{"id":417965,"date":"2026-09-24T17:32:49","date_gmt":"2026-09-24T17:32:49","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=417965"},"modified":"2026-09-24T17:35:49","modified_gmt":"2026-09-24T17:35:49","slug":"apple-pay-scam-message","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/apple-pay-scam-message\/","title":{"rendered":"Apple Pay Scam Message: How Fake Purchase Alerts Steal Money and Logins"},"content":{"rendered":"<p>A text says an Apple Pay purchase for $118.78 is pending and includes a number to call if you do not recognize it. The amount is specific, the warning feels immediate, and calling seems safer than ignoring a possible charge.<\/p><div id=\"mwtad3347846569\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>That phone number is the trap, not the solution.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1672\" height=\"941\" class=\"wp-image-417959 size-full lazyload\" style=\"max-width:100%;height:auto\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Reconstructed Apple Pay scam message claiming a $118.78 purchase is pending\" title=\"\" sizes=\"auto, (max-width: 1672px) 100vw, 1672px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesapple-pay-purchase-alert-text.jpg\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesapple-pay-purchase-alert-text.jpg 1672w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesapple-pay-purchase-alert-text-300x169.jpg 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesapple-pay-purchase-alert-text-1024x576.jpg 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesapple-pay-purchase-alert-text-1536x864.jpg 1536w\"><\/figure>\n<div id=\"mwtad1924235202\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The text invents an unauthorized Apple Pay purchase<\/h3>\n<p>The Apple Pay scam message impersonates an Apple security or payment alert. It claims a transaction is pending, an unfamiliar device was added, or the recipient&#8217;s Apple Account has been temporarily restricted.<\/p><div id=\"mwtad1141447142\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>A callback number or cancellation link is presented as the fastest way to stop the purchase. The sender wants the recipient to use that private contact route before checking Wallet, the bank, or Apple independently.<\/p>\n<h3>The fake support conversation collects access and money<\/h3>\n<p>A caller may be asked for an Apple Account password, security code, card information, or device passcode. Another version sends the victim to a cloned cancellation page that requests the same details.<\/p>\n<p>The scam can expand into remote access, gift card payments, or a transfer to a supposed safe account. The original $118.78 charge may never have existed.<\/p><div id=\"mwtad445971376\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>The campaign combines phishing with social engineering<\/h3>\n<p>The text supplies the fear; the fake support agent turns it into action. The agent can adjust the story as the conversation develops and use each detail the victim reveals to sound more knowledgeable.<\/p>\n<ul>\n<li>The purchase alert arrives unexpectedly from an unverified sender.<\/li>\n<li>The message insists that a supplied number must be called immediately.<\/li>\n<li>The transaction does not appear in Wallet or the card account.<\/li>\n<li>The caller requests passwords, codes, remote access, or payment.<\/li>\n<li>The linked page uses a domain outside Apple&#8217;s official websites.<\/li>\n<li>The victim is told to keep the call or transfer secret.<\/li>\n<\/ul>\n<div id=\"mwtad3862987855\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why a Specific Amount Makes the Alert Feel Real<\/h2>\n<p>An odd amount such as $118.78 resembles a real total after tax. It gives the recipient something concrete to fear and shifts attention away from the sender&#8217;s identity.<\/p>\n<p>The message may mention a recognizable product, retailer, or city. Those details can be invented in seconds. A transaction description inside an unsolicited text is not evidence that a payment network processed it.<\/p><div id=\"mwtad585259956\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Criminals also use the Apple Pay name because it sits between the device, Apple Account, card issuer, and merchant. A worried recipient may be unsure which organization to contact and accept the phone number offered by the scammer.<\/p>\n<p><a href=\"https:\/\/support.apple.com\/en-us\/102568\" target=\"_blank\" rel=\"noopener\">Apple&#8217;s guidance on social engineering and phishing<\/a> specifically notes that scammers may claim there is unauthorized Apple Pay activity. Apple advises users not to share passwords, security codes, or other sensitive account information.