You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:43 PM

Reply
1,958 replies

Mar 16, 2011 9:10 AM in response to MrRees

It certainly makes sense to suspect apps or devices, since they're known security risks and we travel around broadcasting our information in different places with them. But in my case, I don't have a mobile application, so the only possible interception would be at my home computer (unlikely), from an app (I have only ever purchased one (Pinball HD by Gameprom), or at Apple. Or, as some have suggested, brute force attacks. Apple NOW suggests that you not use your email as your id, which of course is the opposite of what they originally asked us to do. As my email address has been spammed and spoofed and everything elsed, it's entirely possible someone picked it up as a potential for attack, although my password wasn't a common dictionary word. Still no answer from Apple, 3 days in.

Mar 16, 2011 11:46 AM in response to Carl Johnson

I, too, had two $40 gift certs charged via iTunes to my Paypal account last night. Only one shows up in my iTunes purchase history, although I received Paypal notifications on both. I have contacted Apple via email, and started the dispute resolution process with PayPal. I basically only access iTunes via my iPhone, so I don't think there's any problem with my computer. I'm guessing it was either a rogue app on my iPhone (which is not jailbreaked or anything like that), or something like that. Hopefully Apple will get this resolved soon. $80 is a lot of money for me.

Mar 16, 2011 11:47 AM in response to stereocourier

Hi again all,

My dad received a reply from Apple. They have reinstated his gift card balance. However, the email reply was focused on password security... I do not think his password was compromised.

I HOPE Apple is looking into these recent fraudulent purchases and not just assuming passwords were compromised. Many here have the same thing happening to them involving the same purchases and gift balances.

Mar 16, 2011 1:24 PM in response to Carl Johnson

I also got a response from Apple today. They've credited the amount back to my account, but they've also locked the account. Doh! Hopefully they won't give me too much hassle about re-enabling it. Of course they gave me the standard drill about changing my password, etc. as well. I'd already done all of that, and I still don't think it was a compromised password anyway, but whatever.

When I responded back with the information that they requested to unlock my account again, I also gave them a link back to this thread, as well as restating what I said in my earlier posts here. Hopefully they're actually going to look into this further, and not just write it off to password hacking or user issues.

Mar 17, 2011 4:24 AM in response to Carl Johnson

Apple has restored my balance and my account. You have to go through a few steps to re-establish your account, but the account representative guided me through it well. I had pointed out this discussion thread to her, and she responded:
"Carl, in regards to the discussion link you provided, please know that we are aware of this, and that we are investigating this matter, as dealing with unauthorized purchases is not something Apple takes lightly."

I'm satisfied for now, but I sure hope they find a way to resolve this, as it seems to have been going on for some time.

Mar 17, 2011 5:40 AM in response to stereocourier

Same thing happened to me on 3/16/11. $19.99 taken from my account for Texas Hold'em (but I don't even have this app). If you go to view your purchases, it appeared with a bunch of other apps that were being updated - but I know that I did not purchase Texas Hold'em. There is a link to report a problem next to each purchase, but it just takes you to a generic page where you have to figure out how to report the problem. I finally think I figured out how to submit, and am now waiting to hear from apple.

I didn't realize that it was related until reading this that "Towson, MD" had replaced my actual city/state/zip, nor that my credit card on file had been deleted.

Now, I won't redeem gift cards until I am ready to purchase something.

Mar 17, 2011 9:36 AM in response to BradGTX77

Purchased on 3/16/11
1 帝國 Online, 23400銀幣禮包, Seller: GAMEISLIVE CORPORATION LIMITED $19.99
2 帝國 Online, 23400銀幣禮包, Seller: GAMEISLIVE CORPORATION LIMITED $19.99
3 帝國 Online, 10530銀幣禮包, Seller: GAMEISLIVE CORPORATION LIMITED $9.99
The Artist listed for these is Lakoo.

My address also changed to Towson, MD

exact problem with me last night. i contacted apple and am waiting for a response. I hope i they take care of this soon. My apple trust meter just went down to .01%

Mar 17, 2011 10:18 AM in response to stereocourier

*德州撲克(Texas Hold'em), 560,000 chips, Seller: Hongbin Suo $19.99*

Just as an FYI because it seems that a lot of people are having these issues (as well as I).... I purchased an iTunes gift card at Best Buy, activated card and within 24hrs this purchased occurred.

I have reported to Apple / Removed App / Changed Password.

_I am concerned and I am not sure if anyone else has had this issue:_
My credit card information was removed from my account, has anyone had any issues with unauthorized purchases outside of Apple?

Thanks

Mar 17, 2011 8:39 PM in response to stereocourier

Managed to get my account unlocked finally. They made me change my password again, despite the fact that I had told them that I had already changed it. What a pain. The response message that I got back focused solely on password issues, with no mention of the other info and suggestions that I shared. I have no confidence at this point that they're going to do anything about the issue, at least until a lot more people have complained.

