stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 69 of 131 last Next
  • by jhughescmoc,

    jhughescmoc jhughescmoc Jan 6, 2012 7:47 PM in response to stereocourier
    Level 1 (0 points)
    Jan 6, 2012 7:47 PM in response to stereocourier

    Moi aussi.  I was hacked today for $79 by KingdomConquest.  My iTunes payment method is now set to none and of course new password.  I called customer service and had a refund while still on the phone.  Kudos to Apple for the quick response.  But will I be getting an iPad3?  NFW.  If the ecosystem is not secure, if my PayPal account can be accessed, it just isn't worth the risk.  So far my kids' Kindle Fires are unhacked, but maybe the android app store is next.  This could be a real problem for the online purchasing paradigm in general.  Take it seriously Apple.  Maybe you guys have the talent to come up with a secure online buying system.  Do what you do best.  INNOVATE!

  • by MacAurora,

    MacAurora MacAurora Jan 9, 2012 7:43 AM in response to jhughescmoc
    Level 1 (0 points)
    Jan 9, 2012 7:43 AM in response to jhughescmoc

    I was hacked today for almost $50 in Apple gift card money. First someone gained access to my account and "downloaded" the free Kingdom Conquest app at 2:45 a.m. when I was asleep, and then bought almost $50 worth of In App Purchases from SEGA Corporation. SEGA says I should complain to Apple and ask for a refund. Apple says it's not responsible for In App Purchases. I'm glad I did not have a PayPal or credit card linked to my account. Apple should do a better job helping those who think they've been hacked figuire the problem out...

  • by Armandus,

    Armandus Armandus Jan 9, 2012 11:03 AM in response to stereocourier
    Level 1 (0 points)
    Jan 9, 2012 11:03 AM in response to stereocourier

    I'v been hacked today on my itunes accout a total of 371,89 euro was bought.

    They used it to buy Texas Poker with inapp buy's and a gift card money of 50 euro...

     

    I disabled my click and buy account and changed my password. I'v e-maild apple for refund.

  • by Trudina1976,

    Trudina1976 Trudina1976 Jan 10, 2012 5:31 AM in response to Armandus
    Level 1 (0 points)
    Jan 10, 2012 5:31 AM in response to Armandus

    Hi...I hope someone can help me.... Today I received an email from Apple where I was told that someone bought music with my idapple on a unregistered mac or pc... I was told to change password. I did it. Now that I have a new password I entered on itunes and... SURPRISE.... I had 69 Euro... I have 0,28 cent.... I check the bought cronology and discovered that yesterday a very kind man or woman bought 5 albums and other songs.... and now???? It is possible to have my credit back? What can I do?I have already written to apple....

    Please help me!

  • by Vincent_V,

    Vincent_V Vincent_V Jan 10, 2012 6:36 AM in response to stereocourier
    Level 1 (0 points)
    Jan 10, 2012 6:36 AM in response to stereocourier

    210 € charged for Haypi Kingdoms, hope Haypi and/or Itunes will refund me.

  • by macdad55,

    macdad55 macdad55 Jan 10, 2012 9:00 PM in response to stereocourier
    Level 1 (0 points)
    Jan 10, 2012 9:00 PM in response to stereocourier

    I was hacked for $35 in apple gift card money by Kingdom Conquest. I e-mailed Apple, and they are going to credit my account in 5-7 business days. It was in app purchases by an unauthorized computer. Seems like apple might consider email verification for purchases from unauthorized computers (duh). Also seems like apple might consider removing an app from their store that is associated with so much fraud. My password was pretty weak, so I changed it, but I have to say I am getting worried about apple's security.

  • by TheMadCoder,

    TheMadCoder TheMadCoder Jan 11, 2012 5:22 PM in response to stereocourier
    Level 1 (0 points)
    Jan 11, 2012 5:22 PM in response to stereocourier

    This is all sounding familiar, and it seems like it might be simpler than we think.

     

    Here's how I think it's happening:

     

    1) Hacker logs into a game with weak security.  These games tend to send username/account/password in the clear and via plain text.  Order & Chaos Online is an example of such a game.

     

    2) By playing in proximity to other people, they easily "see" various usernames/account/passwords from other players (this does require a hack, but is simple and readily available online).

     

    3) Once the hackers have a username/account/password from the game, such as Order & Chaos Online, they attempt to use that account information for iTunes.  In most cases it won't work, but it many it will.

     

    4) Once hacker has username/account/password, they log in and purchase in-app items in other games (or even the same games.

     

    Given my theory here, I don't use my email account (that's tied to my iTunes account) for ANY online game or experience with other players. 

