stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 71 of 131 last Next
  • by Chris CA,

    Chris CA Chris CA Jan 21, 2012 9:11 PM in response to dschleich1
    Level 9 (79,692 points)
    iTunes
    Jan 21, 2012 9:11 PM in response to dschleich1

    dschleich1 wrote:

     

    I think we figured out it's the "Enable In-App Purchases" setting on the iTouch.

    Settings > General > Restrictions - Enable restictions and In app purchases - Off

  • by chaplin1,

    chaplin1 chaplin1 Jan 21, 2012 9:13 PM in response to Chris CA
    Level 1 (0 points)
    Jan 21, 2012 9:13 PM in response to Chris CA

    well I don't own an iTouch so it certainly has nothing to do with the settings on one---at least not for me!

  • by chaplin1,

    chaplin1 chaplin1 Jan 21, 2012 9:17 PM in response to crAsh RR
    Level 1 (0 points)
    Jan 21, 2012 9:17 PM in response to crAsh RR

    I agree CrashRR, I think the problem is the servers where Apple maintains our AppleID accounts, not anything to do with our personal devices or other activities.  That seems to be the way most hackers work--attacking servers is far more efficient than attacking individual devices, whether they be pc or mac.

     

    Apple doesn't seem to want to admit this though, as evidenced by their long-winded explanation of all the things I must have done wrong to cause this.

  • by CSmith402,

    CSmith402 CSmith402 Jan 22, 2012 9:48 AM in response to stereocourier
    Level 1 (0 points)
    Jan 22, 2012 9:48 AM in response to stereocourier

    The same exact thing happened to me last week! I had 8 charges on my account all for the same exact game for different amounts of money. I'm so happy I had it linked to my paypal instead of my bank account, they drained the few dollars I keep in there and they drained my iTunes gift card so we are up to around $25, and then Apple sent me an email stating that I STILL OWE $40.00...

     

    Needless to say I was refunded all $ to my accounts (after many emails and phone calls) and REFUSE to link any Credit Card of bank info to itunes.

     

    NOW I can't even add songs to my iphone from my computer.... *** is going on with itunes????

  • by Chris CA,

    Chris CA Chris CA Jan 22, 2012 10:17 AM in response to chaplin1
    Level 9 (79,692 points)
    iTunes
    Jan 22, 2012 10:17 AM in response to chaplin1

    chaplin1 wrote:

     

    well I don't own an iTouch so it certainly has nothing to do with the settings on one---at least not for me!

    I never suggested it did.

    dschleich1, whiom I replied to, was making in-app purchases and my post above showed how to turn it off.

  • by crice22554,

    crice22554 crice22554 Jan 22, 2012 1:26 PM in response to Chris CA
    Level 1 (0 points)
    Jan 22, 2012 1:26 PM in response to Chris CA

    I am jumping right in, not knowing where this started, but I was in line at the grocery store, trying to pay for my groceries with my debit card, declined, ran it again, obviously a mistake, declined.  Called my bank "are you aware of the itunes store charges in China".  Long story short, over $150 in charges today, and Navy Federal Credit Union customer service said that they had mulitple calls today.  Get online to delete the credit card and change user name and such, can't delete the card, don't want to delete account, call Apple, of course they tell me to use the online chat, finally get to a screen for online chat and it's closed.

     

    The guy on the phone was not even concerned at all that an Apple account had been hacked and I was out the bucks.  Luckily NFCU is great about this kind of stuff, but that's rather sad for him to brush me off and tell me to use the online chat.

     

    Sorry for jumping in, but just a side note

  • by apulleytn,

    apulleytn apulleytn Jan 30, 2012 5:03 PM in response to ck08
    Level 1 (0 points)
    Jan 30, 2012 5:03 PM in response to ck08

    I got hacked today by Sixjoy Hong Kong; 2 in-app purchases for $19.99 each. No idea what it is or how they did it.

  • by LizNDale,

    LizNDale LizNDale Jan 30, 2012 6:35 PM in response to apulleytn
    Level 1 (0 points)
    Jan 30, 2012 6:35 PM in response to apulleytn

    If you haven't already, send an email to itunesstoresupport@apple.com

     

    They will issue refund.

  • by shodanjr,

    shodanjr shodanjr Jan 30, 2012 10:18 PM in response to LizNDale
    Level 1 (0 points)
    Jan 30, 2012 10:18 PM in response to LizNDale

    I just got hacked...hacker got this http://itunes.apple.com/cn/app/id457522213?mt=8

     

    And $100+ worth of DLC..

     

    I ended up changing passwords everywhere and im tracking my credit card. I believe i didn't have one linked to my itunes for a long time.

  • by apulleytn,

    apulleytn apulleytn Jan 30, 2012 10:26 PM in response to LizNDale
    Level 1 (0 points)
    Jan 30, 2012 10:26 PM in response to LizNDale

    Sent an email right after I discovered the fraudulent charges. I received a response within 15 minutes stating that my account will be refunded the stolen charges and to reset everything.

