how can we use apple pay and got hack? it seems the service is not secured



I have got hacked in my accont when i paid the toilet in Rotterdam by apple pay since that they i used. i found out my account has the transection via the FaceBK names every day. im not sure how this service can garantee the user that it's secured.

iPhone 12 Pro, iOS 17

Posted on Feb 26, 2024 7:51 AM

Reply
Question marked as Top-ranking reply

Posted on Feb 26, 2024 9:19 AM

Sawitcha21 wrote:

I reject on this response as i have been using only apple pay no online shopping i don’t know how they can hack and know about my last digit ?

As you can see, the Apple Pay transactions do not know anything about the digits on your card. With that said, it does appear that your card has been compromised using a method other than Apple Pay.

  • Have you ever used the card at a retailer/gas station?
  • Do you have a Facebook account?
  • Does anyone know your password/passcode?
  • Contact the bank the card is issued from to dispute the charges and they should also be able to provide more information on how the card was processed.
8 replies
Question marked as Top-ranking reply

Feb 26, 2024 9:19 AM in response to Sawitcha21

Sawitcha21 wrote:

I reject on this response as i have been using only apple pay no online shopping i don’t know how they can hack and know about my last digit ?

As you can see, the Apple Pay transactions do not know anything about the digits on your card. With that said, it does appear that your card has been compromised using a method other than Apple Pay.

  • Have you ever used the card at a retailer/gas station?
  • Do you have a Facebook account?
  • Does anyone know your password/passcode?
  • Contact the bank the card is issued from to dispute the charges and they should also be able to provide more information on how the card was processed.

Feb 26, 2024 10:32 AM in response to Sawitcha21

The time frame is coincidence. The time frame from when your data is acquired via skimming, shimming or a BIN attack can be weeks or months.


Here’s a YouTube video that will help you understand skimming,


https://youtu.be/9--r1KTKdjg?si=ZGMvy-pFjW36dKMr


Here’s one on shimming


https://youtu.be/8YeEkcHuWQA?si=ePATRto2RkwTcmH2


Lastly, this may help you understand Apple Pay better


https://youtu.be/8XB__8HHqss?si=sXxnd-uHQbf1pCFc


None of these are official Apple videos and are produced independently.

Feb 26, 2024 8:22 AM in response to Sawitcha21

Apple Pay only transmits encrypted data between merchant and bank and back to merchant. Neither your iPhone nor Apple has the key to decrypt the data. Only your bank has the key to decrypt the data. The merchant only receives the necessary data to complete the transaction. The only decrypted part of the card information the merchant receives is the last digits of the device number (Apple Pay number).


So, your hacking/fraud claim happened some other way than Apple Pay.

Feb 26, 2024 9:44 AM in response to Sawitcha21

If you have ever used your physical card by swiping or using the chip, your data can be harvested. Your credit card number was skimmed or shimmed. Skimming is when you swipe your card and the magnetic data is captured by a device called a skimmer. Fraudulent actors then enter the data online or create a fraudulent card (fake) with your data. A shimmer is similar, but captures data off the chip.


No, your credit card number was skimmed or shimmed. Skimming is when you swipe your card and the magnetic data is captured by a device called a skimmer. Fraudulent actors then enter the data online or create a fraudulent card (fake) with your data. A shimmer is similar, but captures data off the chip.


Another popular way of harvesting credit/debit card data is a brute force BIN attack. Fraudulent actors gain access to a smaller business with weak security. They know the first 6 digits of the credit card is the Bank Identification Number (BIN) and put through tens of thousands of numbers and collect the hits that work. Then they use the numbers in a website and collect transaction data that work. This data can be sold on the dark web or used for fraudulent transactions at merchants.

Feb 26, 2024 10:06 AM in response to Mac Jim ID

  1. I don’t have a car..so answer is No.
  2. yes i have the Facebook account but i never use the Facebook online shopping as i know it’s risky.
  3. No
  4. yes i just did


thank you for your advice.

why i think it’s apple pay as because i went for a vacation in Amsterdam this week without the wallet as ( i forgot)

and why i think it’s the Apple Pay because i am leaving in Switzerland and have been using the Apple for 2 years recently what i assumed from the transaction is from apple Pay because i paid for the entrance toilet in the public area in the Market hall Rotterdam and then i saw those transactions keep coming in my account

Feb 26, 2024 10:13 AM in response to muguy

thank you for your advice.

why i think it’s apple pay as because i went for a vacation in Amsterdam this last week without the wallet as ( i forgot)

and why i think it’s the Apple Pay because i am leaving in Switzerland and have been using the Apple Pay for 2 years recently what i assumed why it’s definitely Apple pay as sometimes the payment need to do twice and first of my trip i paid for the entrance of toilet in the Market hall Rotterdam and then i saw those transactions keep coming in my account. So that why i definitely think it’s apple Pay

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

how can we use apple pay and got hack? it seems the service is not secured

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.