You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

📰 Newsroom Update

Billie Eilish is Apple Music’s Artist of the Year for 2024. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:43 PM

Reply
1,958 replies

Feb 26, 2011 10:41 AM in response to stereocourier

Count me in as another victim of this hack. I just got an invoice notice that I had purchased an app for free with the following description: 德州撲克, 560,000 chips, Seller: Hongbin Suo. So in essence, someone 'sold' me the app which I think is an iPad specific card game (FYI: I don't have an iPad on this account) and then charged me for 560k 'chips' for $19.99 which effectively wiped out my credit balance on my iTunes account. I had loaded the account with an iTunes gift card from Christmas. That is what was charged against, leaving me with about $2 left on the account.

I filled out an unauthorized charge note on the Apple Support web site as instructed, but based on what I see here, this is a much bigger issue than just my account. This is a systematic hack of the system that loots accounts of their credit balances. I sure hope those responsible are found and prosecuted. What a violation of trust...

Feb 26, 2011 11:03 AM in response to Ron Fink

wow Ron! Sorry to hear that an unauthorized purchase was made by someone to your account. This is what Im seeing and reading from here, from folks who are not using your machine. This is so freaky and stands to undermine itunes integrity. Do you think that this could be as a result of a malicious app from a prior session? My theory is, that someone has found a way to use a cookie and / or a bit of java code to compromise an itunes account. In my case, i suspect the hack came from somewhere in China. My unauthorized transactions (a 50.00 gift card and a track) occurred a month after I was in physically in China (I was in China from 10/1 to 12/25 of 2010). The transactions according to the bank, has not been presented for payment, and the itunes store reports that I have 1 download to initiate (apparently from the unauthorized transaction). The note I got from the tech person said that it was going to be another 5 to 7 more days before they feel like that they have something to report. While Apple is doing their investigation, I have fired up and created another Apple ID account so that i can download apps onto my iphone and some apps for USPS/ FedEx/ UPS tracking for my laptop. So far, I haven't been flagged with the new ID and hopefully this is the end of it. To summerize: Apple is aware of this thread, they are aware of my unauthorized transactions and that they will get back to me in 5 to 7 business days. In the meantime, i have created up another itunes/ Apple ID to download tracks and apps for my laptop and my iphone4.

All I have to do now is to check on the status of both Apple IDs on a daily basis to see if I get hacked again.

Feb 26, 2011 11:36 AM in response to Terrence

I find it interesting in looking at my on line iTunes account that I have 'no credit card on file' now. I thought for sure I had one listed in the past. But I do not have an issue with the billing address changed to MD as so many have reported.

So from what I can tell, it looks like a free Chinese based Texas card game app was shown as purchased two days ago on my account, followed immediately by an in-app purchase of credits to deplete my credit balance on iTunes. My credit card looks like it may have been removed somewhere along the line. A review of my bank account shows no unauthorized activity pending. So a potential breach of my credit card account may not be a concern.

One other thing I noticed that may/may not be related is that I noticed my iTunes account had 5 authorized computers on it. With all the iMacs, MB Pros and other Apple products around the house, it is very possible that I actually did have 5 legitimate computers on my account. But I decided to de-authorize all five just in case. I don't know if I could have found out what computers were listed and it's likely a moot point now. But it might have been interesting to see if there was an IP or some identification of a truly unauthorized computer listed.

Thanks for the insights into your situation, Terrence. I trust we can all ultimately get some kind of satisfaction from this wide-spread incident. The feeling that comes with a loss like this through no fault of your own is devastating. It will take a lot of time to restore the trust we had before any of this happened.

Feb 27, 2011 11:27 AM in response to stereocourier

Sigh...add yet another hacked, gift card loaded iTunes account. My balance was wiped out the 25th at 11:22 pm by *Hongbin Suo* with *Boyaa Company Limited* for a free app (Asian writing)followed by an "in app purchase" of 1,700,000 chips - followed again by two additional purchases of 340,000 more chips. Sadly, my account now sits at .75 cents. I had only just redeemed a new gift card on the very day of the hack. Changed password and noticed 5 computers were authorized, so deauthorized all and reset to one. I am uber cautious with passwords and security so this is shocking! As a note of interest, I redeemed the gift card via my iPhone (iTunes store), and I do not have my account tied to a credit card. All profile information was untouched. I only caught the fraudulent purchase because I was surfing PING via iTunes on my iPhone and noticed my balance had dropped to .75 cents.

I have filed an iTunes report & received an automated response that someone will get in touch within 24 hours. Hoping to get all my gift money refunded!!

Feb 27, 2011 3:17 PM in response to stereocourier

Add me to the list of people who got scammed. Someone took $21.24 for a fraudulent in app purchase for "德州撲克, 560,000 chips, Seller: Hongbin Suo" and "德州撲克, v2.0, Seller: Hongbin Suo". After googling it, the only app I could find was Boyaa Texas Hold'em from Boyaa Company Limited, which I've never downloaded or used. For now, I'll assume they are an innocent party to this.

My money was from a gift card, so I can't even dispute it with a credit card company. I sure hope Apple comes through and doesn't give me a hassle over it.

Feb 27, 2011 4:29 PM in response to stereocourier

Same issue everyone else here is having... lost $50 in store credit to an Online game I never downloaded. Whoever did this changed my city and state to Towson, MD and removed my credit card info. Interesting that this should occur shortly after I entered my Xmas gift card info... almost like someone at Itunes was watching for that activity.

