Scammers Targeted Users With Fake iPhone Duo Pre-orders
A phishing campaign leveraged a leaked exploit to compromise unpatched iPhones before official pre-orders begin.
Updated on Sept. 30, 2026 in Cybersecurity

Live Poll
Do you feel confident in your ability to spot malicious links while browsing online?
Security researchers identified a malicious website masquerading as an official iPhone Duo pre-order page that uses a leaked version of the DarkSword exploit to compromise devices. The attack targets unpatched iPhones to steal sensitive data, including crypto wallet credentials and saved passwords.
Why it matters
Scammers are capitalizing on high consumer interest in the upcoming iPhone Duo to distribute malware via drive-by downloads. This campaign highlights the persistent risk of leaked exploit chains remaining a threat to users running outdated software versions.
The attack utilizes a version of the DarkSword exploit leaked on GitHub to trigger an automatic device compromise immediately upon visiting the webpage. This exploit targets iOS versions earlier than 26.7.1 to exfiltrate keychain data, messages, and crypto wallet files.
The players
Apple
A global technology company that designs the iOS mobile operating system and the iPhone hardware product line.
The details
The exploit operates as a drive-by download, meaning it launches as soon as a user opens the malicious site without requiring further interaction. Once executed, the underlying malware scans the device for stored keychain data—the secure storage system for passwords and keys—and specific crypto wallet applications. This breach is possible on devices that have not been updated to the security patches provided by Apple in iOS 26.7.1.
Timeline
March 2026: Security researchers first identified the DarkSword exploit.
March 2026: Apple released a patch for the DarkSword vulnerability.
September 30, 2026: Details of the phishing campaign emerged.
October 16, 2026: Official iPhone Duo pre-orders begin.
The Tech Race
This campaign follows a pattern set by the 2026 DarkSword exploit patch by targeting users who have failed to implement security updates. It highlights the recurring challenge of maintaining device security as attackers integrate leaked research-stage exploits into consumer-facing phishing operations.
Users can protect their devices against this exploit by ensuring their iPhone is running the latest software version, specifically iOS 26.7.1 or newer. This update effectively closes the vulnerability that allows the malware to trigger automatically upon visiting a malicious webpage.
The takeaway
Malicious actors are using high-profile product launches as a lure to deliver exploits that bypass typical user warnings. Users should verify that they have applied the latest iOS security patches before interacting with any promotional links regarding the new iPhone Duo.
What happens next
Official pre-orders for the iPhone Duo are scheduled to open on October 16, 2026.
Further reading
For broader trends in device protection and vulnerability management, see the Cybersecurity section.
Live Poll
Do you feel confident in your ability to spot malicious links while browsing online?










