Can Apple Pay get hacked?

I have payments on one of my bank accounts that has been done by apple pay but I dont recognise it


[Re-Titled by Moderator]

iPhone 14 Pro Max

Posted on Jul 13, 2023 1:01 AM

Reply
Question marked as Top-ranking reply

Posted on Aug 23, 2023 1:10 PM

Contact the bank that issued the credit or debit card used for the fraudulent transaction. Apple Pay does not approve or decline charges. Apple Pay only securely transmits the data associated with your card. Your credit card issuer approved the charge and you need to dispute the charge. Please use the phone number on the back of the card and talk to their fraud support team.

99 replies

Apr 14, 2024 8:09 AM in response to Bborz

I’m saying Apple Pay hasn’t ever been hacked. I’m saying people are tricked into revealing information or permitting the use of someone else’s account information.


I can added a card to my device two ways. One is to log into my Apple ID, enter my information, agree to terms and conditions, and pass security requirements Apple, Payment Network and bank require and it’s ready to use Apple Pay.


The second way is for someone to gain access to your Apple ID by socially engineering (tricking) you into revealing essential information and then adding their device to your Apple ID and then adding cards. A similar method is adding card information to an Apple ID (not yours) and again, agree to terms and conditions and pass security requirements Apple, Payment Networks and banks require. In some cases the card passes requirements, but in others social engineering may be required with bank personnel or owner to obtain information necessary to add card to device and use Apple Pay.


The common denominator is people being tricked into providing necessary information. However, as much as we hate to admit it, technology is not the failure point.

Jan 8, 2024 5:29 AM in response to kca33

Just because Chase support personnel are poorly trained and do not understand how Apple Pay works, does not make a statement false.


Your Apple Pay number is encrypted. The actual number is not stored on your iPhone or used in the transaction. A one time use token is used in conjunction with each transaction. Only your bank has the key to decode the number.


The most likely way fraudulent charges occur is by having your physical card skimmed (copies mag stripe number) or shimmed (chip number is copied).

Mar 4, 2024 5:17 AM in response to deanridgeracer

No, Apple Pay has never been compromised. Its safety and security are tops in the industry.


The more likely scenario is the credit/debit card information was skimmed or shimmed at an ATM or transaction terminal at a merchant’s POS. Merchants are occasionally hacked as well, which puts online transactions at risk, if Apple Pay isn’t used.


Ive linked to several videos below that explain skimming and shimming.


https://youtu.be/EhgkuVneHgM?si=83AT4Efg4ouXqzLJ


https://youtu.be/GFoaeHk-UV4?si=PnQaO0wE5kTVko1u

Feb 3, 2024 11:22 PM in response to Ninnie6211

As a fraud investigator, If you are seeing transactions on your bank statement that are not you and your bank is telling you they were done on Apple Pay - then it is most likely that your actual physical bank card details have been added to another apple device to make the transactions. Providing that these transactions you query are not in your Apple wallet history.

Apr 26, 2024 3:51 AM in response to BotanicalGenus

Your account(s) could have been compromised weeks or even months ago. Personal and financial information is bought and sold on the Dark Web 24/7. Even after the accounts are closed by the bank, fraudsters will continue to buy and sell the information.


Apple Pay transactions are end to end encrypted and only the bank has the key to decrypt. Card information is compromised by the use of non-encrypted data such as swiping the card or inserting the card and using the chip. Then the merchant ends up with the complete account information in plain numeric format.

Apr 26, 2024 5:37 AM in response to Bborz

I think the general reaction is to want to blame something we don’t understand, like Apple Pay. Banks told people how safe credit cards were and people believed them. Then they were told to use a chip, it was more secure than swiping and people believed them. Well, now you have something people truly don’t understand and when their credit card is compromised, they blame what they don’t understand, Apple Pay. They also don’t want to accept responsibility for sometime comprising their own account by giving out their 2FA code to fraudsters posing as the bank or Apple. Social engineering by fraudsters is real and is more common than people want to admit. Just my opinion. 😀

Apr 13, 2024 11:03 AM in response to soquel1

Apple Pay has never been compromised and there was no breach. Thinking Apple Pay can be hacked is the first thing that people think. People never suspect their own activities or use of credit devices and how they potentially compromise their personal information.


Even if you want to continue your assumption that Apple Pay was hacked (which it can’t) how do you explain that all Apple has on it’s servers is encrypted data, all you iPhone has on it is encrypted data, and all the merchant has is encrypted data?


How do the hackers decrypt the data? They would need a key, don’t you agree? Who has the key? Your bank has the key. So please explain how Apple Pay got hacked and while you’re at it explain how they decrypted the data they hacked.

Apr 18, 2024 7:44 AM in response to Jeff Donald

Most (all?) banks update the virtual cards in digital wallets (Apple Pay, Google Pay) automatically when new account numbers are issued. They also do this when cards are about to expire and a new card is issued with new expiration dates.


