Scammers Have Used Fake iPhone Duo Pre-order Page

A malicious website uses a leaked security exploit to compromise unpatched iPhones automatically.

Updated on Sept. 30, 2026 in Cybersecurity

Isometric editorial illustration showing a segmented silicon microchip, representing the technical nature of a mobile security exploit.
A malicious website leveraging the DarkSword security exploit is targeting unpatched iPhone devices, threatening crypto wallets and saved passwords with automated data extraction. AI Illustration. Upload story photo >

Live Poll

Do you feel confident in your ability to spot malicious links while browsing online?

Scammers created a fake pre-order page for the upcoming iPhone Duo to bait users with a $500 discount voucher. The site leverages the leaked DarkSword exploit to compromise devices without any user interaction.

Why it matters

The threat exploits high consumer interest in the new device to target crypto wallets, saved passwords, and private communications. It highlights the risk posed by leaked exploits against unpatched mobile operating systems.

The attack utilizes a version of the DarkSword exploit leaked on GitHub to target unpatched hardware. Apple previously addressed the original vulnerability in March 2026 and released iOS 26.7.1 for security.

The players

Apple

Apple is a global technology company that designs and manufactures the iPhone and maintains the iOS operating system.

GitHub

GitHub is a widely used web-based platform for software development and version control where the exploit code was leaked.

The details

The malicious webpage automatically launches the exploit upon being opened, bypassing the need for manual user clicks. Once the device is compromised, the malware scans for crypto wallet applications and extracts sensitive keychain data.

Timeline

  1. Security researchers first uncovered the DarkSword exploit in March 2026.

  2. Apple issued a patch for the initial exploit in March 2026.

  3. This report was published on September 30, 2026.

  4. Official iPhone Duo pre-orders are scheduled to begin on October 16, 2026.

The Tech Race

This incident demonstrates how attackers repurpose leaked security exploits to target users ahead of major hardware launches. It emphasizes the critical need for users to keep devices updated against threats like the DarkSword exploit.

Users can protect their data by immediately updating their devices to the latest software version to mitigate risks from leaked exploits. Avoid interacting with unofficial websites claiming to offer early pre-order discounts for new products.

The takeaway

Security experts recommend users verify the legitimacy of promotional offers before entering personal information on pre-order sites. Always keep your smartphone operating system updated to ensure patches for known exploits are active.

What happens next

Official iPhone Duo pre-orders are scheduled to begin on October 16, 2026, which may serve as a target window for continued malicious activity.

Further reading

Learn more about securing your personal devices in our Cybersecurity section.

Live Poll

Do you feel confident in your ability to spot malicious links while browsing online?