You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

📰 Newsroom Update

Billie Eilish is Apple Music’s Artist of the Year for 2024. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:43 PM

Reply
1,958 replies

Mar 26, 2011 9:54 AM in response to ybenner

I got hit as well. Two $40 gift cards. I removed my CC info, contacted PayPal, called my bank and put a stop payment on them and didn't actually lose any money. It's very aggravating and I'm appalled at the lack of customer service. Apple won't even acknowledge that it's a problem.

+"Dear Michael,+

+I can totally relate your frustration, however kindly note that we will not be able to locate the particular account from which the purchases were made.+

+If you need further assistance regarding this issue, please contact your legal advisor, who may contact Apple's litigation department http://www.apple.com/legal/contacts.html on your behalf.+

+I also understand that you are concerned about the safety of your personal information in regards to the iTunes Store and the App Store. Your privacy is very important to Apple and we take numerous precautions to safeguard your personal information against loss, theft, and misuse, as well as unauthorized access, disclosure, alteration, and destruction.+

+The following page outlines, in detail, how Apple protects your information:+

+Apple Privacy Policy+
+ http://www.apple.com/legal/privacy/+

+Michael, I hope this information helps you .If you feels that there is anything which I can help with this issue please feel free t write back as I will surely help you to resolve this issue as soon as possible with my available resources."+

Ridiculous.

Mar 28, 2011 6:38 AM in response to MichaelTLH

My latest e-mail — does it sound to anyone else like they are trying to blame ME for not having a strong password? The fun thing to keep in mind is that I have never asked how to set my password, how to spend my gift cards (particularly insulting) or anything about password security. I hope they own up to this issue soon.

+Dear Michael,+

+Thank you for replying back and kindly note that you will be able to sign in to one iTunes store account to make purchases if you know the password. Without that we cannot sign in to one account.+

+Please make sure that you are not sharing you iTunes store password with anyone and please make sure that you are logging out from internet browsing centers appropriately as there are chances that someone can sign in to your account if it is not logged out properly.+

+The only method by which we can prevent the account is to keep the password as stronger as possible by following the rules given below:+

+The password must:+
+be 8 characters or longer+
+contain at least one numeral+
+contain at least one character+
+not contain three consecutive identical characters+
+not have been used in the past year+
+not be the same as your account name.+

+These rules will make you to set a strong password.+

+The link which you have provieded :+

+ http://discussions.apple.com/thread.jspa?threadID=2620166&tstart=31+

+Tells us regarding which is the primary payment method. It wont tell you why the amount as charged to your credit card. Kindly note that gift cards and gift certificates cannot be purchased using gift cards.+

+As you have already reported this to your bank, they need to sent us the chargeback and then only you will get the charges reversed after investigation.+

+Once again I would request you to realize the way by which we can protect our accounts appropriately by not revealing password to anyone and by signing out regularly from any system or devices from which we re accessing iTunes store.+

+Thank you for your understanding. Have a nice day!+



Sincerely,

Rakesh
+iTunes Store Customer Support+

+Please Note: I work from Saturday to Thursday 11.00 AM to 8.00 PM CST.+

+Thank you for allowing me an opportunity to assist you. You may receive an Apple care survey email; any feedback you provide would be greatly appreciated.+

Apr 22, 2011 6:42 PM in response to lopes22

Hey, FINALLY got my account back after a mere 11+ days of waiting!!! What terrific service! Still haven't seen the credit back to my account, but surely won't hold my breath. Absolutely will not enter credit card info any longer and will only use gift card if use it ENTIRELY & IMMEDIATELY upon entering it. Security is beyond lax and support doesn't seem to care about it.


Lopes --- You can send daily e-mails to Account Security on this support page:


http://www.apple.com/support/itunes/


You couldn't find info on iTunes support because it's an oxymoron...

Apr 22, 2011 7:34 PM in response to stereocourier

Lopes - go to http://www.apple.com/support/itunes/, iTunes Store account and Billing, then Billing Inquiries, click on the email tab and give them all the info like dates, things you didn't order, and the order number. They buried the email so it's hard to get to the specific area you need to get to. They should get back to you within 24 hours. Ask them to deauthorize the computers, then you can add them back in after you unlock your account. If you didn't notice, there will be one more authorized computer than you had before!