Payment networks (Mastercard, Visa etc.) automatically update subscriptions with new account numbers. Mastercard introduced it first and calls it Mastercard Automatic Billing Updater (ABU).


You card information is compromised and has been added to someone’s Apple Account and it’s being used to pay for subscriptions. When your bank updated the account details, the subscriptions were all updated with the new information.

Apr 14, 2024 9:48 AM in response to Jeff Donald

So, how does a grocery store employee decrypt a code that only the bank has the key to? It’s never been done. Not even in research or a proof of concept. Yet a grocery store employee hacks a previously never cracked code. That’s a good trick. The employee could sell the hack and get millions, but instead chooses to work in a grocery store and nickel and dime fraudulent transactions. That’s an amazing person.


Please read the wiki link I posted on tokens. Even if they hacked a single transaction. The code it contains is a one time use code. It would be rejected immediately if tried to be used again. So, the grocery store employee ends up with code, that hasn’t been hacked, but does, gets a code that can only be used once and uses it a second, third and fourth time. I don’t see the common denominator that you do. A bank employee is in an even worse position.


I’m going to assume, that the bank is referring to the DPAN I mentioned above. The PAN (Primary Account Number) is replaced by your bank with the DPAN (Device Primary Account Number) during the tokenization and provisioning process. This article explains DPAN and usage within the payment process.


https://help.vtex.com/en/tutorial/dpan-and-fpan-understanding-security-in-the-online-tokenized-payment-flow--3RM7RvhKZ057wja5xVEOqb


They may be referring to other identifying information, but with more specifics and can’t help with explaining. There are other unique codes your device has they could be referring to. The codes you refer to (BIC?) could be nothing or a code the bank, payment network or gateway is using as an identifying code. The only BIC I know of is the Bank Identifying Code. BIC is used in Swift transfers when funds are going to transferred from a bank in one country to another. You did say, you’re not in the US, correct? This would mean nothing in a credit card transaction. Not sure what “government services” has to do with the transaction without more information.




May 20, 2024 12:54 AM in response to Jeff Donald

im starting to lean that my bank is compromised with your threads talking about only the bank have the unencrypted data.


I have 30+ year IT experience and have a good amount of experience with security.


every few weeks or so I get SMS telling me banking services will be paused due to security updates. Usually after midnight on weekends.


I’ve been approved for a replacement card and should get it within the usual 3 days.


lets see how this one last considering the compromised one is less than 3 months.


prior to last year I had the same card for 3 years with no issues with the same usual usage habits.


switching banks might be an option if this issue persists.

Apr 13, 2024 11:14 AM in response to Ninnie6211

For anyone in this situation, I cracked the code nearly a month later. I used my Chase debit card in my Apple Wallet at a KwikTrip and inserted my pin, which for the longest time I believed you had to do in order for something to be charged on a debit card. What’s funny is my purchase was only $1.69, and the fraudulent charges that followed were hundreds of dollars. Remove your cards from your Apple Wallet and start fresh - Chase sent me a new card after the first incident and it automatically updated in my Apple Wallet, so MORE fraudulent charges appeared before the card was even shipped over to me. I’ve since added my brand new card (new Chase account and credentials) to my Apple Wallet and have used it with no problems. If anyone else is like me and has been entering their pin at places like gas stations (though this was my first time even doing so inside the store as I don’t drive), make sure you don’t do that anymore! Hope everyone can get their charges reversed and be protected moving forward.

Apr 14, 2024 6:41 AM in response to Bborz

You’re making a false assumption. If Apple Pay is used at a transaction terminal, it’s a card present transaction. Card Not Present (CNP) is done in app or online.


ls Apple Pay considered card-not-present?

If Apple Pay is used in-store at a terminal, it is considered card-present. Payments on a phone or for in-app purchases are considered Card Not Present.”


https://www.chargebackgurus.com/blog/a-business-owners-guide-to-card-not-present-cnp-transactions


It’s done because the bank added your card to another device and it was used for transactions online or in an app. The data was added because either you, a member of your family that has a > trusted device< or the bank personnel were socially engineered into allowing the card data to be added to an Apple device. The device was used to approve either in app or online Apple Pay transactions.

May 2, 2024 9:35 AM in response to Kylemcc10

It requires the authorization of device the card is on. The actual account owner is not required to authorize all charges. In other words if I give my wife my card, she adds it to her wallet and makes a purchase. She authorizes the transaction, not me on my iPhone. If a fraudster adds the card to his iPhone he authorizes the transaction not the account owner. However, the account owner will see the charge. That is what the post sounds like it’s saying, that he didn’t Authorize the transaction. But it’s not required that he authorize the transaction.


So, you entered information on a fraudulent website or website that was hacked and fraudsters. Who is they? You do realize that the card can’t be added without the banks approval? The issuing bank approved and verified that card when it was added to Apple Pay. Did you ask your bank why they verified fraudsters to add the card to Apple Pay? Why did your bank do it?

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Can Apple Pay get hacked?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.