<\/p>\n<div id=\"mwtad81513266\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Apple Pay Scam Message Works<\/h2>\n<h3>Step 1: A fake purchase alert creates immediate concern<\/h3>\n<div id=\"mwtad2504379834\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The text says a payment is pending, completed, or under review. It may include a case number and a short deadline for cancellation.<\/p>\n<p>The message is written to make inaction feel dangerous. In reality, taking a minute to inspect the card account is safer than contacting an unverified number.<\/p>\n<h3>Step 2: The victim calls or opens the supplied link<\/h3>\n<p>On the phone, an agent answers with a polished Apple-style greeting. On the web, a copied page offers to cancel the transaction after the visitor \u201cverifies\u201d the account.<\/p>\n<div id=\"mwtad1464251683\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>Both routes keep the victim inside an environment controlled by the criminal. Every confirmation comes from the same source that made the original claim.<\/p>\n<h3>Step 3: The scammer performs a fake security review<\/h3>\n<p>The agent asks for the recipient&#8217;s name, email, billing address, or card ending. Some details are framed as harmless identity checks, but together they support account recovery attempts and payment fraud.<\/p>\n<p>The caller may claim that several devices or transactions are linked to the account. These statements cannot be verified through the call and are used to increase urgency.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1672\" height=\"941\" class=\"wp-image-417960 size-full lazyload\" style=\"max-width:100%;height:auto\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Reconstructed fake Apple Pay support page asking for a password and security code\" title=\"\" sizes=\"auto, (max-width: 1672px) 100vw, 1672px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesapple-pay-fake-support-page.jpg\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesapple-pay-fake-support-page.jpg 1672w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesapple-pay-fake-support-page-300x169.jpg 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesapple-pay-fake-support-page-1024x576.jpg 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/imagesapple-pay-fake-support-page-1536x864.jpg 1536w\"><\/figure>\n<h3>Step 4: A password or security code is requested<\/h3>\n<div id=\"mwtad3558057680\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The criminal may start a real Apple Account login or password reset while speaking with the victim. That action sends a genuine code or approval notification to a trusted device.<\/p>\n<p>The caller says the code cancels the transaction or confirms the victim&#8217;s identity. Sharing it can instead approve the attacker&#8217;s access or a sensitive account change.<\/p>\n<h3>Step 5: The conversation moves toward money or device access<\/h3>\n<p>A fake refund process may require screen sharing or remote-control software. The agent can then watch the victim enter credentials, manipulate what appears on screen, or instruct the victim through a bank transfer.<\/p>\n<p>Another script claims that gift cards are needed to reverse the purchase. Gift card numbers transfer value directly to the criminal and have no legitimate role in cancelling Apple Pay activity.<\/p>\n<h3>Step 6: The scammer creates a reason for continued secrecy<\/h3>\n<p>The victim may be told that bank employees are involved in the fraud, that speaking to family will compromise an investigation, or that the case must remain open until money is moved.<\/p>\n<p>Secrecy keeps helpful people from interrupting the scheme. A genuine fraud investigation does not require a customer to lie to a bank or remain connected to an unsolicited caller.<\/p>\n<div id=\"mwtad1223491599\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Check the Alleged Purchase<\/h2>\n<p>Open Wallet directly and review recent activity for the relevant card. Then check the issuer&#8217;s official app or website, where pending and posted transactions can be confirmed.<\/p>\n<p>The absence of a matching $118.78 entry is a strong sign that the text invented the purchase. Do not allow the caller to explain why the charge is supposedly hidden or delayed.<\/p>\n<p>If an unfamiliar transaction is present, contact the card issuer using the number printed on the card or the official app. The bank can explain the transaction and begin a dispute without asking for an Apple Account code.<\/p>\n<p>Apple Account activity should also be reviewed from Settings or Apple&#8217;s official account site. Remove devices you do not recognize, but do not follow account links included in the text.<\/p>\n<div id=\"mwtad966871635\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Identity, Contact, and Payment Checks<\/h2>\n<h3>Inspect the message without trusting its label<\/h3>\n<p>A sender name such as \u201cApple Security\u201d can be spoofed, and ordinary numbers can be used for mass texts. Read the content as an unverified claim.