     

    Thank you Apple! :)

  • by Dragonchilde,

    Dragonchilde Dragonchilde Jan 31, 2012 9:09 AM in response to apulleytn
    Level 1 (0 points)
    Jan 31, 2012 9:09 AM in response to apulleytn

    I contacted Apple Support after waking up to find that I've received $50 in fraudulent charges on my iTunes account. I used the Express Lane in Apple Support, and was provided with the option to receive a call. They immediately called me, and put me in touch with very supportive techs. I was immediately elevated to a senior security advisor, who disassociated my Paypal account from my iTunes account, confirmed that these were fraudulent charges (and in fact, said "There's no way you could convince me that you did make these purchases") and told me to get in touch with Paypal for a refund, since Apple themselves haven't received payment yet for them, they can't actually refund me yet. 

     

    The advisor was VERY supportive and helpful, and made sure my account is now secure. He said that he suspects this is a sophisticated, deliberate attack, probably made using a proxy to obfuscate the activity trail.  He couldn't specifically say where the purchases were made, only that they were over 1,000 miles from me, on the west coast... as I'm located on the far east coast, it definitely wasn't me!

     

    I'm a major security fanatic, although my password for iTunes was not terribly secure (they probably brute forced it) I definitely did NOT respond to any phishing attempts. 

     

    There's only two things about the situation that are startling... in my transaction record, the hackers actually made the purchase payable to my password - "Gift for PASSWORD" right there in my transaction record.

     

    So they definitely HAD it! They won't be able to crack my new one, though.

     

    The only thing I can figure is I purchased a free app last night... it's the only activity I've had on my iTunes account in over a week.  It's possible that app somehow compromised the security of my iPod.

     

    So props to Apple for the speed with which they responded, and the attention they've given my case.      Let's just hope Paypal's as responsive (which I doubt.)

  • by handss,

    handss handss Jan 31, 2012 12:48 PM in response to stereocourier
    Level 1 (0 points)
    Jan 31, 2012 12:48 PM in response to stereocourier

    I just got hacked today. at 5:19 am pst (while i was asleep) there were 2 transactions made for "gift certificates". one was $20 and the other $30. all it said was "gift certificate for dfs, gift certificate for fp". my smartness had my paypal account linked to my itunes store account so all you needed was my password to buy anything. the weird thing issssss when i called apple support the genius said there are no gift certificates on the itunes store. you cant buy them. yet i had the deduction in my paypal, apple, and an email sent saying i made the purchases. well ive talked to paypal, apple and my bank. its going to take time to get the money back IF i even do. paypal out of everyone was the most helpful with every question i had. the bank was trying to charge me $25 PER stop transaction which amounts to the total i was charged in certificates! then they wanted me to come in and change my bank account number and buy new checks for $25! ***! so im on the verge of an overdraft fee for 2 transaction, each fee costing $25 per item, totaling the amount taken from my account to $100. HA! yea i know its only $50 but i get paid tonight at 12:01 am so my funds tend to dwindle before i get paid. i hope to god i get that **** money back.

  • by bigeslp,

    bigeslp bigeslp Feb 1, 2012 10:28 PM in response to stereocourier
    Level 1 (0 points)
    Feb 1, 2012 10:28 PM in response to stereocourier

    I too can say I have been hacked. Same thing. My ITunes is linked to PayPal. I got some emails from PayPal about purchases to ITunes. Obviously I have not made any of these which all in all have totaled $161.01. Mostly the same app being purchased: Samuari Lite from GL Games at 12.99. Plu some various music and albums.

     

    I have emailed PayPal as well as ITunes. Hopefully I will get some resolution on this matter soon. Since I have changed passwords on both PayPal and iTunes. And removed the payment method on iTunes.

     

    The whole process *****.....

  • by Snoofus,

    Snoofus Snoofus Feb 3, 2012 4:32 AM in response to bigeslp
    Level 1 (0 points)
    Feb 3, 2012 4:32 AM in response to bigeslp

    I was also Affected today... Fortunatly I refuse to link my credit card to anything ever, so I only lost 9 dollars or so temporarily (from a past gift card i bought), but also had something to do for some random game and random VPN program....

     

    To those people who are saying that it has something to do with your own computer, I can pretty much ensure you it does not, it is purely an apple ID problem or else our emails/paypal accounts themselves would also be affected.

     

     

    Oh well, after being pretty much glued to the internet since the late 90's something like this was bound to happen to me sooner or later .

  • by MadScientistZ,

    MadScientistZ MadScientistZ Feb 3, 2012 8:56 AM in response to Snoofus
    Level 1 (0 points)
    Feb 3, 2012 8:56 AM in response to Snoofus

    I, too, like everybody else here was the victim of a hacked iTunes account. However, there are a few differences:

     

    1. I do not have an iPad, iPhone or iAnything.

    2. I haven't used iTunes in a long time.

    3. The two machines in my office (which have iTunes) are locked down tight (I do security work).

    4. I never received an email from Apple informing me that $99 worth of purchaes were made on my account.

    5. My first inkling that there was a problem was when I received an email from Apple telling me that the purchases had been reversed and that I was being given an instore credit for $99.99.

    6. What?!

    7. When I wrote to iTunes support that I, "wanted a straight answer, has Apple's servers been hacked?" I recieved this reply from 'Salman', "I would like to inform you that, it was not hacked by Apple servers."

    8. My requests to talk to somebody above 'Salman' about this have been ignored.

     

    It is my professional opinion, and I have a doctorate in computer science, that Apple's iTunes servers have been repeatedly hacked, that Apple is in denial about this (or just covering it up).

first Previous Page 71 of 131 last Next