Hacked appleid added new Security questions, apple says this is not possible...

This morning I got a spam of 4 emails from AppleID saying someone changed date of birth, name, password and the security questions on a very old alternative appleid I have which I've never used for anything as far as I know. I'm sure it had a weak password.


I still want to recover it though, or understand Apples process, for the principle if nothing else and as it's scary to believe they don't know how their own system works if it happens to an important account.


So as the hacker didn't change the email, I could reset the password, but after signing in with the new password, it now asks for the Security questions, but they are now in Chinese, and (translating with google lens...) they are NOT anywhere near any questions I would have picked. If I click "Reset your security questions", Apple support says this should ask me any of the original questions from when I created the account, but then I get:


Cannot Reset Security Questions

We don’t have sufficient information to reset your security questions.


Apple Support claims that it is IMPOSSIBLE because ALL accounts have security questions. But is this true? Maybe a super old account doesn't have it? It does seem the login page itself gets confused here :)


They did offer to open an "email dispute" for the account so I at least could re-use the email later if I want. They also helpfully said I could call the police..


The hacker did NOT add any extra phone to the account, and I had no devices connected to it either and fortunately no payment methods so there is really no big deal about this, like I said it's just out of principle I'm curious on what is missing here.


Obviously the hacker got in by a weak old password, but I'm pretty sure they wouldn't have been able to guess any pre-existing security questions if there even was one (this was probably an automated script), this leads me to believe Apple have a problem here with old accounts. Apple support says even for old accounts there was always at least one security question, which is why they refuse to process any recover requests now for hacked old accounts, but like I wrote above this seems to be false or have some issue that Apple themselves don't know about...


It would have helped Apple and its customers a LOT if they had some kind of smarter hack detection system that like immediately flags an account if someone goes in and in a matter of *minutes* changes ALL available fields in an account...


Furthermore it's not very helpful for AppleID to send out these emails saying that if I wasn't the person doing the changes, log in and reset your password, when the system won't let me do that :)


Posted on Aug 22, 2024 2:42 AM

Reply

Similar questions

5 replies

Aug 22, 2024 7:10 AM in response to AppleFanboy44

You are confusing things. Several years ago Apple transitioned to using two factor authentication instead of security questions. You can continue to use security questions if you already use them and they are working for you, but if you have problems then they no longer get direct support. You can try the directions in this support article If you forgot the answers to your Apple ID security questions - Apple Support but the article is labeled "archived" and may contain information that is out of date. If the instructions work then fine; if they do not (e.g., “not enough information”) then you will have to change to the newer security method if you can. Over the past few years Apple has been persistently encouraging users to switch to the newer security system. For those who have disregarded their encouraging, Apple will likely only help you change to two factor authentication, if even that is possible. Follow the instructions in the "Turn on two-factor authentication for your Apple ID" section in this support article --> Two-factor authentication for Apple ID - Apple Support to try to change to two factor authentication.


If you still need help, contact Apple ID support at this link ➞ https://getsupport.apple.com/?caller=cups&PGF=PGF63005

Select "Other Apple ID Topics", then "Security concerns or account compromised." This will give you a chat or telephone call option.


If Apple can not or will not help you transition to two factor authentication then it is quite possible you will have to simply abandon the old account and everything it contained.


Good luck!


Aug 22, 2024 2:16 PM in response to Limnos

Yeah well I can prove I'm the owner of the account to the same security-level as the account was created in, as I own the email associated with the account and there was apparently no further conditions back then. I also have the password to the account. And Apple certainly knows that there were no other security questions active at the time the account was setup once upon a time.


Thus, insofar as that logic applies, the account is mine equally much now, as it was when it was created. Nothing has changed, except that a script from China has added 3 security questions to the account but those were added today, and if Apple had any access to the Changelog of the accounts they would be able to see this and disregard these newly added questions and revert to the previous state of the account.


If they would have done that, it wouldn't matter who was the hacker or who wasn't, as the account would just be in the hands of the original email account again and not to any of the ones in a potential account dispute.


Their support even said that we can open an "email dispute process" where I prove I own the email the account is based on. And if successful, I get my email back for re-use at apple, but the account is then donated to the hacker, so not very useful. For the case of these old accounts, they should have extended that "email dispute process" to include the account as well.


As a funny side-note, I'm writing this as the hacked account. On the discussions.apple.com page, you can apparently login with the account in this state (i.e. username + password), as long as you just click Cancel when it then asks you for the security questions, it asks you if you want to upgrade to 2FA, you click Cancel again, and you're suddenly logged in to the Communities... doesn't help me of course.



Aug 22, 2024 8:18 AM in response to Limnos

Yeah I know about the 2FA, I use it on my primary AppleID accounts of course. I didn't even know I had this older account, and they never sent any emails to it about it requiring a 2FA upgrade either so had forgotten about it.


Like I wrote, you just get the "We don't have sufficient information to verify you" if you try to reset the security questions that the hacker inserted.


So since you can't log in fully, you can't enable any other 2FA, you can't "Upgrade your protection methods" or whatever that button was called, because that button also leads to the Security Questions box.


It's a kafkaesque nightmare and Like, currently nobody can log in to the account - the hacker can't (because I changed the password and I own the email) and I can't log in since it is setup using the hackers security questions.


I spoke with them on the phone, but the guy was unhelpful and basically said he couldn't do anything, if you can't log in to your account we are not going to help you. This would make sense for a 2FA account (and I fully agree on that policy!) but it does NOT make sense for a pre-2FA account pre-security questions account.


There is nothing on the account so I don't care personally but I like Apple's products in general and am a backend developer and CTO and therefore I just get incredibly annoyed by such oversights.


Like I wrote first, it amazes me that they don't have anti-hack protection tools in place in the first place. Who needs to change all parameters of their account the same 5 minutes, if it was untouched for 15 years? It would require a one line of backend code to put a quarantine on that process. Same quarantine that they apparently have if you try to switch an account from security questions to 2FA.


[Edited by Moderator]


Aug 22, 2024 8:59 AM in response to AppleFanboy44

if you can't log in to your account we are not going to help you


Yes, that sounds like a fair summation from what the support articles say and what others have reported. Apple will help you change to two-factor, but to do that you have to be able to prove by some other means you are the owner of the account. If you cannot then they have no way of telling that you yourself are a hacker trying to get into somebody's account.


As I said before, Apple changed to two factor several years ago and will persistently ask you to change to 2FA every time you log in. If you ignore that then the consequences are upon you should you later have problems with the account. I'm not being mean but that's basically what it means.


As for anti-hack tools, you are welcome to make any suggestions you have to them at: Product Feedback - Apple

Apple may not respond but your comment will be read.


Aug 22, 2024 7:04 AM in response to AppleFanboy44

Your Apple ID was on outdated security feature, sounds like secondary authentication. It’s been highly recommended for several years to update your security and use two factor authentication and known that only the user can be in control of their Apple ID.


Does Apple have behind the scenes processes in place? Yes, but it’s not shared and we can’t speculate to it here that would likely satisfy your curiosity.


Does it suck you’ve lost the account? Yes.


What can you do now? dDo your best to forget and move on.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Hacked appleid added new Security questions, apple says this is not possible...

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.