<\/p>\n<p>Misspellings can reveal a scam, but their absence proves nothing. Well-written messages can still route every response to a criminal.<\/p>\n<h3>Verify the transaction with the card issuer<\/h3>\n<p>Use the bank&#8217;s app or the number on the physical card, not the contact information in the text. Ask specifically about the amount, merchant, status, and digital-wallet token if a real entry appears.<\/p>\n<p>Do not share a code with an incoming caller. A bank can discuss activity after completing its own secure verification process.<\/p>\n<h3>Reach Apple through an official route<\/h3>\n<p>Use the Support app or type Apple&#8217;s support address yourself. End the incoming conversation before starting a separate one.<\/p>\n<p>A genuine support representative will not need an Apple Account password or the device passcode. Those secrets belong only in the appropriate trusted interface.<\/p>\n<h3>Reject alternative payment and safe-account stories<\/h3>\n<p>No Apple Pay cancellation requires gift cards, cryptocurrency, cash, or a transfer to a newly supplied account. Those methods remove normal purchase protections.<\/p>\n<p>A \u201csafe account\u201d controlled by someone else is not safe. Contact the bank directly if a transfer has already been requested or sent.<\/p>\n<div id=\"mwtad1745680763\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Common Variations of the Message<\/h2>\n<p>One version says a new card was added to Apple Pay. Another claims an expensive device was purchased using Apple Pay and is ready for pickup. Both include a phone number or link for cancellation.<\/p>\n<p>A fake Apple receipt can arrive by email instead of text. It may show an app purchase, subscription, or gift card and direct the recipient to a refund form.<\/p>\n<p>Some campaigns use a group-message thread or send repeated alerts from different numbers. Blocking one sender may not stop the campaign, because the criminal can rotate numbers and domains.<\/p>\n<p>A later caller may pose as the bank rather than Apple. The change in identity does not make the request legitimate. Security codes, remote access, and transfers remain clear boundaries.<\/p>\n<div id=\"mwtad781057866\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What the Scammer May Try After the First Call<\/h2>\n<p>The first conversation may end without a payment, yet the information collected can make a second attempt more dangerous. A later caller may know the name, email address, card ending, or exact amount discussed.<\/p>\n<p>The criminal can switch identities and claim to represent the card issuer, a merchant, law enforcement, or Apple&#8217;s fraud team. A new caller does not mean an independent organization confirmed the story.<\/p>\n<p>If an Apple Account password was captured, the attacker may send repeated approval requests and hope one is accepted accidentally. Deny unfamiliar prompts and change the password from a trusted device.<\/p>\n<p>If card details were captured, small test charges may appear before a larger attempt. Alerts should be reviewed through the bank&#8217;s app, not through another number supplied by text.<\/p>\n<p>Remote access creates a separate risk. Even after the visible session ends, unattended-access settings or startup software may let the attacker reconnect. Removal and account review should happen before normal banking resumes.<\/p>\n<p>Finally, ignore anyone promising guaranteed recovery for a fee. Recovery impersonators often target people whose details were already collected by the first scam.<\/p>\n<p>Keep a short timeline of the incident, including the original text, call time, information disclosed, software installed, and payments attempted. A clear timeline helps the bank distinguish the invented $118.78 alert from any real transaction the criminal later created. It also prevents a follow-up caller from rewriting what happened.<\/p>\n<p>Check the device&#8217;s call blocking and message filtering options only after saving the evidence. Blocking reduces interruptions, but it should not erase the record needed for a dispute or report.<\/p>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol style=\"overflow-wrap:anywhere;word-break:break-word;padding-left:1.25em\">\n<li><strong>End the conversation immediately.<\/strong> Hang up, close the page, and stop replying. Deny new sign-in prompts and disconnect the device if the caller has remote access.<\/li>\n<li><strong>Secure the Apple Account from a trusted device.<\/strong> Change the password, review trusted phone numbers and devices, remove anything unfamiliar, and confirm that account recovery information is correct.<\/li>\n<li><strong>Contact the card issuer.<\/strong> Use the official app or number on the card. Report exposed card information, review pending and posted transactions, and ask whether the card or digital-wallet token should be replaced.<\/li>\n<li><strong>Explain any code you shared.