Opens in a new tab

Before iPhone Duo preorders open, a warning about a fake one

A person holds a foldable smartphone open, displaying a home screen with various app icons and widgets on both halves of the flexible screen. The background is a desert scene—rumoured to be the new iPhone Duo available for pre orders.

Preorders for Apple’s iPhone Duo do not begin until Friday 16 October, but scammers are already taking action. According to reporting from 9to5Mac, a fraudulent preorder site designed to closely mimic Apple’s official storefront is active. It entices users to order early by promising a $500 “Authorised Partner Exclusive” discount.

Rather than the counterfeit discount, the primary concern lies in the site’s immediate behaviour upon loading. Security analysts discovered that the page executes the DarkSword exploit chain completely passively, requiring zero user action, with no forms, downloads, or clicks needed. Merely loading the site initiates an intrusion designed to harvest saved passwords, personal notes, and crypto wallet credentials.

While concerning, a key technical detail mitigates the overall risk: DarkSword was publicly documented and patched by Apple in March 2026. Consequently, the attack only poses a threat to unpatched iOS devices. An iPhone running up-to-date software remains fully safe from compromise, regardless of site interaction.

Why this matters to UK businesses

While it may seem like a consumer-targeted scam, it still creates both targeted and broad security risks for your business.

Regarding the targeted threat, this vector centres strictly on iOS rather than macOS. Because the DarkSword exploit exclusively impacts iOS, macOS devices remain unaffected. Updated iPhones are fully protected against this vulnerability, while any device missing the latest updates can be compromised immediately upon page load.

The general risk applies to any device, Mac included, and it’s the more familiar kind: a convincing fake site is still a convincing fake site. New product launches create urgency, and urgency plus a limited-time discount is the classic combination that makes sensible people click quickly. The same trick shows up in invoice fraud and phishing emails year-round. Good design is no longer a sign that a page is legitimate, so staff need a better test than “it looked real.”

What to do now

Ensure your iPhones are updated to a current iOS version. Keeping devices centrally managed and up to date is the single most critical step to neutralise this specific threat, leaving DarkSword with zero leverage. If you are unsure about your fleet’s patch status, verify it today, well ahead of 16 October.

Beyond that, these habits still apply:

  • Buy Apple hardware from Apple or a known reseller. Preorders go through apple.com or the Apple Store app. Nothing else. If your business is ordering devices, route it through your usual supplier or your IT partner.
  • Treat “authorised partner exclusive” discounts as a red flag. Apple doesn’t hand out surprise $500 vouchers through unfamiliar websites.
  • Type the address, don’t click the link. Search results and social media ads can both be paid for by scammers. Going directly to apple.com avoids the problem entirely.
  • Send a short internal note before 16 October. A two-line message in your team chat ahead of launch day does more good than a training module a month later.
  • Keep personal crypto off work devices. If anyone holds wallets, they shouldn’t sit on a machine used for day-to-day business browsing, on any platform.

The wider lesson

Every big Apple launch brings a wave of fake stores, fake tracking emails, and fake “your order has a problem” messages. Expect more of them in the weeks around 16 October, especially delivery-themed texts once real orders start shipping.

The defence is boring and effective: devices that are centrally managed and kept patched, one trusted route for buying hardware, and a team that knows a discount that good isn’t real. The first of those three is the one that actually stopped this particular attack in its tracks for anyone who already had it in place.

If you’d like us to check what your Macs and iPhones would currently block, and confirm your fleet’s patch status while we’re at it, we’re happy to take a look.

FAQs

Is this fake iPhone Duo site dangerous just to visit, or only if I enter details?

Just visiting is enough on an unpatched iPhone. The site uses a zero-click exploit chain, so no form, download, or approval is needed for the attack to start. A phone on a current iOS version isn’t vulnerable to this specific attack.

Does this affect Macs as well as iPhones?

The confirmed exploit targets iOS specifically; there’s no evidence it works against macOS. A Mac visiting the same fake site faces the more general risk of a convincing scam page, not this particular payload.

How do we know if our business iPhones are patched against this?

The patch was issued in March 2026, so any phone updated since then is already protected. For centrally managed devices, this is straightforward to confirm directly.

DR Logic

Dr Logic is an Apple Premium Technical Partner supporting businesses across London and the UK. Founded in 2003, the team of 34 Apple-certified engineers and consultants helps organisations get the most from their technology through proactive IT support, cyber security, and strategic IT planning.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.