FB pixel

Bogus fitness apps leverage biometrics to steal money from iOS users

 

Multiple apps recently banned from the Apple App Store stole money from iOS users by activating a payment mechanism while they scan their fingerprints to track their fitness, Slovak cybersecurity company ESET’s publication WeLiveSecurity reports.

The “Fitness Balance” and “Calories Tracker” apps offered BMI calculations, daily calorie intake tracking, and healthy activity reminders, but Reddit users claim that when used for the first time, they request a Touch ID scan to identify the user. When the user activates the fingerprint scanner, the app briefly displays a pop-up showing a payment of US$99.99 or $119.99 or €139.99. If a credit or debit account is on file in the user’s Apple account, the transaction is automatically completed.

If the user does not perform a fingerprint scan, a pop-up prompts she or he to “continue” and then repeats the scam attempt. WeLiveSecurity reports that “Fitness Balance” received at least 18 mostly positive reviews, including several 5-star ratings, and had an average score of 4.3 stars, and notes that the use of fake reviews by scammers is well-known.

The report authors speculate, based on similarities in interface and functionality, that the apps have the same developer.

iPhone X users can activate a feature which requires them to double-click the side button to confirm a payment.

Apple has been steadily expanding its integration of Face ID as the main biometric feature in its mobile devices.

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Report demystifies India’s unique face biometrics market beyond the benchmarks

Biometric authentication is taking off in India as the country’s government and market align around identity as a trust layer…

 

Trust inevitable in building human rights-sensitive digital ID systems

Some digital rights advocates who spoke at the recent ID4Africa 2026 AGM in Abidjan emphasized that for African governments to…

 

Nepalese raise concerns over new DPI loans amid previous project failures

Some experts have expressed apprehensions that the government of Nepal has contracted a new loan for the implementation of a…

 

GripID introduces ultra-compact multimodal biometric enrollment kit

France-based GripID has unveiled the compact V10 multimodal biometric enrollment kit for registration to national ID and civil digital identity…

 

Australia opens feedback on verifiable credential policy, trust framework proposals

Australia’s Department of Finance is inviting community feedback on a policy for using verifiable credentials proposed by the Commonwealth. The…

 

FBI warning on Kali365 phishing kit exposes limits of weaker authentication

A new Federal Bureau of Investigation (FBI) warning about a phishing-as-a-service kit targeting Microsoft 365 accounts is underscoring why major…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events