Hacked appleid added new Security questions, apple says this is not possible...
This morning I got a spam of 4 emails from AppleID saying someone changed date of birth, name, password and the security questions on a very old alternative appleid I have which I've never used for anything as far as I know. I'm sure it had a weak password.
I still want to recover it though, or understand Apples process, for the principle if nothing else and as it's scary to believe they don't know how their own system works if it happens to an important account.
So as the hacker didn't change the email, I could reset the password, but after signing in with the new password, it now asks for the Security questions, but they are now in Chinese, and (translating with google lens...) they are NOT anywhere near any questions I would have picked. If I click "Reset your security questions", Apple support says this should ask me any of the original questions from when I created the account, but then I get:
Cannot Reset Security Questions
We don’t have sufficient information to reset your security questions.
Apple Support claims that it is IMPOSSIBLE because ALL accounts have security questions. But is this true? Maybe a super old account doesn't have it? It does seem the login page itself gets confused here :)
They did offer to open an "email dispute" for the account so I at least could re-use the email later if I want. They also helpfully said I could call the police..
The hacker did NOT add any extra phone to the account, and I had no devices connected to it either and fortunately no payment methods so there is really no big deal about this, like I said it's just out of principle I'm curious on what is missing here.
Obviously the hacker got in by a weak old password, but I'm pretty sure they wouldn't have been able to guess any pre-existing security questions if there even was one (this was probably an automated script), this leads me to believe Apple have a problem here with old accounts. Apple support says even for old accounts there was always at least one security question, which is why they refuse to process any recover requests now for hacked old accounts, but like I wrote above this seems to be false or have some issue that Apple themselves don't know about...
It would have helped Apple and its customers a LOT if they had some kind of smarter hack detection system that like immediately flags an account if someone goes in and in a matter of *minutes* changes ALL available fields in an account...
Furthermore it's not very helpful for AppleID to send out these emails saying that if I wasn't the person doing the changes, log in and reset your password, when the system won't let me do that :)