You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:43 PM

Reply
1,958 replies

Apr 4, 2011 1:32 PM in response to stereocourier

Add me to the list - got hit yesterday for over $36.

1 Weather+, v1.7, Seller: International Travel Weather Calculator (4+)
Write a Review Report a Problem $0.99
2 Final Fantasy III, v1.0.0, Seller: SQUARE ENIX Co., Ltd. (9+)
Write a Review Report a Problem $15.99
3 LEGO Harry Potter: Years 1-4, v2.2, Seller: Warner Bros. (9+)
Write a Review Report a Problem $4.99
4 Penultimate, v2.3, Seller: Cocoa Box Design LLC (4+)
Write a Review Report a Problem $1.99
5 Dungeon Hunter 2 HD, v1.0.0, Seller: Gameloft (12+)
Write a Review Report a Problem $6.99
6 XSysInfo - device booster, v1.4.4, Seller: XZone Software LLC (4+)
Write a Review Report a Problem $1.99

Contacted Apple, got the "we got your e-mail" automated response. I didn't notice a change in address (will have to double check when I get home) but did notice the CC I had on file was now gone.

Apr 5, 2011 7:57 PM in response to stereocourier

Hey, Same thing happened to me. Apparently I downloaded 德州撲克(Texas Hold'em) and 20 dollars worth of chips in this game, unbeknownst to me. I talked to my dad, who happens to work at apple, and he has pretty much sent an email directly to the VP of Itunes. Hopefully that will allow this problem to be fixed and if not well that *****.

Edit: Also this was a use of the allowance feature to give me money so it is not only the gift cards.

Message was edited by: Gunchkman

Apr 5, 2011 8:11 PM in response to MichaelTLH

Today I received the following email notifications from iTunes for the following unauthorized transactions:
Allowance for inan398ming@hotmail.com 1 $40.00
Allowance for yan979pingkung@hotmail.com 1 $40.00
Allowance for han2012tzui@hotmail.com 1 $40.00
Allowance for michingch@hotmail.com 1 $40.00
Allowance for semiable38@hotmail.com 1 $40.00

These charges did not appear to post to my checking account (yet), but I called my bank and canceled my debit card. My bank instructed me to keep an eye on my checking account and report these charges if they do show up.

First I changed my password, then I also spoke to someone in iTunes customer service (after the robot hung up on me twice) and he suggested that sometimes people log in to the wrong iTunes accounts by mistake and conduct business as usual, not realizing that it's not their account. I was like: what.

Whomever got in to my account changed my debit card to a number that I did not recognize (I could only see last four digits, but it wasn't mine), and they changed my city, state, and ZIP, but my name and street address remained the same. The invoices emailed to me by iTunes had the last four digits of my debit card, so I flipped at first. I had my identity stolen a few months ago so I am ultra paranoid now and very cautious, or so I thought. I also emailed iTunes customer service with the order numbers, etc.

Then I removed the (unrecognized) credit card from my account, fixed my address, and de-authorized the five computers / devices that I'd had authorized. I just did this last bit out of instinct. Only three of the five are computers to which I have regular access (the other two are computers that are no longer in use), one of which is my work PC, which I suspect has in the past been compromised (although I haven't used iTunes on it in ages). I'm almost positive my previous identity theft occurred through my work computer, but I can't prove that. But we get a lot of viruses at work.

A facebook friend of mine, who works in information security, suggested that perhaps my iTunes account had been compromised not due to an issue on Apple's part, but via my own computer, an older MacBook Pro, which he said would have much more serious and scarier implications for me. I'm not a computer expert, so I don't really know what he means by that. I hope to learn more and will post here if / when I do.

Apr 6, 2011 9:24 AM in response to Tab1975

That's a fairly rude response. I've had that before, when there have been downloading issues and they've "graciously" offered to fix them, and I understand, they don't want people taking advantage of them by getting free downloads. But this problem clearly has nothing to do with the people being ripped off, and everything to do with Apple. We're not buying these rogue apps (which shouldn't even exist if they can siphon off accounts -- isn't that a security risk that should be apparent), we're not giving out our passwords to others. There is no chance that my account was compromised anywhere but at Apple's end, and they're still giving out varying responses to what appears to be a major problem. I was about to cut my cable and purchase a number of TV seasons through iTunes, but now I won't, and I'll make my music purchases elsewhere, too. I can't risk having all my personal info ransacked and having to beg for Apple's indulgence to fix it.

Apr 6, 2011 6:46 PM in response to stereocourier

I got hit today as well with the unauthorized purchase of 德州撲克(Texas Hold'em), 560,000 筹码, Seller: Hongbin Suo. I found this thread via Google. I emailed ITS and they responded within a few hours, refunded my account and the disabled my account. I responded to a few questions and now my account is reenabled. ITS did this all in a matter of 5 hours...must be good day for them 🙂.


Points of interest:

I recently added a iTunes gift card to my account.
I added the GC to my account with a MacBook Pro.
My credit card information was removed.
My billing city and address were changed to MD.

Seems like this is a pretty common occurrence as of late. Apple needs to address this with its consumers.

Apr 7, 2011 9:15 AM in response to NuPoet

Got hit by the Texas Hold'em folks as well this morning for $24.99.

