You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:43 PM

Reply
1,958 replies

Aug 3, 2011 10:19 AM in response to henrique1605us

My situation is a little different. Three APL itunes charges showed up on my credit card account that I did not recognize. There were large amounts like $100, $50 and $20. However, when I check my iTunes account, they only showed one charge in the last month, which I recognized ($1.98). So, it looks like someone used my credit card, but not my iTunes account.


I canceled the credit card and changed the password for iTunes. I tried to call iTunes but was referred to the website and hung up on.


My wife had a similar thing happen a month ago.


Maybe the solution is to only use gift cards wtih iTunes. Just buy a gift card when you want to purchase something.

Aug 3, 2011 9:02 PM in response to machunter123

Got a email back from apple today, i was refunded all the money that was taken. Apple did disable my account had to reenable it,which ment i had to change my password once more, but I am glad that they fixed my problem very fast. I still wish that they would get to the bottom of the problem so that it won't happen again but I was pleause with apple customer service.

Aug 4, 2011 5:39 PM in response to Arvin Bhatnagar

My account was hacked in the spring and I haven't had occasion to use it since then. Was told everything was restored and that my money had been returned. Just tried to buy an album only to discover my account has been disabled. Sent them an email asking how I rescue the funds on my balance. Waiting for a reply. This is pitiful for a multinational.

Aug 4, 2011 7:03 PM in response to stereocourier

I was hacked on 7/3 (yesterday) and they hit me for $49.99 buying some in-ap thing. Looked like some asian stuff they were downloading. I've emailed and called, awaiting feedback. I seldom use the account, but it was also a gift card they cleaned out. Checked my firewall and zone alarm for traffic, scanned the computer, can't find anything. My account had 3 devices authorized, but I've only ever authorized 1. I deauthorized everything, changed my pw, reauthorized the 1 device I used, and contacted Apple.


With all these complaints on the internet about this same thing, kinda has me worried now...


Dave

Aug 4, 2011 9:07 PM in response to lorifromharrisburg

"Here's what I don't understand, how some consumer/pc watchdog or competitor group hasn't gotten their claws into this yet? Itunes was hacked, gift card on file was drained, Apple was very responsive to refund, but there has to be something internal somewhere leaving consumers vulnerable...needs to be addressed and is prime pickings for the competition isn't it? "


No idea...its more glamorous to report how china is infiltrating the FBI servers, the UN ones, the Canadian govt. and stealing trade competiton secrets from various international companies instead? Or how chinese greedy pigs and govt. corrupt officials are supporting efforts of intentional hacking and building hacker colleges? or how a remote wierd named chinese city has five copy cat, illegal, unauthorized Apple stores, and how ikea stores were also copycatted so exactly they fooled their staffers into believing it was legit, too? Seems china just cant help but do illegal and immoral things in most any sector... from poisonous recalled brand named 'fake' toothpaste that sickens ppl. years ago to crud like what they continue to pull today. And by all means do no media companies or big buyers of chinese parts ever dare stand up against such practices; wouldnt want to 'offend' them or raise the ire of such honorable 'practices'.


There are limbwristed reports on youtube that show up every now and then about the iTunes hacking; inaccurate ineffective 'solutions' like use a credit limited CC card or gift card, as if they didnt have the brains to see those were being abused too.


There was a Global Edmonton tv interview I was asked to be a part of on July 18 by a "Troubleshooter" reporter which amounted to absolutely nothing new or helpful; the 'security company hacker' they quoted blamed me/iTunes users for having unknowingly installed some malware or having wide open firewalls...said on camera hes "seen it all before", essentially. So the so called 'expert IT and security" rejtards out there are blatantly feeding misinformation and furthering the lie one way or another, that Apple is not to blame. Years after the start and without any indepth look into the problem, the media doesnt care and choses ignorance... just interviewing the armchair 'experts' saying how they know its not Apple.


Ive been ignored by Macworld so much when trying to bring it up Im considering dropping subscription... no printed email or letter of mine or response from any direct questioning... never tried Macrumors... macintouch I tried... again traction isnt there...


Just bury h ead in the sand or tie a towel over your eyes.... if you cant see or hear it IT MUST not be actually happening.... right?

Aug 6, 2011 5:05 AM in response to kroeterich

I just wrote a complaint and after reading this forum, I see that I am not alone in this situation. I hope a solution will be found quickly because the trust in the system decreases.


I have reviewed the security of my computer with antivirus, antispyware, anti-rootkit and also the firewall and nothing abnormal. This tells me that the iTunes Store servers have indeed been hacked.


Sorry for my poor English but I speak French


Benoît

Aug 6, 2011 5:16 AM in response to stereocourier

Follow up - been credited, though the issue of Apple's system being compromised has not been addressed. They also accused me of "not remembering" the purchase, and told me I should lock down my Iphone (I don't have any Apple products, certainly not an Iphone - and after this experience I will certainly ensure not to.)


Instead of answering as a human, they're using scripted responses. It's too bad. I thought Apple was better than this. The representative said she spoke with a supervisor and couldn't determine what happened, and has not responded to any of my email since. Next step I guess is file a complaint with information privacy commissioner, the media and the better business bureau.


