A friend's iPhone X was stolen yesterday from his gym locker.
We immediately set iCloud to activate the 'Lost Phone' function to lock it when it comes back online, as the phone was turned off. The option was also selected to notify us if the phone was located.
A short while later, he received an sms on his wife's phone stating that the phone was located, containing a URL:
https://apple.com.location-apps.top/?idmsa=005
This URL redirectes to the authentic iCloud website.
If this was a phishing attempt by the culprits, how could that help them?