I decided that I'm not taking any chances by leaving any gift card credit on my account for now, so I bought a few apps that I'd been thinking about with the balance that I had left to clear it out. I'm also not leaving a credit card number on my account for now -- if I really want to buy something, I'll put it on the account, and then take it right back off after the purchase is made. A lot of hassle (so I'll have to really want whatever I'm buying), but better than having to deal with disputing unauthorized charges (as a bonus, it'll probably keep me from buying a lot of worthless junk as well!). Otherwise I guess it's just free apps for me for a while. Hopefully Apple manages to resolve all of this soon.

@Nalberici -- I don't think you need to worry about your credit card being used outside of Apple, as iTunes masks all but the last four digits when it displays it. Then again, if the hackers have gotten into Apple's servers . . . but hopefully Apple is storing info like that encrypted. I dunno, I wouldn't be too worried right now, just keep an eye things.

Mar 17, 2011 9:04 PM in response to arcane93

Congrats on having your account straightened out. But, like you I am not happy with the whole process. At a minimum, there should be a live human in the loop to deal with fraudulently or unauthorized charges to ones account. I should not have to dance through hoops of fiery emails to report that fraud is being committed. I do hope that Apple Inc will realize that there is a liability issue in this continued practice. The larger question at play is.. how did this happen in the 1st place? To argue that it was you and I who were lax and that it was the end user who compromised and exposed their account for hacking, I find it very hard to believe. There definitely is a weakness and an exploit that continues to be at play. In my instance, the hacker did not gain access to my banks CC and initiate charges on that information, but rather was in a position to modify an existing bank CC to change the address, the CC number and the 3/4 digit security code. Once that was done, the hacker was then able to make the purchase of 2 50 dollar gift cards and 1 music track. A check of my bank information showed that I was not charged for it, but yet showed up as an event by the apple itunes store as if I had done so. For me, this occurred the 1st week of November 2010 when I was traveling overseas. As a result of that transaction, and lack of feedback to me, I was unaware that I had any problems with my apple id until 2 months later, when I tried to download a free app from the mac app and the iphone app store. At each time, it said that my apple id was disabled. I would never have guessed that my apple id was disabled since I was still able to log into my itunes store account and view my history. Likewise, i was able to log into the support area of this web site with my apple id to view and to leave messages. It was only when I attempted to purchase or download free apps, that I had any idea that there was a problem. To me, this isn't acceptable. The way I view it, if there is a problem with my Apple ID, I need to know ASAP without delay. That is a vulnerability that needed to be fixed immediately and not some 2 weeks or 2 months later. As a test..after my account was re activated so that I could download apps and music tracks, I purchased a 15.00 gift card and now have it up on my account. Every day, I check to see if it has been nibbled on. Every other day, I run MacScan and iAntivirus. In the meantime, I don't have any payment information on file other than the itunes gift card sitting there as bait.
It sure sounds like there are some Asian hackers on the loose that managed to post their apps to make stealth in app purchases. if that is so, there is a clear need to have that disclosure made. That NO APP can initiate an in app purchase without a confirmation code.

Mar 18, 2011 5:30 AM in response to kwoo2000

As a follow-up, Apple did respond to my report a problem message (I don't think they're even reading this board to look for people to fix) and restored the $19.99 to my account, along with a warning about passwords, and how I can request to unlock my account.

After reading this board, it seems to me that the hackers are getting in another way - and not from passwords. I did recently change my password last week when I bought the ipad2. I hope the store wasn't compromised then.

Mar 18, 2011 7:31 AM in response to Carl Johnson

It's something Apple doesn't take lightly?? Well maybe they could have a phone number to call? Also what about not being able to de-authorize other pc's? I don't have 4 other pc's to authorize so i can shut them all off at once, there should only be 1 authorized pc on my account. So far I'm out ALOT of money and no answer from Apple. I can't track where all the gift cards went, I can't do alot of stuff. All I can do is wait for Apple to "get back" to me?

Mar 18, 2011 5:13 PM in response to stereocourier

This has just happened to me as well. I got 2 emails from Paypal, each about a $40 purchase at Itunes on 3/17/11. Only one shows up on Itunes, but both show pending at my bank. I, of course, couldn't reach a human to take immediate action at Itunes, but was able to cut Itunes off as a payee from my Paypal account right away, through a customer service agent.

I can't believe this has been going on since late November last year, and is Itunes not found a way to interfere with it User uploaded file

I changed my Itunes account to form of payment: none.

I changed my password from a word and 4 numerals, to mix of capital and lowercase letters, symbols, and numbers, and began strengthening other passwords.

I called the Apple 1800 #, cuz I got there from the Itunes website, but was informed that they(Apple) are not Itunes and they couldn't resolve it for me, however the same helpful customer service agent did send Itunes an email about my account and all the particulars. I then got an email from Itunes that they'd received the report email, it was an automated response, said they'd get back to me within 24 hrs........ I am assuming they will make good my $80 somehow. I don't want account credit at this point, I want a check.

By the way, the "purchases" I didn't make were both for Itunes gift cards. The one I could see on Itunes said it was for "fds". I don't know who that is. My address, etc. was unchanged.

THERE SHOULD BE AN ALERT SENT OUT TO ALL ITUNES CUSTOMERS, TO AT LEAST STRENGTHEN THEIR PASSWORDS!

Good Luck
Liz

iTunes store account hacked

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.