Apple is making a "one time exception" to their policy and refunding my money and resetting my account. They also "suggest" that I change my password following their guidelines. I will change it, of course, but I've got to say, as wide spread as this seems. It feels more like an Apple security issue and not a user security issue. People aren't guessing our passwords, and they shouldn't be able to brute force their way into our accounts, there should be security measures in place to protect against that on Apple's end.

With the exception of a few instances of "allowances" being attacked, the issue seems strongly tied to gift cards, so I hope Apple is looking into this and not writing it off as an acceptable level of customer dissatisfaction. I for one, will be ceasing to purchase Apple gift cards for friends and family until such time as I feel like this is under control...

Apr 9, 2011 1:09 AM in response to stereocourier

My account was hacked today. 6 purchases of a total of around $200 worth of 'account allowances' (gift cards?) were made within 2 minutes of each other. Then my account info was changed to my street number but the city was changed to Lewisburg, TN in Bedford County. Also, the credit card number was changed. I changed my password, but I feel violated.

Message was edited by: vaalkyrie

Apr 9, 2011 7:23 AM in response to vaalkyrie

just a thought,

the change of cc # on the hacked accounts:
you dont think the same cc# would be used on all the hacked that had the cc# changed, do you? i wouldnt think so, but id be interested to prove it wrong!

for the people that had there cc changed to a diff. # , would you want to post the last 4 digits?

Apr 10, 2011 8:22 AM in response to Carl Johnson

This just happened to me, and I don't know what to do because Apple conducts business with 'phantom' customer service. Try to talk with anyone and you get the automated run-around. How do I get them to refund me for this and what do I need to do to keep my account from being hacked again. many thanks for any input.
帝國 Online, 23400銀幣禮包, Seller: GAMEISLIVE CORPORATION LIMITED $19.99

Apr 10, 2011 1:44 PM in response to bush817

Same thing just happened to me yesterday. Street address was the same but the rest was changed to Towsend MD, 21286-7840. 德州撲克 3.0.ipa was the app that I found in my account (texas hold'em app). Credit card information was wiped out and they used up most of my credits.

I got charged 49.99 and 9.99 for "chips" in the "free" app. I was on a camping trip while this was charged to my account. I didn't have any electronics with me so it wasn't me. Apple needs to ban this developer and pull the kill switch on their apps. What are they waiting for?

Itunes security is compromised. They needs to fix it now.

I've sent off a note and hopefully, I'll get back my credit.

Apr 10, 2011 7:28 PM in response to stereocourier

Wow, I don't know if I'm glad to see I'm not the only one or ****** to find out that this is such a widespread problem and Apple hasn't figured out what's going on yet!

I bought my iPad 2 three weeks ago, got $50 in App Store cards a couple days later. I did enter them via my iPad, since someone asked about that. Today I went to check my balance, which should have been in the $20 range, and it was 90 cents! This morning someone downloaded 13 apps, half of which are in Chinese, for a total of $19.17. Luckily I did not have a credit card listed, so once they ran the gift card down they were finished.

I changed my password immediately and contacted support to try and get a refund - now I will be severely ****** if they don't give it to me, seeing as how this is clearly a known problem. I have ONLY logged into this account through the iPad App Store in the past several months. The last time I even downloaded anything on iTunes was last May, and I certainly haven't given the password out over email or anything.

Now I'm not sure how to proceed. I'd planned to only buy apps via gift card, to avoid a dozen $1-5 charges on my credit card, but are those the source of the security breach? But then, I sure don't want to give them my credit card info after this. Grrrr, I just handed Apple $500 for this iPad and now I feel like I can't even safely buy software for it.

Btw, none of my other account info had been changed (address, etc). No changes except that the 13 apps had been bought.

Message was edited by: Brandy Evans

Apr 11, 2011 6:11 AM in response to Brandy Evans

Yeah, I'd planned on using Gift Cards as well, but it must be that they can just waltz in and gobble up any time used on them, so I may not even bother with that.

It's a shame that Apple won't A: acknowledge there's a problem (but who can blame them really... "Hey, just FYI people can steal from you and take all your store credit and we can't do anything. Our bad.") and B: close whatever security breach. They have GOT to know about this. Canned e-mails reminding us to change our passwords are just insulting.

Apr 11, 2011 8:08 AM in response to stereocourier

I have just been compromised as well (Purchases made on April 10th). The remaining balance of my daughters gift card is now gone. All the purchases were for applications in foreign languages I don't speak. All from the same Seller.

宝宝胎教音乐课堂, v1.0, Seller: Yang Yun (4+)
宝宝轻松睡眠摇篮曲, v1.0, Seller: Yang Yun (4+)
中国历史文化故事集【有声读物】, v1.0, Seller: Yang Yun (4+)
妈妈讲故事-宝宝学成语, v1.0, Seller: Yang Yun (4+)
唐诗宋词【有声书】, v1.0, Seller: Yang Yun (4+)
中外童话故事【有声书】, v1.0, Seller: Yang Yun (4+)
宝宝学说话--边听边学, v1.0, Seller: Yang Yun (4+)

I have reported these as problems but I am concerned that in the drop down list there is no option to choose that these purchases were not made by myself.

iTunes store account hacked

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.