The iPhone Duo isn’t available yet, and pre-orders won’t open until October 16 — but that doesn’t mean you won’t see ads promising to let you pre-order the foldable. These ads are a scam, and you should avoid them at all costs.
Spotted by Malwarebytes, this scam promises buyers that they can save $500 by pre-ordering an iPhone Duo. I can see the appeal of that when the duo starts at $2,000, but that’s a big red flag. If something seems too good to be true, it probably is, but logic tends to go out the window when hundreds of dollars are on the line.
This isn’t just your usual run-of-the-mill scam, though. Malwarebytes reports that the fake pre-order site is actually using a leaked DarkSword exploit chain to try to crack into vulnerable iPhones. A successful version of this exploit tries to steal all stored credentials, notes and crypto wallet data. This exploit targets iPhones running iOS 18.4 to iOS 18.6.2, but apparently the offending code should not affect iPads or Macs.
Latest Videos FromTom the guide
The scary part? The exploit starts when you open the website. You don’t have to download or click anything, nor do you have to fill out the wrong pre-order form for things to start going south.
The page certainly looks legit. It has Apple logos, font, copyright information and general language style. Unlike many scams, there are no obvious typos or grammatical errors. However, all the links to things like the privacy policy and terms and conditions don’t actually go anywhere.
The fake pre-order form shows some red flags, such as the mention of a “Natural Titanium” color, despite the fact that the iPhone Duo is only available in Start White and Night Sky (black). It also gets the dimensions wrong, with size options of 6.3- and 6.9-inches, which are the screen sizes on the iPhone 18 Pro and Pro Max. The duo only comes in one size, with a 7.6-inch foldable screen and 5.4-inch cover display.
But by that point it’s already too late and the DarkSword exploit has already started. However, this form will hand over a bunch of your personal data directly to the scammers so they can use it however they want. That includes selling it for profit, using it to further scam you and all the other risks that come from exposing your personal data.
How to protect yourself
The first thing you can do to make sure this scam doesn’t affect you is to update your iPhone to the latest version of iOS. Since it only affects certain versions of iOS 18, updating to the newly released iOS 27 will ensure that your iPhone is protected from DarkSword. It also means you have access to the best new iOS 27 features and updates, some of which are incredibly useful.
Apple has already patched the exploit, but it can’t force fixes to your phone if you ignore the update notifications that iOS sends you. It doesn’t bother you to be nervous, those spots are important.
The second is to always be careful about the type of links you click – especially if you don’t keep your device software up to date. If an ad offers something a little too unusual, steer clear. Chances are it’s some kind of honeypot designed to lure you in for other nefarious purposes.
Finally, be sure to only pre-order iPhones from legitimate channels. That means the Apple Store, major retailers like Walmart or Best Buy, as well as the best phone operators. Many of those third parties also have different deals, but for something as new and sought-after as the iPhone Duo, they’re likely to come in the form of increased trade-ins or discounted data plans — not money from the phone itself.
As for Apple, they almost never offer discounts on their devices, certainly not at the beginning of their life cycle. So any official looking site that offers big discounts is guaranteed to be some kind of scam. And just to reiterate, pre-orders for the duo open on October 16th, and won’t be available anywhere until that day.
If you’ve already accidentally clicked on a potentially dangerous link, don’t worry, Malwarebytes recommends updating and restarting your phone. Apparently the exploit doesn’t continue to steal data after a reboot, although there’s no telling what they stole before. If this happens, be sure to create a new crypto wallet with a different recovery phrase and transfer your money.
You should also change any passwords that have been stolen. iOS 27 has a feature that can do this for you in case of future data breaches, but for now you’ll have to do everything manually.
follow Tom’s Guide to Google News in the add us as a preferred source to get our latest news, analysis and reviews in your feeds. Make sure you click the follow button!
