You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

📰 Newsroom Update

Billie Eilish is Apple Music’s Artist of the Year for 2024. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:43 PM

Reply
1,958 replies

Apr 11, 2011 8:12 AM in response to Brandy Evans

I agree, I wouldn't leave gift cards or my credit card number on my account while all of this is going on. At this point, I'll only redeem a gift card if I intend to spend the entire balance immediately, and I'm telling anyone who has bought me an iTunes gift card in the past not to get me another one.

What I've been doing since this happened is putting my credit card number on my account when I want to buy something, and then immediately removing it afterward. I go into my account (which you can do on your device by using "Account" button on the bottom of the "Featured/New" screen in the app store on the iPhone at least -- a horrible, unintuitive place to put it, if you ask me), put in my credit card info, make my purchase, and then go back into my account and change my credit card back to "None" immediately afterward. It's a huge pain, but it keeps my potential exposure to these issues as minimal as possible.

It's also had the side benefit of cutting down on my random app purchases -- I have to really want the app for it to be worth going to all of that effort. So it's actually saved me some money. Of course, on the same token, it's also cut into Apple's profit margin from me, as I've been buying less because of it. Their loss if they won't address the issue.

Apr 11, 2011 12:42 PM in response to stereocourier

Hacked here as well last night apparently. I had a $10 gift card in my account. Logged on today to download any podcasts that I subscribe to and found my balance was now $0.01. They bought some kind of platinum currency for an MMO app. The hacker did the same thing... changed my city, state, ZIP and phone to... Towson, MD 2????, 654-6543210 and just noticed that my credit card info is wiped clean.

How can this not yet be exposed in the media since it seems to be frequently happening? iTunes security is a mess.

Apr 12, 2011 8:31 AM in response to StoneyPA

My iTunes account was hacked yesterday. They removed my credit card info and used $7 of my $10 remaining on my gift card. Contacted iTunes yesterday. I will immediately spend the remainder of my $10 and not purchase anything on iTunes again. It's a good thing I have an android phone, but with all my Macs and iPods and iPad, there's no way I cannot have iTunes account.

Message was edited by: dwd3885

Apr 12, 2011 4:07 PM in response to StoneyPA

It took the apple representative (via email back and forth) at least 4 days after I contacted APPLECARE to reset my account. If you are near an Apple Store, or Apple Genius bar at the closest best buy, you might want to call them. Here in Anchorage Alaska, there is a Apple paid employee working out of the local
Best Buy and he might be able to walk your situation thru to completion. I know that if I had been delayed by another day to fix Apple ID account, I was going to go back to the AT&T store where I purchased my iphone4 and get them involved. Please post when your account is reset and you can access the app store.
After my Apple ID account was reset and I was able to download apps on both my laptop and iphone, I changed my password and then ran out and purchased a 15 dollar itunes gift card and hung it out on my itunes account to see if I am able to bait the hackers into trying to do that again. So far, its been a few months and no hackers have taken it. I make sure that account doesnt have any PayPal or VISA CC information on it. I used to check my itunes account daily.. but now.. its every other day.

Apr 12, 2011 4:42 PM in response to stereocourier

I can add my name to the list. $10 credit in my account gone. Address reset to Towson, MD, CC info erased. 2 machines authorized for my account. I changed my password, but I dont think they are getting in that way. There is some other major security flaw and Apple isnt talking about it because they cant fix it yet, thats my guess. With all these refunds that Apple is having to issue, you'd think this would be a top priority and perhaps it is. They just dont talk about it because they cant stop it and it would hurt business.

It kinda ticks me off that there is no number to call to resolve this more quickly. You have to email and wait. You'd think with the BILLIONS of $$$$ Apple brings in, they could have a phone contact for issues like this.

Apr 13, 2011 10:49 AM in response to ybenner

This is utterly ridiculous how we're being blatantly victimized by an internal and/or external thief PLUS being looked down upon and having everything dragged out by this company. I work as a pharmacist in a retail setting and would be fired ASAP for such terrible and demeaning service. In any case, this is my first experience with Apple's support, so to at least put a positive spin on something, they have nowhere to go but up?

Apr 13, 2011 10:55 AM in response to trailbossc

trailbossc wrote:
Well here we are. 15 pages deep of people being hacked and not a single response or post by an Apple employee, even though some of the techs claim to be aware of this thread in their responses to restore your account. Do they care?


This forum is for user-to-user technical support. It's not Apple Customer Support. That's clearly stated in the TOU to which you agreed when you registered. Apple will not respond here. You need to use the Contact Us link that you'll find at the bottom right corner of every page.

Best of luck.

Apr 13, 2011 11:00 PM in response to stereocourier

This happened to me today. I reported the incident to support and received an email saying that my account has been credited but also disabled. In order to enable it, I have to respond to the email with the following:

1) The billing address listed on the account, and

2) One of the following:

- the last four digits of the payment card used for your iTunes Store account
- the order number of your most recent purchase
- the name of any item you've purchased using this account

Is this really the protocol for these incidents? I have yet to respond to the email because I find it silly to ask for information readily available to anyone with current access to your account. None of this information is hidden. Please tell me I'm just being paranoid...

Apr 14, 2011 6:39 PM in response to StoneyPA

stoneypa,

I've had to verify that information TWICE. The second time was silly because the info was already in the body of the email from the first time they asked me this. Then I get this email
+My name is X and I am a senior advisor for the iTunes Store team. I am currently working toward a resolution for the issue you have reported. I recognize that this has been a particularly frustrating experience. You will receive an email after the matter has been investigated and further information is available. I will endeavor to ensure it is resolved as swiftly as I can.+

+Thank you for your patience. Apple wants your iTunes experience to be as enjoyable as possible.+

Sincerely,

X
+ iTunes Store Senior Advisor+

I don't know why this is taking so long.

Message was edited by: ybenner

iTunes store account hacked

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.