Thanks Apple for taking information security seriously. That's too bad. Before this I was considering an Iphone. Certainly not now.

Aug 6, 2011 9:00 AM in response to Baba

I am thankfully NOT being hacked at the moment, but SOMEONE, one of you who has, NEEDS TO TAKE THIS TO THE MEDIA. Fox would probably get the most exposure. And when you contact iTunes support, you should be providing the link to the this discussion. They won't understand the seriousness of this until you do because


1. Apple Support does not read the discussions

2. Different support agents get your reports. They aren't linking them just fixing YOUR problem.


And there is absolutely no excuse for an Apple agent to try to put the blame on the customers. I am so sorry this is happening to all of you.


Did any contact Towson, MD PD? Your own Police Dept? The scam happening here is breaks a TON of laws and this person or people should go to prison. Credit Card Theft, CC Fraud, Identity Theft & Fraud, etc. These people MUST be stopped and until Apple and the Media expose it, this will keep happening to people. The only way Apple will see the pattern is if victims show them this thread! Please, if this has happened to you, contact apple AGAIN but this time, tell them that they NEED TO READ THIS THREAD and then contact your local news station. This is a WORLDWIDE issue, not just the US but it all leads back to Towson, MD (which is probably fake info anyway).


Here's another question for those of you who were stolen from:


Did any of you use PUBLIC wifi (free wifi or paid)? There has GOT TO BE a link between all of you besides you having gift card credit in your accounts. There is no way to transfer credit to another account so it has to be something else, like wifi. Also, are you all on PC's? I'm asking because a lot of you are mentioning spyware, antivirus, etc. It could actually be happening from something you installed like a third party plug in for iTunes.

It could also be a SITE you all joined. The point is there IS something you ALL have in common. We just need to find out what it is. I don't know if there is anyting I can do to help, but I'm here if anyone needs it. 😉

Aug 6, 2011 9:39 AM in response to Sandy W

I agree that it needs Media attention.

I was taken for $43, Apple refunded me after about a week of back and forth.


But, you are wrong on one part. Apple DOES read these discussions.

I had a problem with my WiFi on my 27" iMac, still do but 98% of the time it works fine, I never contacted Apple just the discussions.

A Tech called me at home..... using my AppleID contact info, and E-mailed me as well. There were others that were contacted as well. We had to run a script to gather some info and forward that to them.


As for the rest of your question.


I have my AppleID input on 3 Mac's, an iPad and an iPhone. Not on any PC.

I do have one PC, but it's games only and doesn't even have iTunes installed on it.

I Run FireFox with NoScript, Ghostery and AdBlock. (If only NoScript for Safari would be released...) So it's not exactly trackers etc on my end. I Block anything Google, facebook, etc.


If you go back to my initial issue, I logged into my AppleID and changed my Password (using Safari) on my MBP which I had just burned it down and started fresh prepping for Lion. (I had no 3rd party stuff on it, wanted as smooth a transition as possible on the MBP) the new password was never input anywhere other than the MBP. 45 minutes later, password was again hacked to drain me of the $43. First time it was a free app, and I got the email saying an unathorized computer was used.. I changed the password before they could purchase anything with the gift card.


It's either Apple's website... iTunes itself, or an inside employee making money off selling iTunes account passwords to someone selling only those with a Gift Card balance. (apple is not immune to bad employee's) you say the address was changed to somewhere in MD, mine was set in California.


The only thing that everyone of us has in common... Gift Card balances. (why I suspect an insider, iTunes or Apple webiste)

They don't use our CC's. At leaset i haven't read of anyone getting their CC used..

I found that this issue has been going on since Nov of last year, you can search to see that it was reported on back then, but nothing came of it and nothing has changed.


The apple responce's are scripted, they probably have to follow the rules and send you the same scripted responce explaining that there could be multiple ways to get your password, and possibly it's the end user.


I don't join random website, I don't do social media (waste of time) I don't use my itunes email or that password i use for it anywhere else. I have 3 email's i regularly use. the one I use for itunes is pretty much the only thing it's used for anymore.. Apple wouldn't let me switch it to my MobileMe account, so it stays.

Aug 7, 2011 10:24 PM in response to stereocourier

My Daughter bought me a £25.00 gift voucher for my birthday which lifted my balance to £28.00, yesterday I recieved an email from Itunes notifying me of a account change (4am in the morning) two minutes later I had two emails confirming two purchases of £7.99 each. I noticed this at 7am and reported this as a problem but did not recieve confirmation until 11am. I now have just £10 left 😮


How can this happen? why did apple allow these two purchases two minutes after my account change without confirmation from myself that it was I that had changed the account??


I strongly suspect that I have been "hacked" and this is not an administration error, one of the purchases appears to be a Chinese music album.


I have searched for a telephone number to call regards a fraudulant activity but is seems apple do not have one.


It seems that this problem is widespread and has been going on for years, why has this not been publisised???


What is more frustrating I don't know who to contact to sort this out, apple seem to be quite vauge.

iTunes store account hacked

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.