Mac users are now in danger of a well-known Windows phishing attack

    By Monica J. White
Published March 20, 2025

If you’re using a Mac, such as the new MacBook Air, you might have to be careful. A phishing attack that previously plagued Windows users has now made its way to macOS, and it’s easy to fall for it.

This was spotted by 9to5Mac. Researchers from LayerX have been tracking a well-known phishing attack that caused a lot of grief to those who were tricked by it. Previously, the main target of these hackers was Windows, but Microsoft was able to largely eliminate it — up to 90% of all attacks on Windows PCs are said to have been fixed thanks to new updates to Edge, Chrome, and Firefox that block scareware.

As the hackers were out of luck on Windows, they appear to have turned to macOS. Macs are often said to be safe from hackers, which means some users may let their guard down and be easier to target.

On Windows, the phishing attack imitated Microsoft security alerts. The idea was that the hackers wanted to steal the users’ security credentials. In the case of Apple, their goal is to steal Apple IDs, and to do this, they make it seem like the PC is compromised.

We’ve all seen similar pop-ups in the past, but this attack feels more legitimate because it also freezes the website that the victim is viewing. An unresponsive PC with a message saying that it’s been compromised is often enough for someone to give up their login credentials.

LayerX claims that macOS and Safari users are now the primary targets for this particular phishing campaign, and they claim that it’s a highly sophisticated attempt at a hack which may not stop here — it’s just the first attempt at adapting to the fixes rolled out on Windows.

Weird pop-ups that ask you to log in may look believable, but it’s important to stay vigilant. It’s worth warning friends and family members who are less plugged into the latest tech news. I know I’ll be warning my relatives who are using the Apple ecosystem. It’s unclear when, or if, Apple will be rolling out a security update to address this phishing attack.

Related Posts

Qualcomm is set to ratchet up chip prices in September, and your next gadget upgrade could bear the brunt

The price hike will be in effect from September 1, 2026, a recent Bloomberg report claims. Essentially, all the companies placing their chip orders after that will pay a higher price. 

Stop fighting with your roomie over outlets and get one of these multi-port chargers before you head back to school

Back-to-school season is a smart time to buy one. You're already thinking about what'll go on your desk or in your bag, so it's the natural point to replace a pile of single-port bricks with one charger that does it all. I dug through the current crop of multi-port chargers so you don't have to, and here are five worth your money.

OpenAI’s rogue AI hack was just the beginning, Hugging Face warns

Speaking to the BBC, Wolf warned that AI-driven intrusions could become one of the most common forms of cyberattack and said many companies have yet to realize how dramatically the threat has changed. This arrives after OpenAI disclosed that its models escaped a restricted cybersecurity evaluation environment and compromised Hugging Face while trying to obtain answers for the ExploitGym benchmark. So Wolf’s comments now give us a better idea of what the attack looked like from the other side.