You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:43 PM

Reply
1,958 replies

Aug 25, 2011 9:12 PM in response to stereocourier

@joshfromgrandville.


It looks as if you are experiencing a carbon copy of my hacking, the support page drop dpwn menues do actually work but it takes around 10 seconds for the menu to activate once selected. If you click on the drop-down and wait you will eventually see your cursor start to blink. extremely slow just like the Apple support. Good luck!

Aug 26, 2011 8:42 AM in response to stereocourier

Same scam happened to me cleared out £50 quid worth of store credit. Got email asking for details which I supplied got a follow up message saying basically tough take it up with your CC company. Don;t think they bothered reading the email sent them as said had never used a credit card on the store only gift cards.


Might have a chat to the Ombudsman office next week as have seen forum post going back to June 2010 about accounts being hacked in the same way. Itunes are just help the fraudsters steal the money as they have done nothing/are looking at doing nothing to stop this activety. Hope the Ombudsman give them a heafty fine they deserve it. Also sent something to THE SUN paper (know its one of the lower papers but think they be more interested in the story than other)

Aug 26, 2011 12:22 PM in response to Halo26

Well everyone I have an update on my end. They totally shut down my account but I was able to get it going agaiin after answering a few question. They also refunded my account the missing money. The flip side is all contacts I made I inquired about what they were doing on their end to prevent this again and have yet to receive an answer. Its like they skirted the issue at all times. I am now getting 5 dollar gift cards and just going to load them as I need them. It's a very sad situation for a company that is sopposed to be on the cutting edge of things...

Aug 26, 2011 9:25 PM in response to CndrllC

Count me in as well. I got an email around 10:00 pm today 8/26/2011 that states my apple ID was used to make a purchase from the app store on a computer or device that was not previously associated with the apple ID.😮 So I log into the store and sure enough the 100 gift card I just got from purchasing my macbook a few days ago is wiped out. Since the educational sale is going on with the gift cards it seems the hackers are out in full force. I changed my password immediatley but didn't think changing the apple ID was possible. I am going to try but I was always told you cannot do this. I emailed Apple support as soon as I got the email. Now I'm scared that they got into my bank account because I did have my debit card linked. I reported my debit card as stolen so hopefully that will stop anyone from getting into my account if they want. I am not very happy right now and won't be getting any sleep.

Aug 26, 2011 10:09 PM in response to stereocourier

Add me to the list....I never click on links in emails or download from unknown sources, run a security suite & spyware search regularly. I know this didn't come from me. I got an email at 8:45 this morning stating that my address had changed in my account to 1517 baythorn drive wesley chapel, FL 33543-7870 (I did a search on Yahoo! and there is a reference in Yahoo! Answers that someone had posted about this happening to their account as well).

Then I got another email, this one stating: Your Apple ID, *****.com, was just used to download 明珠三国OL from the App Store on a computer or device that had not previously been associated with that Apple ID. Despite the automated system knowing that something was wrong, it still allowed the purchase, which of course, depleted my ENITRE bank. $90 worth. They purchased: 明珠三国OL, 686元宝, Seller: Pearl-in-Palm Information Technology Ltd 9 @ $9.99.

I've emailed Apple twice, just auto replies. Changed my password twice, just to see them make ANOTHER purchase, despite not having any more credit left to steal...AND APPLE LET IT GO THROUGH....despite having NONE selected for other payment. I originally had Paypal selected, which for some odd reason, they terminated the relationship with Paypal as soon as they got access to my account. I got this notification from Paypal: iTunes Store has cancelled a Billing Agreement with you. What???? The entire thing is just weird...frustrating...totally unacceptable.

Aug 27, 2011 4:32 PM in response to SocalNatv

Same here and puzzling as to why the system knows something is wrong, yet allows the fraudulent transaction to go through?


Your Apple ID, xxxxxxxxxxxx, was just used to make a purchase in 明珠三国OL from the App Store on a computer or device that had not previously been associated with that Apple ID.


If you made this purchase, you can disregard this email. This email was sent as a safeguard designed to protect you against unauthorised purchases.


If you did not make this purchase, we recommend that you go to iforgot.apple.com to change your password, then see Apple ID: Tips for protecting the security of your account for further assistance.

Aug 27, 2011 10:48 PM in response to stereocourier

I've just found out that I've been the victim of it as well :-|


Someone purchased Philharmonic Beatles + 2 extra tracks using a gift card a friend had bought me for my birthday.


I used the "report a problem with this purchase" link regarding this - wonder if I'll get any joy from Apple.


What I'm more concerned about is the fact that this company seem to be doing nothing whatsoever about this. Who can we (in the UK) report this to? A case for BBC's Watchdog to look into perhaps?!

Aug 28, 2011 9:57 AM in response to SocalNatv

I got hacked on 8/26/11, minutes after I downloaded a free Chick-Fil-A app via a link CFA posted on Facebook.


The thief first changed my billing address to:

1517 baythorn drive

wesley chapel, FL 33543-7870


Then, he/she downloaded seven $10 copies ($70 total) of Pearl-in-Palm Information Technology Ltd. and 2 $2 in-app purchases by the same vendor, bringing my iTunes credit down to $0.12.


Kudos to Apple, though, for investigating and refunding at least the $70 from the first purchase. I just hope the company persues this matter. I tried to file a police report, but my local sheriff's office said I'm no longer the victim, and it's up to Apple to take action.


My internet search on this address shows that many people have been hacked in the exact same manner with the exact same address.

