You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:43 PM

Reply
1,958 replies

Jun 14, 2011 4:45 AM in response to Baba

Baba, there are actually a lot of really funny gospel songs like Tammy Wynette's "I'd Like To See Jesus On The Midnight Special" which you might enjoy, atheist to atheist. Wanda Jackson's "Jesus Put A Yodel In My Soul" also comes to mind.


In any case, to update you all on my situation:


After a week of emailing them, I finally got a response and had my 74.01 in gift cards restored. I have yet to log back in to my account and did mention in one of my emails back to the tech who wrote to me my concerns about having my account hacked twice and not being refunded if it happened again and was told to get anti-piracy software and when I asked about suggestions for that was told they were not allowed to rec any non-Apple programs. For all I know, my money could already have been ganked again. I can't come up with 74 bucks worth of songs I want to buy at once so have not bothered dealing with getting into my account again.


I've been dealing with other brand new iTunes problems like the app refusing to burn anything for the first time ever (Mac user since '87), crashing as soon as I hit BURN DISC and having my posts on that subject erased by the mods -- THEY ARE LISTENING!!! JUST NOT HELPING WITH ANYTHING!!!!!! --


I'm very glad this problem with THOUSANDS OF HACKED ACCOUNTS has gotten so much press in the past week and can only hope it gets more press before more unwitting victims put in their credit card info online for iCLOUD and wind up being evicted because their checks bounce while ten year olds in China gamble with their rent money.


It's clear from just the posts in this thread, nevermind all the rest of the discussion on this topic all over the web, that an official statement from Apple and a sturdy policy line on refunds when a client has obviously been stolen from (hello KamaGames!) would go a long way to clearing up any confusion on the matter.


<Edited by Host>

Jun 13, 2011 5:41 AM in response to Kevin Ballestrini

Kevin to be honest I doubt it was a brute force hack. These days due to auto locking and other security features there is almost no way to be able to determine a password from a brute force attack. You may find that you're hacking was unique and you may have been key logged which would explain the reason that you kept getting get logged out as there may have been missing letters which the hacker may have to determined

Jun 13, 2011 5:56 AM in response to freddiegrover

I kind of wonder about brute force though (at least after the initial hack). My account was restored to me a few days after I reported my hacking to apple. I changed my password and logged in to make certain that everything was correct with my account (which it was). Then I logged off and didn't try to access my account for several days. The next time I logged on to my account I had a message from Apple that stated that my account was locked because too many access attempts had been made.

Jun 13, 2011 1:30 PM in response to zerg1234

@zerg1234--


My email should be on my profile -- I would love to chat with you at greater length about your experience here with APple and iTunes (and anyone else who sees this as well). I'm a reporter writing this up and the sense I am getting is that while Apple is good about compensating people a preventative measure of some kind would be appreciated. But someone tell me if I am reading this wrong.

Jun 14, 2011 3:30 AM in response to zerg1234

I don't think I did anything to get my iTunes account drained. I believe it's something on their end that got compromised.


My password was one of those "non character repeating, number, upper case, lower case, and special character", kind of passwords. The only time I ever use my iTunes password, is when I make a purchase in either iTunes, my IPhone or iPad.


If someone has the brains or resources to not only replicate iTunes or an Apple iOS App, AND trick Apple into sending me what I bought, well then I guess they deserve some praise.


But again, ultimately, I believe the blame is on Apples side of the connection, not mine.

Jun 15, 2011 9:55 AM in response to stereocourier

I just had the same thing !!!! Couldnt get email from my account off my iPhone, so logged on to the account from my work computer and got the error that my account was locked due to too many tries to access...I got a hold of Apple help in chat but she didnt say anything to me about this or to change my password...


Then I got up the next morning and BAM - Kingdom Conquest (5 times) were purchased (but not downloaded) and all my store credit gone...I did notice my credit card info was delete and i kept it that way...


So what is going on -- is it just iTunes being hacked into or is it our apple accounts?

Jun 15, 2011 10:58 AM in response to kitten4444

Looks like I'm in the same boat. Got notice this AM about some purchases on my iTunes account from Paypal, with no info as to what they were. So I logged into iTunes and found several in-app purchases for Kingdoms at war. Totaling around $120. I changed my password and called Apple.