Contacted Apple Customer Service, and they set up an incident report telling me I should hear back in 12-24 hours. We're into day 3 now with no reponse.

I contacted the company that distributes the game, and they told me my Itunes account had probably been hacked, made some security suggestions, and said that they are hearing this A LOT. Interesting that they got back to me just a few hours after I emailed, and yet Apple has still not responded.

It is very apparent that Apple Itunes has a big problem on their hands, and they are keeping quiet about it. When you have been hacked, and peoples money and private info has been stolen, you should **** well be more responsible (and responsive) than Apple is being.

As for me, I am regretting my purchase of the Ipad, and will certainly not be purchasing any more Apple products or dealing with Itunes in the future.

Wake up Apple, and offer phone support for the people who have been ripped off using your service. Otherwise, you might just lose your cash cow.

Feb 28, 2011 7:07 AM in response to stereocourier

Add me to the list as well. This morning I got a receipt from iTunes showing three transactions on my account... one was for downloading a free app and the other two were for in-app purchases of $19.95 each from that app. The item purchased was mostly illegible characters, but did list "GAMEISLIVE CORPORATION" and the artist was "Lakoo".

I emailed both Lakoo and Apple this morning and have already gotten a response from Apple (about one hour later) stating that the money will be back in my account within 48 hours. Nice response!

Feb 28, 2011 11:19 AM in response to nauticus25

Add another to the list. Just got charges yesterday for:
德州撲克, 560,000 chips, Seller: Hongbin Suo $19.99

Never bought the game or chips, they used all the credit left on my balance in iTunes. Sent an email in to support, and I hope they respond and refund promptly. I have already changed my password, so I hope it doesn't happen again. You would think they would block this seller/app by now so it wont keep happening. Too bad its not a Credit card, which is easy to refund, I am not at the mercy of Apple....

Feb 28, 2011 11:20 AM in response to stereocourier

Same issue dated 2/27/11. I received two gift cards over the weekend and redeemed them via my iPhone. Then I saw two unauthorized orders over totaling $50.00.

1 帝國 Online, 23400銀幣禮包, Seller: GAMEISLIVE CORPORATION LIMITED $19.99
2 帝國 Online, 23400銀幣禮包, Seller: GAMEISLIVE CORPORATION LIMITED $19.99
3 帝國 Online, 10530銀幣禮包, Seller: GAMEISLIVE CORPORATION LIMITED $9.99
The Artist listed for these is Lakoo.

And then there is a separate order for three more items (one app and two in-app purchases) totaling $8.97. I can't paste the details of that order here because I haven't received the email confirmation of the order from iTunes, and the iTunes app doesn't let you copy and paste text. This order shows the App Seller as Hua Tian and the Artist as ZipXing Studio. The two in-app purchases listed are Seller GAMEISLIVE and the Artist is Lakoo, just like in the first order.

I've emailed iTunes support and am awaiting their response. In the meantime, I've not noticed any activity on my checking account that it tied to iTunes. I removed my credit card from iTunes and changed my password. We'll see...

Feb 28, 2011 4:31 PM in response to BradGTX77

I have just been charged for three unauthorized orders over totaling $35.97.

There was Online, v2.3,Seller: GAMEISLIVE CORPORATION LIMITED|Lakoo|App|Free
Online,23400, Seller: GAMEISLIVE CORPORATION LIMITED|In App Purchase|$23.99
Online,5850, Seller: GAMEISLIVE CORPORATION LIMITED|In App Purchase|$5.99
Online,5850, Seller: GAMEISLIVE CORPORATION LIMITED|In App Purchase|$5.99

The Artist listed for these is Lakoo.

I checked and confirmed on my iPhone that I HAVE enabled Restrictions and In App Purchases are OFF.

I have changed my password and I too have emailed iTunes and awaiting their response.

Feb 28, 2011 7:03 PM in response to stereocourier

I have had the exact same thing happen to me. Same seller: Hongbin Suo and same changes made to my address. I was charged for about $25 against a gift card balance, leaving .17 in the account. I had previously had my iTunes linked to my debit card, and I have no recollection of removing it. However, it's saying I have no card on file now. This makes me worry even more since now I don't know if my bank account has been compromised. I've sent an email to iTunes (after frantically calling Apple and being told I have no other option) as well as my bank. This is really disturbing 😟.

Feb 28, 2011 9:22 PM in response to stereocourier

In my instance, my account was apparently hacked into. Somehow, 2 unauthorized purchases was made. 1. A music track and 2. a 50 dollar gift card. Both of these transactions did not show as being paid by me and a research of my Bank's CC didnt show neither of these transactions as being submitted or paid. In saying that however, it had appeared that my CC information had been altered at the time of the unauthorized transactions. The CC number had been altered as well as the Billing City, State, & Zip code. I can see at the time where I had written Apple and notified them of these unauthorized purchases, but no follow up disposition back to me. The only thing that I was aware of was being unable to download music tracks from asia which is understandable. Then, upon the introduction of the mac app store and the aquisition of an iphone4, i realized that I was unable to download free apps, with each failed attempted, the download would halt with a message saying that the Apple ID that i was using was disabled.
Apple has resolved my account so that I can download music and download free iphone and mac apps, and I am grateful for that, but now, I have this queasy feeling that I need to look over my sholder and check my Apple ID wondering when the next breech of security is going go to happen.

iTunes store account hacked

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.