With iOS 17.3, Apple is launching a new Stolen Device Protection feature that aims to protect users should they have their iPhone and their iPhone’s passcode both stolen.
In a new article and video on Wednesday, The Wall Street Journal’s Joanna Stern sat down with a prolific iPhone thief who took advantage of the iOS vulnerability to rake in over $20,000 every weekend from victims.
This story is supported by Mosyle, the only Apple Unified Platform. Mosyle is the only solution that fully integrates five different applications on a single Apple-only platform, allowing businesses and schools to easily and automatically deploy, manage, and protect all their Apple devices. Over 38,000 organizations leverage Mosyle solutions to automate the deployment, management, and security of millions of Apple devices daily. Request a FREE account today and discover how you can put your Apple fleet on auto-pilot at a price point that is hard to believe.

Stern and Nicole Nguyen at The Wall Street Journal were the first to go in-depth on this widespread phenomenon back in February. Thieves would watch people enter their iPhone passcodes, then target that same person and steal their iPhone. With the passcode, the thieves could change the victim’s Apple ID password, access banking applications, and much more.
Today’s article from Stern gives an up-close look at the life of one criminal who made this a full-time job.
“I’m already serving time. I just feel like I should try to be on the other end of things and try to help people,” Aaron Johnson told Stern. “That passcode is the devil,” he said. “It could be God sometimes—or it could be the devil.”
Dimly lit and full of people, bars became his ideal location. College-age men became his ideal target. “They’re already drunk and don’t know what’s going on for real,” Johnson said. Women, he said, tended to be more guarded and alert to suspicious behavior.
There was also quite a bit of social engineering involved in Johnson’s process:
Friendly and energetic, that’s how victims described Johnson. Some told me he approached them offering drugs. Others said Johnson would tell them he was a rapper and wanted to add them on Snapchat. After talking for a bit, they would hand over the phone to Johnson, thinking he’d just input his info and hand it right back.
Once Johnson had the passcode and iPhone, he’d quickly change the Apple ID password and enroll his face in Face ID on the device. From there, he’d look for any funds in banking apps, Apple Cash, and crypto apps. He’d also check the Notes and Photos apps for extra information like Social Security numbers.
Top comment by Expert (Retired)
Earlier this year, two customers- both men in the mid to late 20s- came into my store a couple days apart with exactly the scenarios written about here.
Both in bars, both had their phones stolen in the split second they left on a bar or table and turned their head away from it. Of course, someone saw their passcode and then went to work.
One had $20,000 taken from a bank account. He was lucky. He worked for the bank and they were able to reverse the transaction. The second had an Apple Card opened up in his name and trying to convince Goldman Sachs that this wasn't him and the phone was stolen was not an easy task. I have no idea how that turned out.
The new system coming in iOS 17.3 is a big improvement but it will be a bit of mess inside Apple stores. Many people have no idea what their Apple ID password is; or they have six different ones written down on various scraps of paper and none are correct. Right now, it is pretty easy- too easy- to create a new one. Once Stolen Device Protection is out, it is going to take an hour before they can do that and some customers are not going to be happy. Oh well.. I'll just tell them it is better than having their bank account emptied.
After he was done with the iPhone in question, he’d erase it and sell it to his partner, Zhongshuang “Brandon” Su, who would then sell it overseas.
On a good weekend, Johnson said, he was selling up to 30 iPhones and iPads to Su and making around $20,000—not including money he’d taken from victims’ bank apps, Apple Pay and more.
Johnson pled guilty to his role in accumulating nearly $300,000 from stolen iPhones in March and was sentenced to 94 months in jail.
The full piece and accompanying video are well worth checking out at The Wall Street Journal. Here’s a link to the story on Apple News as well.
Follow Chance: Threads, Twitter, Instagram, and Mastodon.
FTC: We use income earning auto affiliate links. More.

Comments