Aug 28, 2011 10:11 PM in response to stereocourier

Just sent this to Watchdog:-


At 04:35 AM 7/8/11 I received an email from Apple that my account had been changed.

at 04:37 AM 7/8/11 I received two further emails containing invoices for purchases on my account. Both the first and the subsequent emails asked if I had made these changes/purchases and if I hadn't I should review my security settings.


I had not made these changes so I immediately accessed my account and found that the credit I had on my account (birthday present from my Daughter) had been virtually cleaned.


I changed my password, emailed Apple/Itunes.


I also Googled “Itunes account hacked” and was amazed to find that this security problem is vast.


I subscribed to an Apple support community and asked for new posts on a single thread be emailed to me, the come in at around 10 a day from this single thread and there are many threads. Obviously these threads only reflect a very small portion of the effected customers.


I asked Apple how they allowed two purchases from my account within two minutes of account changes without confirmation that is was I that changed them, Apple will not comment.


According to the support community these scams are widespread with no action or comments from Apple, they seem to include straight theft of credit and downloading of ‘poker’ games with the purchase of gaming tokens, some customers who have credit cards linked to their accounts have lost hundreds of pounds/dollars/euros.


All the hacking involves Eastern links, the purchases from my account were music albums with oriental fonts for titles.


It seems that Apple will not act and that this security breech is ‘hushed’, I spoke to an Apple high street shop at first the employee said they had never heard of this before, but when pressed admitted that there is a problem. Apple tech support would not talk to me about this subject.


I also find it unbelievable that in a case of fraud such as this Apple have NO PHONE NUMBERS TO CALL!


In the end Apple refunded my loss but stated that this was a one off and that I should be more careful regards my security.


The problem is not with my security but with Apple, why is it that I have not heard about these scams/frauds when it is obviously widespread throughout the UK and overseas?


Still waiting for a response from The Telegraph and the Daily Mail.

Sep 1, 2011 10:40 PM in response to stereocourier

Just hacked about 3 hours ago. Sent an email to iTunes, changed my email and iTunes passwords and security questions. My address was not changed, but the credit card I had on file is now gone. Called CC company, they don't see any activity but will contact me if something shows up.


The developer of the free app that was downloaded is Addmired, app "Original Gangstaz Rock." PLEASE. I'm sure they'll be able to see by my previou downloads all being medical references that this is not exactly my type of app? After the free app was downloaded, two in-app purchases were made totaling $35.00, leaving a few dollars left to my credit balance from a gift card I received a few months ago (thankful there was only $40 total).


Such BS, folks... for this thread to have been going on for so long, but its still happening? At least I got an email saying a purchase was made on a computer that was not previously used for my account. I see that there are three devices authorized on my account, but can't tell what they are- hopefully when Apple contacts me, they'll be able to tell? It may just be my Macbook, PC and iTouch though. Anyone else have problems with this developer/app? A google search brought their name up a few times in "app farming" articles.

Sep 2, 2011 8:21 AM in response to jenn920

Its been quite sometime since I made a post on here. My apple ID was disabled and havent been able to do anything or offer an update. I got an email from support 24 hrs after contacting them about my gift card disappearing. I was impressed but it didnt last. The support staff said as a one time offer, I will have my itunes balance restored. Umm okay. The tone was like it was my fault. The gift card was from a new mac purchase, part of their educational deal going on. I wish they had the free ipod instead because so far I haven't been able to do much with this "free" gift card. I have changed my password several times and it lets me in however when I go to purchase something, I get a message my account is still disabled. I am then prompted to change my password again. After 6 times, I'm running out of ideas on passwords. I have sent several emails directly to the person from support, that contacted me but no response. I see my restored balance but no way of being able to use it. At this point, if I am able to use the balance, it wont be much fun as I will feel the need to just use it up on anything just so I can feel like I got something out of it before someone takes it again. I'm pretty diappointed in this whole thing and obviously this is a big issue.


Also as precaution, I had my bank destroy my debit card as it was linked to my itunes. I will not be linking any bank cards in the future with itunes.

Sep 2, 2011 9:05 AM in response to Ldoty71

I think the bad guys may still be trying your old password with your Apple ID. When they get all their tries wrong, it locks you out until you change the password. Then, the process begins again. I had it happen to me once, and after I changed my Apple ID email address, it stopped. Might be worth a try.


I don't think anyone has had their CC info stolen..I think the info gets cleared out when the bad guys can't reproduce the CVC from the back of the card/when they change the address. This seems to be solely an issue with gift card balances.

Sep 2, 2011 9:30 AM in response to Jmuskratt

Jmuskratt thanks for the tip. I am not sure how to do this though because I have moblie me. My apple ID is my email address. I see there is an option to change the apple ID but it is not lit up for me to do and I think its because of the mobile me. A while back I wanted to change my mac email and was told I could not until the subscription expired. Now it looks like they are doing away with it altogether. If that happens then maybe I will be able to change it all but until then I am at a stand still till apple does something for me.

Sep 4, 2011 12:29 AM in response to stereocourier

Hello same thing happend to be but two days ago and this company took it of me and bought bizar apps

tem Artist Type Unit Price
User uploaded file
帝國 Online, 5850銀幣禮包, Seller: GAMEISLIVE CORPORATION LIMITED Lakoo In App Purchase -$5.49
帝國 Online, 23400銀幣禮包, Seller: GAMEISLIVE CORPORATION LIMITED Lakoo In App Purchase -$20.99
User uploaded file
Order Total: -$26.48
User uploaded file


it took all my money so i contacted the itunes thing which they kindly refunded my 26.48 and i cchanged my password but again today i got annother bill which is listed up above telling my i have bought the same thing as two days ago again ..... HACKED HELP sombody i dont trust itunes and am not using it till it is all sorted

iTunes store account hacked

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.