<\/strong> Tell Apple or the bank exactly what the notification said. A code may have approved an account login, password reset, card enrollment, or payment.<\/li>\n<li><strong>Remove remote-access applications.<\/strong> Uninstall software requested by the caller, disable unattended access, and inspect startup items. If online banking was open during the session, tell the bank.<\/li>\n<li><strong>Change other reused passwords.<\/strong> Begin with email and financial accounts. Use unique passwords and enable multifactor authentication while rejecting unexpected approval prompts.<\/li>\n<li><strong>Run a Malwarebytes scan.<\/strong> Update Malwarebytes and perform a complete scan if a file was downloaded or remote software was installed. Remove detected threats and seek help if the device remains unusual.<\/li>\n<li><strong>Use AdGuard as an added safeguard.<\/strong> AdGuard can block many known phishing pages, malicious advertisements, and tracking links. It cannot reverse a transfer or account takeover, so complete the recovery steps first.<\/li>\n<li><strong>Preserve and report the evidence.<\/strong> Screenshot the message, save the number, URL, call log, receipts, and transaction details. Send a screenshot of suspicious texts to <code>reportphishing@apple.com<\/code> and report financial fraud to the appropriate authorities.<\/li>\n<li><strong>Be cautious with recovery contacts.<\/strong> Scammers may return pretending to have recovered the money. Do not pay an upfront fee or share another password, passcode, or verification code.<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Does Apple send Apple Pay fraud alerts by text?<\/h3>\n<p>Account and payment notifications can occur, but a text should not be used as the only proof. Check Wallet and the card issuer independently, and never use an unverified callback number.<\/p>\n<h3>Can a pending Apple Pay charge be hidden?<\/h3>\n<p>Processing times vary, but a caller cannot prove a transaction by claiming it is hidden. The card issuer can check authorizations and pending activity through its own systems.<\/p>\n<h3>Will Apple ask for my security code to cancel a purchase?<\/h3>\n<p>No legitimate agent should ask you to reveal an Apple Account verification code or device passcode. Those secrets may authorize access rather than cancel it.<\/p>\n<h3>What if I called but did not share information?<\/h3>\n<p>End the call and block further contact. Review Wallet and the Apple Account directly. The immediate risk is lower if no credentials, codes, remote access, or payment information were provided.<\/p>\n<h3>Can I get money back after a transfer or gift card payment?<\/h3>\n<p>Recovery is not guaranteed, but report it immediately. Contact the bank, payment service, or gift card issuer and retain every receipt and communication. Speed can preserve options that disappear later.<\/p>\n<h3>How do I report the scam message to Apple?<\/h3>\n<p>Apple advises sending a screenshot of a suspicious text to <code>reportphishing@apple.com<\/code>. Also use the phone&#8217;s junk-reporting feature and notify the carrier when available.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The Apple Pay scam message uses a precise purchase amount to start an unverified support conversation. The transaction story is only bait for passwords, security codes, remote access, or irreversible payments.<\/p>\n<p>Check Wallet and the bank directly, then contact Apple through a route you choose yourself. If anything was shared, secure the account and payment method before answering another message.<\/p>\n<div id=\"mwtad3712369215\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A text says an Apple Pay purchase for $118.78 is pending and includes a number to call if you do not recognize it. The amount is specific, the warning feels immediate, and calling seems safer &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Apple Pay Scam Message: How Fake Purchase Alerts Steal Money and Logins\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/apple-pay-scam-message\/#more-417965\" aria-label=\"Read more about Apple Pay Scam Message: How Fake Purchase Alerts Steal Money and Logins\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":417959,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-417965","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/417965","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=417965"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/417965\/revisions"}],"predecessor-version":[{"id":418523,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/417965\/revisions\/418523"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/417959"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=417965"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=417965"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=417965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}