Exposed Check

Apple Pay scam text

This is a scam text pretending to be Apple Inc. Apple is not sending it.

What the message claims

That there has been an unauthorised Apple Pay charge, or suspicious activity on your Apple Account or device, and that you need to confirm it, reverse it or secure the account. What follows, by link or by a phone number in the message, is a request to sign in, to read back a code, or to switch a security setting off.

How to tell

In order. The first one holds even when the rest of the message looks completely real, which is the situation most people are actually in.

  1. It steers you to sign in somewhere, or asks for a password, device passcode or verification code.

    Apple states this with no exception: "Apple will never ask you to log in to any website, or to tap Accept in the two-factor authentication dialog, or to provide your password, device passcode, or two-factor authentication code or to enter it into any website." It holds even if you do use Apple Pay and even if a charge really was made, because dealing with a real charge never involves handing a code to someone who contacted you. That is what makes it the one worth remembering: it survives the message being partly true.

  2. It asks you to turn a security feature off.

    "Apple will never ask you to disable any security feature on your device or on your account." Apple says scammers frame this as necessary to stop an attack or to get your account back, when the point is to lower your defences first. This one earns its place because it usually arrives late, after you have already decided the contact is genuine, so it is the tell that still works once the earlier ones have been talked past.

  3. The urgency is aimed at stopping you contacting Apple yourself.

    Apple describes the mechanism directly: the scammer "usually creates a strong sense of urgency to avoid giving you time to think and to dissuade you from contacting Apple yourself, directly", and may say you are free to call Apple back but that the fraudulent activity will continue and you will be liable. Apple says plainly that this is false. Pressure not to go and check is not a side effect of the scam, it is the scam.

What Apple actually does

Look at the charge where the charge would be, on your own device. Open Wallet, or Settings, and read your own Apple Pay transaction list and your Apple Account purchase history. A card charge also shows in your bank or card issuer’s own app, and that issuer’s number is printed on the back of the card. If you want Apple, reach Apple through its official support channels, never a number or a link supplied by the message.

Where to report it

Apple
Apple asks for a screenshot: take one of the message and email it to reportphishing@apple.com. In Messages you can also tap Report Junk under the message.
Your mobile carrier
Forward the message to 7726, which spells SPAM on a keypad. It is free on every major carrier.
The Federal Trade Commission
Report it at ReportFraud.ftc.gov, which is the route Apple’s own page names for scam contacts.

Where this comes from

Source
Apple Support, Recognize and avoid social engineering schemes including phishing messages, phony support calls, and other scams, published 15 June 2026
First seen
June 15, 2026
Last confirmed active
June 15, 2026 current
Source checked
October 6, 2026

“Apple will never ask you to log in to any website, or to tap Accept in the two-factor authentication dialog, or to provide your password, device passcode, or two-factor authentication code or to enter it into any website.”

This record was compiled from the source above and has not yet had a second pair of eyes on it. Read the quoted line rather than taking our summary of it.