Z")

</div>

Sounds like Phising to me.  
They want you to enter your credentials. If you didn’t do that, I think there would near-zero risk.

---

<div class="post-metadata">

**Author:** ![Acsenray](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/acsenray/32/4519_2.png) [@Acsenray](https://boards.straightdope.com/u/Acsenray)\
**Post date:** [September 3, 2017, 4:40pm UTC](https://boards.straightdope.com/t/fake-e-mail-from-apple/795408/3 "2017-09-03T16:40:54Z")

</div>

Okay, thanks!

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [September 4, 2017, 2:20pm UTC](https://boards.straightdope.com/t/fake-e-mail-from-apple/795408/4 "2017-09-04T14:20:20Z")

</div>

There have been numerous exploits found in Adobe’s PDF readers over the years. A really amazing number. Adobe has gotten better and if your reader is up to date (or better yet non-Adobe), then you’re better off. (But never 100% secure, of course.)

Sending a PDF that tries one of these exploits is still attempted once in a while.

Don’t ever click on a PDF link from a less than 100% trusted source.

I suggest you update your anti-virus software and run a scan _now_. Just in case.

---

<div class="post-metadata">

**Author:** ![Acsenray](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/acsenray/32/4519_2.png) [@Acsenray](https://boards.straightdope.com/u/Acsenray)\
**Post date:** [September 4, 2017, 2:48pm UTC](https://boards.straightdope.com/t/fake-e-mail-from-apple/795408/5 "2017-09-04T14:48:28Z")

</div>

> [@ftg](#):
>
> I suggest you update your anti-virus software and run a scan _now_. Just in case.

How does one do that on an iPhone?

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [September 4, 2017, 2:52pm UTC](https://boards.straightdope.com/t/fake-e-mail-from-apple/795408/6 "2017-09-04T14:52:57Z")

</div>

Apple doesn’t use Adobe’s PDF reader on the iPhone…

---

<div class="post-metadata">

**Author:** ![pulykamell](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pulykamell/32/3166_2.png) [@pulykamell](https://boards.straightdope.com/u/pulykamell)\
**Post date:** [September 4, 2017, 3:10pm UTC](https://boards.straightdope.com/t/fake-e-mail-from-apple/795408/7 "2017-09-04T15:10:14Z")

</div>

> [@Acsenray](#):
>
> I just got an e-mail message supposedly from “Apple ID” that said it was confirming an Apple iTunes purchase. It had a PDF that had a receipt with a bunch of items I had never heard of. I then clicked on the “Apple ID” sender and saw that it had a random e-mail address. I deleted the e-mail, but I’m wondering whether I might have done something risky by opening the PDF on my iPhone. Should I do anything more?

I get these all the time. Yesterday I got the “Your Apple ID was suspended” version of the email. Last week, I get the “Your ID is automatically locked” version of the email. If you opened it up on your iPhone, you should be okay. I don’t know of any known current PDF exploits on that. (There are reports of security holes in the past, but I can’t find anything current.)

---

<div class="post-metadata">

**Author:** ![TubaDiva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tubadiva/32/507_2.png) [@TubaDiva](https://boards.straightdope.com/u/TubaDiva)\
**Post date:** [September 4, 2017, 4:39pm UTC](https://boards.straightdope.com/t/fake-e-mail-from-apple/795408/8 "2017-09-04T16:39:33Z")

</div>

Seems to be an uptick in this kind of phishing attempt lately; almost every day I get a “receipt” for some purchase I have made either from iTunes or amazon. This morning’s mail brought me the receipt for renewal of Pandora, which is a neat trick since I don’t subscribe.

All total crap, of course.

---

<div class="post-metadata">

**Author:** ![md2000](https://avatars.discourse-cdn.com/v4/letter/m/73ab20/32.png) [@md2000](https://boards.straightdope.com/u/md2000)\
**Post date:** [September 5, 2017, 5:18am UTC](https://boards.straightdope.com/t/fake-e-mail-from-apple/795408/9 "2017-09-05T05:18:12Z")

</div>

Yeah, I got two days ago the “suspicious activity on your Apple Account - Click here to verify your account details”.

I would believe it more, maybe, if they had used good grammar.
