You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:43 PM

Reply
1,958 replies

Jun 25, 2011 3:08 AM in response to UnbrknCh8n

Another victim here:


£65 credited yesterday in gift vouchers gone by this morning courtesy of Kingdom Conquest.


I've emailed Apple after being told they offer no telephone support for iTunes.


My credit card was also removed from file.


Apologies if its already been covered in this thread but has anyone had any further problems ie Credit Card fraud?


Cheers

Jun 25, 2011 12:25 PM in response to TheScotty

Apologies if its already been covered in this thread but has anyone had any further problems ie Credit Card fraud?


Cheers

Hi Scotty;


I havent seen any issues on my iTunes ripoff outside of iTunes... which makes me think they are limited only to accessing your account and limited to purchases inside iTunes only, and without having to know your CC specifics. If they have access that bypasses my extreme password and user questions, then it doesnt matter if they can see or not see the CC info Apple weakly lets them have access to, does it? All the charges will be made to the account holder and they can turn around and resell the credits or game app to whoever....


This is such a deeply inside job Apple is powerless to do anything about it and I see no admission of a problem from them, nor do I see any changes over the years for this ongoing problem, Im convinced. Until Apple makes the EULA more balanced (IE: where Apple commits to my personal security, data safety and takes on some form of accountability) then I will not be trusting Apple, its 'cloud', or accounting mechanism to any degree ever again.


As it stands they give you 'one credit only' for any rip off that Apple is responsible for letting happen, then you are on your own for any future ripoffs, and will not get any reimbursement. iTunes has proven to be so easily abused in this thread that I will not trust Apple as a company with my personal security. The only 'good' thing about the payment options in my personal account is the 'None' selection, which keeps no payment information in my account.


It doesnt seem to matter if its CC info, gift cards, paypal linked or any particular kind of payment method, they have control of the mechanism that bills you, not particularly the specific info to bilk you outside of iTunes....


I seriously believe the iTunes mechanism that allows purchases is weak and faulty to allow this or everyone around the world would be seeing fraudulent purchases for goods to be sold out of the backs of trucks and what not.


If they did use the CC info outside of iTunes though, they would expose themselves down to the very city the crime is originating from and make it very easy for arrest or investigation. Clearly they know this and are happy with the nickel and dime approach, when Apple isnt doing a thing to stop the crime from happening.


They have thought this out quite well; a very organized crime approach. Regardless, there are other companies out there who have a non-faulty billing and accounting mechanism that I trust more than Apple's weak wristed version, and I plan to use them for my music. App wise, I only pop in my CC info the moment I need something and remove it the moment the purchase has been confirmed... I see no other way.


I havent had the interest to use my CC info in that manner, yet, however....

Jun 25, 2011 2:54 PM in response to stereocourier

I had my iTunes account locked within the last 24hrs. I had no credit balance anymore but have put a credit card back on. I felt safe doing that since it seemed that there's been no charges to anyone's credit card (unless they were through Paypal).


There were no purchases on my account, it was just locked. Nothing had been changed, my address, phone number, and credit card were all there. Not really sure if it was just a failed attempt to access my account that locked it down or a party got access to my account then locked it.

Jun 25, 2011 4:18 PM in response to stereocourier

Add another one to the list. My account was accessed without my knowledge today and someone bought a bunch of in-app purchases in Chinese apps, and, of course, the infamous Kingdom Conquest was purchased as well. Thankfully, I had no credit card information stored on my account, but I had around $30 in balance from gift cards. This is all gone now, I have only less than a dollar left to use. I've contacted Apple and I'm still waiting for a response. However, seeing here that more people have been having issues like mine (and with Kingdom Quest) I find it very obvious that there is something wrong. I've also noticed that there are 0 computers authorized with my account, and I was pretty sure that before all this there were about 4 computers authorized to play iTunes protected content. Weird.


Wish Apple can solve this, because we are more and more dependant on iTunes everyday, and with iCloud coming soon we'll have more and more personal info with them.

Jun 25, 2011 10:11 PM in response to stereocourier

Add me to the list. Someone deleted my CC info from the account. (and yes this was shortly after a $50 gift card had been added) Then spent the remaining cash on my gift card on 2 free and 2 in app purchases to some GAMELIVE chinese app for $27. I have emailed apple and changed my info.


