Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:43 PM

Reply
1,958 replies

Dec 6, 2010 7:54 AM in response to elcarmean

Hi
Same thing has happened to me - $42 worth of credit from a gift card wiped out, and address changed to 1905 60th Place, Towson, MD, 21286-7840 with phone number (365) 8542658
I have deauthorised all computers on my itunes account (there were 5 authorised - only ever had 4 before I THINK) and changed my password.
Emailed Apple - waiting for a response.

Why would hackers bother changing the postal address? Strange.

Dec 18, 2010 7:52 PM in response to mattyk72

Same thing happened to me in last three days. Got an email from apple saying my credit card info changed, which was weird. It actually was deleted from my account. Then 4 apps were purchased using $10 credit that I had. I notified apple, they refunded, and now the itunes store says I can't use my credit card. No Towson address change, though.

Dec 20, 2010 4:02 PM in response to stereocourier

Had very similar thing too. Got £25 giftcard. Added it to my account but hadn't spent it. Couple of days later I get an email saying my Name and Credit Card details had been changed, and two receipts for £11.99 in app purchases that certainly were not mine. Credit Card details were wiped, and I became a Mr instead of a Ms.
iTunes support were very helpful in giving me my money back, but I feel Apple are ignoring the bigger picture, that there is a massive scam going on and they need to do something about it fast. How many people are going to load giftcards on Christmas day and see them disappear?

Dec 22, 2010 9:30 AM in response to stereocourier

+1 for me. They wiped out $30.98 of iTunes gift card credit and changed the city/state to Towson, MD. I did have a credit card associated with my iTunes account, but lucky for me it was somehow removed from the account so no fraudulent CC charges occurred.

Those gift cards were birthday presents... What soulless creature steals BIRTHDAY PRESENTS!!?!?! That's just as bad as punching Santa Claus in the face.

An incredibly nice Apple customer support agent is helping me out now.

Dec 22, 2010 3:17 PM in response to stereocourier

add me to the list. While on holiday I got an email from Apple that the creditcard info on my iTunes account had changed. Could not respond since the wifi signal was poor/stopped working. When I came online again the next day `I received two mails with a purchase receipt for two apps each, totalling €27.46 , thus leaving €0,28 in my account. I do not have an IPhone nor iPad and I never bought an app. Luckily the creditcard I used for opening the account does not work anymore, so this was all they got.

I contacted Apple and they responded very quickly. They closed the account and will refund the €27.46 the next days. So that is good.

What is remarkable is that the purchase receipts show 3 out of the 4 apps to be developed by a certain "bin mao", the another one by "yu gao|1091937977". Certainly no coincidence.

Looks like this could be a way to get the apps in the top-charts or to write positive reviews? Unfortunately after Apple blocked my account I could not write a review anymore, to let the punters know that this is a fraud that works through compromised accounts.

If Apple wants to do anything about this theft they should go after the developers that use this fraud to get their apps rated. Apart from that I am very happy with the way Apple handed the situation, giving me a refund rightaway.

Dec 23, 2010 3:41 AM in response to Eagerbob

Same thing! They changed my billing address to Towson, MD 21286-7840, and burned up $29.54 worth of credit from a gift card. I just got the email that a change was made to my account yesterday, 12-22-2010. When I checked the account and found the charges I was (am) po'ed! I sure hope that Apple will find whoever is doing this and fix this hole!

iTunes store account hacked

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.