The rep I spoke with couldn't help me, but offered to report the incident to the iTunes support folks, and I got a confirmation email from them shortly after.


I also filed a dispute with Paypal. Hopefully I'll be refunded without too much hassle.


This whole incident is rather disturbing...

Jun 16, 2011 6:00 PM in response to stereocourier

Well you can add me to the list of people who had their account hacked. I have no idea exactly how my account got hacked, but here I am. Though I am a bit more fortunate that most of the people here, and so far they have only purchased a single application, but they may have gotten my CC info. Reported to iTunes and my CC company, and hopefully this issue gets resolved quickly.


Is this a tie in to all the other places being hacked recently, or a completely different group of hackers?

Jun 16, 2011 8:57 PM in response to stereocourier

twice in 2 days for me!

Kingdom Conquest cleaned out my account 2 days ago...got an email from Apple this morning saying they had refunded me, then a few hours later got another receipt from KC saying it had cleaned out my account AGAIN!


I hadn't even logged back in after the refund....but had changed my password after the inital attack.

So whatever it is, is NOT using a password to get in...must be some backdoor/inside Apple issue.


Awaiting to see if I will be refunded again.

Jun 16, 2011 11:25 PM in response to TheGuyintheProjectionBooth

Thats because you arent ALLOWED to see it when you set up the account the first time: it isnt shown.


I just set up my niece on a new iPad she got for graduating... told her right off the bat to never give Apple CC info and DO NOT use the gift card I bought her for xmas until she had nearly the total amount of songs/apps/software in a wishlist in iTunes... and once she got that figure then only then to buy with the gift card or it will be stolen.


It is not a matter of IF but WHEN you will get ripped off, for anyone using iTunes... its multiple rip offs each day by the recording of this thread alone.


But back to the NONE button: you cannot have an iTunes account without first giving Apple your CC info.


I hate that fact.


But atleast what you can do when setting up a new account or one for your loved ones you can give a (has to be valid, it is checked before your account is activated) CC card and then IMMEDIATELY go back into your profile specs and then you see the NONE button.


I deleted the CC info and chose NONE, logged out, logged back in to make sure there was no CC info and that NONE was still selected, and have been ok ever since.


Whatever freaking lousy pretend EULA that Apple wants to push in my face now that apparently waives all responsibility of them for anything that goes wrong with my account or credit line if I get hacked again, they can go stuff themselves with it as I will not be paying for any song or app and not be giving them the data to allow the hackers to freely use.


If I 'cant live without that song' I will do the "CC data in, purchase, confirmation slip, remove CC data right away again" routine. Apple will have no recourse and no excuse then; and they also wont be giving me the 'you were hacked once, we dont refund for hacks more than once" excuse.


the stinking hackers can use their own CC info if they want to so easily and brazenly use my account to do something ********.

Jun 17, 2011 6:07 AM in response to stereocourier

OK! This is a big deal. I was a little naive in thinking that it was an isolated incident a year or so ago, but I have switched off the CC info button on my account page. I just went to my 'Purchased' section of iTunes and found that I have a Christian music thief (ironic or oxymoron) hacking my account. I have no idea who these artists are. The hacker must have gotten in when I had a PayPal account set up for a very short time about 4 months ago. I decided to go back to a CC for simplicity. I am going to try and retrieve the info from that period. It is creepy.

Jun 17, 2011 6:53 AM in response to donikatz

Got an email from Apple the other day that they'll be refunding me the stolen credit in 5-7 business days. But they disabled my account pending an "investigation" that "could take several days". So now I'm locked out of my iTunes account and can't even download updates to things I've already purchased!


What the heck, Apple? Not only is your security garbage, but the customer is the one who gets penalized?? I already changed my password, why would you need to lock my account? Any investigation shouldn't need my account to be locked out. I am furious!


I've been strongly considering switching to Android, yet been reluctant because of all the iApps I'd already bought for my iPhone. But I guess now there's nothing holding me back. Goodbye, Apple.

iTunes store account hacked

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.