Free Skins or a Locked Phone: How Scammers Use Apple IDs to Blackmail Kids

MSSP
MSSP Global,

Gaming scams have long moved past simply stealing in-game accounts. Today, attackers exploit children's trust to hijack their smartphones, and then demand money to restore access. At the heart of this new scheme is social engineering – a manipulation tactic where the victim is convinced to willingly provide access to the device.
Why Are Children the Primary Targets?
Popular online games, such as Roblox, Brawl Stars, Genshin Impact, and others, have long become a platform not only for player communication but also for scammers. Children are promised free in-game currency, rare items, skins, or fully leveled-up accounts.
As a rule, communication begins in the game chat, Telegram, or Discord. The scammer poses as an experienced player and offers a bonus for completing a few simple steps.
It is at this stage that the child faces a request to log into a stranger's Apple ID account on their iPhone or iPad to download a game, receive in-game content, or activate a gift. Many children do not understand that an Apple ID is not just a login, but a key to controlling the device.
How the Scheme Works
After the child logs into a stranger's Apple ID, the attacker gets the opportunity to use Apple services to remotely control the device.
In most cases, scammers:
- lock the smartphone via the "Find My" service;
- display a message on the screen claiming that the device is allegedly stolen and provide instructions to contact them;
- demand a ransom for unlocking the device;
- threaten to delete data or publish it.
The size of the demands can range from tens to hundreds of thousands of tenge. At the same time, even after transferring the money, scammers often continue their extortion, realizing that the family is ready to pay.
Why This Scheme Works
The main reason for the success of such attacks is not technical vulnerabilities, but the human factor.
Children are used to trusting members of gaming communities, strive to quickly gain gaming advantages, and often do not understand the consequences of transferring access to their device. That is exactly why scammers rely not on hacking, but on psychological pressure and the promise of a "free reward".
How to Protect Your Child
It is impossible to completely eliminate the risk of encountering scammers, but basic rules of digital safety can significantly reduce it.
Explain the main rule to your child: never log into a stranger's Apple ID on your phone, regardless of what the interlocutor promises.
Additionally, it is recommended to:
- set up the "Family Sharing" feature so that purchases and content downloads are confirmed by parents;
- add a trusted contact for restoring access to the Apple ID;
- use a strong passcode to unlock the device;
- explain to your child that any offers of free in-game currency, skins, or accounts from strangers require verification with adults.
What to Do If the Device Is Already Locked
If the smartphone is locked after logging into a stranger's Apple ID, it is important to act calmly. Do not transfer money to scammers. Paying the ransom does not guarantee restoring access and often leads to new demands.
Instead, it is recommended to:
- contact official Apple Support;
- prepare documents confirming the right of ownership of the device (receipt, box with serial number);
- change the password for your email and Apple ID if there is a possibility the account has been compromised;
- contact law enforcement agencies if there are signs of extortion.
The Main Rule of Cyberhygiene
Most modern cyberattacks begin not with a complex hack, but with user trust. The better children understand how fraudulent schemes work, the less likely they are to become their victims.
Regular conversations about digital safety, explaining the principles of how accounts work, and monitoring the settings of family devices help prevent such incidents and keep both personal data and access to devices safe.
Also, read our posts on Instagram and follow us: https://www.instagram.com/citizensec.kz/
You will be interested
Взлом Discord. Данные пользователей службы поддержки оказались в руках хакеров
Платформа Discord сообщила о кибератаке, в результате которой часть данных пользователей оказалась украдена. Инцидент произошёл не из-за ошибки самой компании, а из-за взлома стороннего подрядчика, который помогал Discord обрабатывать обращения в службу поддержки.

@CitizenSec
07-10-2025Cookies, Super Cookies, Fingerprint и Таргетированная реклама: как всё связано?
Cookies, super cookies, fingerprint и таргетированная реклама: как отслеживается поведение пользователей, какие технологии используются и как частично защитить свою приватность.

@CitizenSec
19-05-2025Полное руководство по шифрованию диска: что это, зачем нужно и как сделать
Шифрование диска — это важный инструмент для защиты данных на вашем устройстве.

@CitizenSec
15-05-2025Журнал о кибербезопасности
Сегодня мы рады представить вам нашу подборку рекомендаций по кибергигиене в текстовом формате, оформленную в виде журнала.

@citizensec
28-01-2025Завершите регистрацию и обновите данные сертификата на портале CitizenSec
Просим завершить регистрацию и обновить данные сертификата о прохождении курса по кибергигиене на портале CitizenSec.

@CitizenSec
02-08-202459% паролей взламываются за час - узнайте, как защитить свои данные и обеспечить безопасность в сети
Современные компьютеры в 2024 году могут взломать пароли, которые раньше считались надежными, за несколько секунд.

@CitizenSec
27-06-2024Как вредоносные документы Word и QR-коды превращают обычные фишинговые атаки в опасное оружие
Хакеры часто используют вредоносные документы Word, которые могут содержать макросы с вредоносным кодом. Такие файлы при открытии могут нанести вред компьютеру жертвы.

@CitizenSec
26-06-2024Как не попасться на фишинг
В данной статье мы поговорим о том, что такое фишинг, покажем примеры такого вида мошенничества и расскажем о методах противодействия.

@CitizenSec
15-06-2024В NuGet обнаружен пакет, возможно, предназначенный для промышленного шпионажа.

@CitizenSec
22-04-2024