The cc charge you didn't make needs to be disputed through your bank.

Apr 27, 2011 6:51 AM in response to stereocourier

Hi guys...the same thing happened to me as well.. just yesterday i got an email saying that i had spent like $33.97 on some funny game called KINGDOM CONQUEST http://itunes.apple.com/us/app/kingdomconquest/id384877854?mt=8


This is quite a horrendous experience... i had assumed that ITunes was supersecure! By comparison, i have been shopping on AMAZON for over 6 years and i am yet to face any such issue.


Now who do i email about this? Before they clear out the US$50 or so i have left!!

May 20, 2011 11:21 AM in response to stereocourier

I have also been hacked. I orignally thought that I had accidentally made an in app purchase, but after investigating further I have discovered that this has happend to other people.


帝國 Online, 23400銀幣禮包, Seller: GAMEISLIVE CORPORATION LIMITED
User uploaded file Report a Problem


$21.24 of my gift card credits are now gone and my credit card information has been taken off of my account. Does anyone know if my credit card is now compromised because of this? I've sent an e-mail to iTunes support is there any chance I will be reimbursed?

Jun 21, 2011 10:03 PM in response to Cincytom

Here is the odd part, my cc was removed also. apple gave me a pretty crap response. Keep in mind the first response was overly confusing they sent me as I posted earlier in the thread. I asked them "who removed my cc? should i cancel my cc? .. What exactly happened? I did not remove the cc myself and this kind of worries me"


Here comes this odd response.


Brian, i apologize if I was wrong, let me correct it we have not disabled your credit card.


I'm sorry that I can't be of further assistance with your request, but the iTunes Store does not provide any account information—including account activity and personal information—without a subpoena. We do this for your protection.


You may access certain account information by signing in to the iTunes Store and choosing View My Account from the Store menu at the top. You will need to log in with your Apple ID and password. If you no longer have the password, click the button that says "Forgot Password?"


If you need further assistance regarding this issue, please contact your legal advisor, who may contact Apple's litigation department http://www.apple.com/legal/contacts.html on your behalf.


I value your time and patience and I regret for all the inconvenience caused.




Lemmie get this right, I need a subpoena for them to do what? They do have account access as they can see my cc was removed and everything else. Only difference in their system is I doubt they can see peoples whole cc's besides a very small department.



This is all too odd.

Jun 30, 2011 1:21 AM in response to stereocourier

Hello everyone,

Sadly, I have to add to the list. I awoke this morning with three e-mails from Apple.

1)

Hello,


The following information for your Apple ID XXXXXXX was updated on 29/06/2011:


Credit card
If these changes were made in error, or if you believe an unauthorised person accessed your account, please reset your account password immediately by going to iforgot.apple.com.


To review and update your security settings, sign in to appleid.apple.com.


This is an automated message. Please do not reply to this email. If you need additional help, please visit Apple Support.


Thanks,

Apple Customer Support


2) & 3)

Dear XXXXXXXX,


Your Apple ID, XXXXXXXXXX, was just used to purchase 帝國 Online from the App Store on a computer or device that had not previously been associated with that Apple ID.


If you made this purchase, you can disregard this email. This email was sent as a safeguard designed to protect you against unauthorised purchases.


If you did not make this purchase, we recommend that you go toiforgot.apple.com to change your password, then see Apple ID: Tips for protecting the security of your account for further assistance.


Regards,

Apple


I know that I have not responded to any phishing e-mails or could have compromised my account in any other way. This must have been a direct hack on the iTunes Store. My credit card details were deleted and $23.99 was stolen to make this in-app purchase. Of course, I have immediately changed my password and e-mailed Apple - not easy to find out how to do this - except thanks to this thread. I phoned Apple Australia but they were powerless to help. Thankfully, no credit card transactions have resulted. I await a reply from Apple.


This is a very worrying situation. I am already unhappy with Apple over dropping some vital features as a result of closing MobileMe, so now will stop being an Apple evangelist....at least until they start looking after their faithful customers better! Let you know if I get my credit back!

Jul 16, 2011 5:41 PM in response to stereocourier

$40+ hacked from my account for the KingdomConquest App.

Had everything put back after apple reset my account.

