I have seen a scenario where once a target is on a network they use the "game center" feature that is on by default in ios to connect to your device. The "game" is a fake home screen that is shared onto the device "to be able to play with friends"
They spoof basic password prompts for icloud or email because you are interacting with a faked home screen on your phone.
He could punch in his password, they take that and drain funds, remove the game and he comes back to the real app later confused by what happened.