     

    I don't think the problem is iTunes, rather lack security in applications that require an email address to use, and lack security in users who choose the same username/password for iTunes and application logins.

     

    That's just my 2 cents.

  • by Vincent_V,

    Vincent_V Vincent_V Jan 11, 2012 10:04 PM in response to TheMadCoder
    Level 1 (0 points)
    Jan 11, 2012 10:04 PM in response to TheMadCoder

    I don't think so, in many cases people don't even have these games. In my case the game was purchased along with real purchases of mine. It seems as if somebody hacked into my account while I was using the Appstore, and that's a security issue that Apple has. Of course the seller should also see if the account who get's the in-game purchase is the same one that pays for it. But they probably don't care as long as money flows in.

  • by pepsiloveshotdogs,

    pepsiloveshotdogs pepsiloveshotdogs Jan 13, 2012 8:25 AM in response to macdad55
    Level 1 (0 points)
    Jan 13, 2012 8:25 AM in response to macdad55

    I was also hacked with Kingdon Conquest.  They purchased the game and in-app credits.  My amounts were $49 and $46.  My iTunes account was funded by PayPal which then pulled from my checking account.  I caught it quick so I called PayPal and closed my checking account and the charges cannot go through.  I am so very frustrated and disappointed with Apple and iTunes!

    I do not buy or play games like this, nor do I use the game center so my email address is not out there in any way.

    Apple really needs to get on top of this before they start losing customers...

  • by vebazzo,

    vebazzo vebazzo Jan 15, 2012 1:05 AM in response to Armandus
    Level 1 (0 points)
    Jan 15, 2012 1:05 AM in response to Armandus

    The same thing happened to me this morning: 100 Euros in Gift Cards, not related to any game. I have a question to all these people saying: "E-mail Apple". What e-mail? I only find the "Express Lane" in their page when looking for support for iTunes, and the "Express Lane" link is currently not working. How else can I contact Apple on this matter?

     

    Thank you all.

  • by LizNDale,

    LizNDale LizNDale Jan 15, 2012 10:52 AM in response to stereocourier
    Level 1 (0 points)
    Jan 15, 2012 10:52 AM in response to stereocourier

    Count me in as well. $100 in 3 seperate hits on this *&(&^%%$## Kingdom Conquest at 3:15, 3:17 and then again at noon today WHILE I was creating dispute with Paypal.

     

    And Vebazzo, I too had an awful time trying to figure out the email, it is itunesstoresupport@apple.com.

     

    I hope for a reply soon.

     

    In the mean time, I changed my password and changed my itunes payment method to "none".

  • by atomb0215,

    atomb0215 atomb0215 Jan 15, 2012 1:04 PM in response to stereocourier
    Level 1 (0 points)
    Jan 15, 2012 1:04 PM in response to stereocourier

    What email address did you use to contact Apple?  I have the same issue, and I can not find an email address.  I called the 1-800 number, and they said to email a response.  I have spent an hour looking for it on the apple support site!!

  • by LizNDale,

    LizNDale LizNDale Jan 15, 2012 1:36 PM in response to atomb0215
    Level 1 (0 points)
    Jan 15, 2012 1:36 PM in response to atomb0215

    atomb0215, use itunesstoresupport@apple.com

     

    They have already refunded 2 of my 3 charges, which I incurred around 3:00 this morning.

     

    I agree, is is VERY difficult to find the email addresses.

  • by hypnoqueen,

    hypnoqueen hypnoqueen Jan 16, 2012 8:16 AM in response to John Kranz
    Level 1 (0 points)
    Jan 16, 2012 8:16 AM in response to John Kranz

    That tip may not always work.  I got hacked and charged for 3 purchases I did not make and so I changed my password, and removed payment options to "none" and I still got another charge a few days later.  How can my account be charged when there is not payment option?  The thief used the same credit card # that was no longer attached to my account. 

  • by LizNDale,

    LizNDale LizNDale Jan 16, 2012 8:40 AM in response to hypnoqueen
    Level 1 (0 points)
    Jan 16, 2012 8:40 AM in response to hypnoqueen

    holy cow.

     

    What the heck is going on? Apple and Sega know full well that this is an ongoing concern with Kingdom Conquest.

     

    1) Why do they continue to allow In App purchases for this game, in general?

    2) Why do they allow the specific In App purchases for this game when they knew the device is unauthorized? If they can send me a warning email, can't they block the purchases?

    3) Why do they pretend that I was a victim of ID theft, when they know something fishy is going on with Kingdom Conquest?

     

    And what of the Tech Media? Why are there many blogs and articles written about this in June of 2011, but utter silence since then?

first Previous Page 69 of 131 last Next