Banking · 30 September 2026
iPhone 18 scam sites drain bank accounts, Kaspersky warns
Kaspersky says fraudulent websites in Arabic, English and Portuguese are exploiting iPhone 18 launch hype with fake 25% discounts to steal bank details and payments.
What happened
Cyber security firm Kaspersky has warned that fraudsters are exploiting the launch of Apple's iPhone 18 to run a wave of scam websites designed to empty victims' bank accounts. The warning comes as hundreds of customers queued at Dubai Mall for the new device, with some hoping to be among the first in the region to own one.
According to Kaspersky, the fake sites — built in multiple languages including Arabic, English and Portuguese — advertise the iPhone 18 at a 25 per cent discount, offer instalment payment plans, and push buyers towards paying in Bitcoin. The firm says the pages use a "deceptively credible interface" that mimics a legitimate retail checkout, designed specifically to lower visitors' guard.
Once a shopper is drawn in, the sites harvest personal data — including bank account details, email addresses and phone numbers — with the goal of draining accounts directly. In other cases, scammers simply collect a "down payment" on the fake device and disappear with the funds.
Why it matters
This is fundamentally a story about the design of trust. The scam works not because the offer is convincing on its merits, but because the interface borrows the visual and procedural cues of a genuine purchase journey — familiar layouts, plausible pricing logic, structured payment steps — at precisely the moment consumer attention is highest and scrutiny is lowest: a hyped global product launch.
For experience and service-design leaders, the episode is a reminder that trust cues are learned behaviours, and anything that replicates them can be weaponised. Retailers, banks and telecoms operating in markets with high launch-day demand — the Gulf region prominent among them — have a growing incentive to actively counter-programme these moments: pre-empting customers with verification guidance, flagging official channels clearly, and building friction into unusually attractive offers rather than removing it.
By the numbers
- 25 per cent discount advertised on fake iPhone 18 listings used to lure victims
- Hundreds of customers queued at Dubai Mall for the genuine iPhone 18 launch
- Three languages identified in the fraudulent sites — Arabic, English and Portuguese — indicating a multi-market operation
The Renascence take
Most coverage of this story will frame it as a security issue. It is really a behavioural design problem, and that distinction matters for anyone building digital commerce experiences.
Scarcity, urgency and social proof — a launch-day queue, a "limited" discount, a countdown to checkout — are the same psychological levers legitimate brands use to drive conversion, which is exactly why they transfer so cleanly into fraud. The lesson isn't that customers need to be more sceptical; it's that genuine retailers need to make authenticity easier to verify than deception is to fake. That means visible, hard-to-spoof trust signals at the exact moments hype peaks — not generic security advice buried in a help centre, but proactive, real-time nudges ("here's how to know this is really us") built into the launch experience itself. Brands that treat fraud prevention as a customer-experience design task, not just a security bulletin, will convert less and lose fewer customers to it.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
FAQ
Questions we get on this topic
More in Banking
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.