My question to people here is this.


Has anyone seen any unauthorized charges to a credit card? Because if so I will be calling Mastercard tomorrow and ordering a new card.

Jun 25, 2011 10:39 PM in response to mamabear slc

@mamabear slc. Are you saying that someone used YOUR credit card when they hacked into your account? or that someone hacked your account and used their own?


If they used YOUR credit card then it would seem that someone hacked into your itunes account and used your existing account information to make purchases.


The majority of us here seem to be having a problem when using gift cards though. I had a credit card attached to my account but I was given a Gift Card for Fathers Day. So after I used the gift card is when someone hijacked the account... DELETED my existing CC info (which thus far has no unauthorized charges) and then proceeded to use up my gift card.

Jun 26, 2011 6:40 AM in response to stereocourier

Looks like a glut of hacks. Two days ago I got word that my iTunes account credit card information had been changed. Imagine my surprise. When I logged in, my balance went immediately from $35+ to almost nothing and my credit card information was gone. They yesterday, I got a receipt for $34 worth in in-app purchases from Kingdom Conquest.


Hey, Apple! How about some public acknowledgement about the problem and reimbursement? Who do I call/email?

Jun 26, 2011 8:19 AM in response to edawgfromMD

It's alarming that so many of us have been caught like this and yet still Apple are doing little to stop it happening, it's all very well refunding but really we just want the rogue apps stopped. I've just posted on the BBC Click Facebook page about this, maybe some more high profile publicity will provoke better action by Apple (and even perhaps an improvement in their Ts & Cs). This is the link to their page if anybody else would like to add comment: http://www.facebook.com/group.php?gid=4287320286 but you will probably need to "join" the page to see the thread.


I have also posted a similar thing on the iTunes UK Facebook page. Lo and behold it was deleted almost immediately.


It's time for us to agitate!

Jun 26, 2011 10:28 AM in response to Brad Schurman

Some very fine points there Brad and I agree entirely with what you have said.


From now on, or until I am confident Apple has addressed the issue, I will be keeping my credit card well away from iTunes.


Apple's lack of acknowledgement of any problem will save them embarrassment from the wider public who will remain unaware but will only infuriate further those who have been victims of this breach of security. It is a dangerous game to play as they may end up alienating many loyal customers the further this escalates, by the time they acknowledge a problem it may be too late.


One further thing that is currently frustrating me is that despite 'reporting a problem' over 32 hours ago I have yet to hear from anyone from Apple. A serious breach of my personal financial information held on their servers and they haven't yet responded to ensure me it will be resolved and not to worry. I would of course have preferred to report this to a person on the phone but I was told that Apple do not offer telephone support for iTunes.

Jun 26, 2011 3:14 PM in response to TBF99

I finally received a reply from Apple.


They will refund the lost funds within 5 days.


My account has been disabled and I have to email them more personal information (full address and last legitimate iTunes purchase) and they will look into the possibility of reopening it.


No admission of a problem


No reassurances that iTunes is a safe platform.


They effectively placed responsibility with me and urged me to improve my password and account security.


I have other unrelated issues with Apple at the moment (mainly related to MobileMe and iCloud) but this is the culmination in a change of attitude for me toward what I once thought was a thoroughly innovative and responsible company.

Jun 27, 2011 5:49 AM in response to TheScotty

My account got hacked on the 25th. Someone downloaded Kingdom Conquest and used $49.71 leaving me with $0.69.

I contacted Apple and a representative told me that they would credit my account, as well as make my account inactive until I supplied some personal information. Once this info was supplied they would email me informing me that my account was now active. They also suggested that I change my password.

I did all of the above.

I am still awaiting an email saying my account has been reactivated, however, I have gotten an email informing me that my account has been used to download Kingdom Conquest AGAIN twice on the 26th!!! Once for $8.99 and again for$2.99.


So it certainly appears that APPLE HAS A PROBLEM!!!

I hope they get this sorted out quickly, I'm also glad they do not have any credit card info, as I only use gift cards.

iTunes store account hacked

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.