Phishing email example · Tactic: Trust
Apple phishing email example: fake order shipment notice
This Apple phishing email is a shipping confirmation for an order you never placed, a refurbished iPod touch, with a Track Shipment button. The tell is the sender, apple@shipment-status.com, which is not an Apple domain. The goal is to make you click in a panic to see or cancel the order.

The red flags
- Subject
- Here is your shipment and tracking information
- From
- apple@shipment-status.com
- 1
Not an Apple domain
shipment-status.com has no connection to Apple.
- 2
A product Apple no longer sells
Apple announced in May 2022 that iPod touch would be sold only while supplies lasted. A new order for one in 2026 should make you suspicious straight away.
- 3
The button is the whole point
Track Shipment is where the attack happens. You can check any real Apple order in your purchase history without touching the email.
- 4
A stale copyright line
The footer says “Copyright © 2019.” Scammers often copy an old genuine email and never update it.
Why this Apple scam works
An order you don’t recognise is alarming. It suggests someone is using your account or your card, and that worry pushes people to click the first button they see to find out what happened.
Everything else looks right. The layout copies Apple’s real shipping emails closely, with an order number, a carrier, a tracking number, the real Apple Store phone number and a long, genuine-sounding help section. Familiar detail makes the one fake detail, the sender, easy to miss.
The tactic: Trust. The message wears a brand or a colleague you already trust, so scrutiny drops. See all six tactics.
Who gets this email
Anyone with an Apple Account, which is most smartphone owners. It works best on people who buy from Apple online, and on busy people who see “order” and “shipment” and react before reading what was bought.
Other versions of this scam
- An App Store or iCloud receipt for a subscription you didn’t buy, with a “cancel” or “dispute” link.
- An “account locked” or “suspicious sign-in” alert asking you to verify your Apple Account.
- A text message about a failed delivery that links to a fake Apple or carrier page.
Check it in 30 seconds
- Read the sender domain.
- Ask whether you ordered this. If you didn’t, don’t click to find out.
- Check your orders and purchase history in the Apple Store app, or at apple.com typed in yourself.
- Look at the small print, like dates and copyright years, for signs of a copied email.
What real Apple email looks like
- For App Store and iTunes purchases, Apple says genuine receipts include your current billing address, and that account details should be changed only in Settings on your device, iTunes or the App Store, never through a link in an email. Source: Apple Support
- Apple says it will never ask you to log in to a website, share your password or device passcode, or give out a two-factor authentication code. Source: Apple Support
What happens if someone clicks
Track Shipment in an email like this usually leads to a fake Apple sign-in page, often followed by a form to “verify your payment method” so the order can be cancelled. With your Apple Account password and card details, an attacker can make purchases, lock you out of your account and, in some cases, lock your devices.
How to report a Apple phishing email
- At work, use your email’s Report Phishing button, or forward the message to your IT or security team, before anything else. They can pull the same email from everyone else’s inbox.
- Apple asks for suspicious emails to be forwarded to reportphishing@apple.com. Apple: recognise and avoid scams
- If you lost money or shared personal details, report it to the FTC. ReportFraud.ftc.gov
Already clicked? Close the page, change the password for any account you entered, sign out of active sessions, and report it anyway. Speed matters far more than blame.
Questions about Apple phishing emails
Don’t click anything in the email. Open the Apple Store app or type apple.com into your browser and check your order history. If there is no order, it was phishing: forward it to reportphishing@apple.com and delete it.
No. Apple announced in May 2022 that iPod touch would be sold only while supplies lasted. A new shipping confirmation for one is a red flag in itself.
Apple asks for suspicious emails to be forwarded to reportphishing@apple.com. At work, report it to your IT or security team first so they can remove it from other inboxes.
It is a phishing simulation template from Hook Security’s library, modelled on real attacks. Links and tracking have been removed from the screenshot.
Give your team a safe first encounter with emails like this.
Hook sends realistic simulations built from real attacks, then a short training moment right after any click. It runs on Autopilot.