Apple support said the best thing I could do to bring this problem to greater attention at apple is to submit the feedback form and pass on the link to others with the same problem. Here's the information I was given:


Please know that Apple takes the feedback from our customers very seriously. This is the reason for our feedback page - to create a forum where our users can vent, praise or share whatever feelings they have to allow us to meet your needs, and grow as a company.


I took the liberty of submitting your feedback to Apple on your behalf. I would also encourage you to share this link with all of your friends and family who wish to submit the feedback, and have them all submit the same request.


Here is the link for you.


HYPERLINK "http://www.apple.com/feedback/itunesapp.html"


I know sometimes it feels as though submitting feedback will not yield results, so I will also invite you to check out the following link. This is a letter from Apple's CEO addressing customers who purchased an iPhone very early on at $599, then the price went down to $399 shortly after. Mr. Jobs heard our customers and Apple responded accordingly.


HYPERLINK "http://www.apple.com/hotnews/openiphoneletter/"


I hope that you will consider sharing your thoughts on the feedback page.

Jul 31, 2011 7:15 AM in response to stereocourier

This is a privacy issue - personal information data security breach.


I have experienced the same as what a lot of people are stating here - unauthorized purchase on a non-shared account, taking great caution to secure my system and be careful.


In addition to the feedback form that is mentioned here several times, ensure that you write to Apple's privacy team.http://www.apple.com/privacy/contact/


Who knows if they will do anything about it, however this is a personal information privacy issue - if someone was able to make the purchase, they were also able to gain access to your personal information that you provided to Apple.

Aug 6, 2011 6:39 AM in response to stereocourier

It's getting worse, not better. I received this reply from Apple. The problem is, I'm not Josh. EVERYONE, please contact Apple iTunes AND security about this problem. Just because you get your $10 back isn't going to help solve this problem. Here are the links. DO IT!


iTunes

Security


Dear Josh,


Welcome to Apple iTunes Store Customer Support! My name is Raj and I am glad to assist you.


I understand that you are concerned about the purchases made with your iTunes Store account, "xxxxxxxx@yahoo.com" without your permission or knowledge.


I can certainly see how disappointing this could be. Please accept any apologies for any inconvenience you've experienced, as I know how concerning it can be to deal with such issues. customer reporting unauthorized charges.


It appears that your account has already been disabled to avoid further charges. Please note that you can enable your iTunes Store account in the future by providing specific information to iTunes Store support, as described at the end of this email.


I also understand that you are concerned about the safety of your personal information in regards to the iTunes Store and the App Store. Your privacy is very important to Apple and we take numerous precautions to safeguard your personal information against loss, theft, and misuse, as well as unauthorized access, disclosure, alteration, and destruction.

Aug 8, 2011 2:01 AM in response to Robert Mungo

Lakoo - Apple are you listening? Look into this dev. please!!!


I was just burned on the weekend, the rapid succession of emails (4-5am) about my account details changing, then purchases made from a device not previously authorized. My CC information has been removed from my account, nothing else was altered.


My $30 iTunes voucher cleaned out, am now down to $0.07. What's annoying is the fact that when i read the reviews of the app in question, there are about 5 that state the very same issue. Hacked accounts and false charges! If this happens multiple times for the ONE app, then why isn't something done by Apple?

http://itunes.apple.com/au/app/id371613788?mt=8


This is the 2nd time i've been burned by hackers, 2009 and now 2011. Same issue as last time, account details changed and apps purchased totaling $72. 15 emails from Apple, full of "i understand your concern..." etc. Talk to me like a HUMAN, not a robot. Same e-mail 15 times over, same response with a minor change in content. Took 3 months to have my charges reversed after getting my bank involved with Apple security, SUCH a hassle.


The annoying thing is, the emails from Apple make out as if WE are the ones in the wrong and don't really take the time to understand our concerns. Am i sure i didnt change my login? Am i sure i didnt make the purchases?...of course im sure! I dont spent $72 on apps just released with NO reviews, NO ratings, both games by same developer...join the dots Apple. Good to see those two apps dont exist anymore 'iCool' and 'iFruitShow'.
"The iTunes Store cannot reverse the charges." This was a 2009 email so no idea what the current stance is, but how easy of Apple to wipe their hands clean of any issues when they arrise.


I ditched Apple in 2009 because of this, refused to have my CC on file with them. Now its reared its ugly head again and i refuse to put my CC back on file AGAIN.

iTunes store account hacked

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.