stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 77 of 131 last Next
  • by clairetweet,

    clairetweet clairetweet Feb 20, 2012 12:22 PM in response to MadScientistZ
    Level 1 (0 points)
    Feb 20, 2012 12:22 PM in response to MadScientistZ

    Wow - this is dreadful. It sounds just like my hack problem as my Credit Card was changed to Non, and I could not work out why. If this is true Apple, it is shocking and this should be made public and sorted urgently. I am switching off all access to iTunes.

  • by Decie,

    Decie Decie Feb 20, 2012 12:59 PM in response to stereocourier
    Level 1 (0 points)
    Feb 20, 2012 12:59 PM in response to stereocourier

    I just received an email from Shaun from the iTunes Store/Mac App Store Customer Support regarding the report I submitted through express lane and he has informed me that I will be a full refund of the unauthorised purchases. I hope you all get your money back aswell.

  • by phifli,

    phifli phifli Feb 20, 2012 10:22 PM in response to charleysmith
    Level 1 (0 points)
    Feb 20, 2012 10:22 PM in response to charleysmith

    Someone just used my account to purchase $40 in 125 Dark Matter on Galaxy Empire.. Did you get this resolved?   I happened to change my password in the first ten minutes, and filled out a form for Apple..  I never use my iTunes account on anything except iTunes.. I'm a security consultant as well.  I don't get phished, so I'm pretty sure if Apple uses cryptography and/or hashes for all authenticaiton that it has to be on their end... Let's see how this gets handled...

  • by gingerCE12,

    gingerCE12 gingerCE12 Feb 21, 2012 1:38 AM in response to stereocourier
    Level 1 (0 points)
    Feb 21, 2012 1:38 AM in response to stereocourier

    This has happened to me too, except it was $40 for army of darkness points--taken from my gift card on the acct.  Mine occured Jan 27, 2012, but have not signed into my iturns account until tonight to purchase some songs and discovered this theft.  I don't know how my account got compromised but it seemed to happen days after I loaded gift cards from Christmas onto my account.  I never received any emails regarding this purchase, though just checked my email again and I did get one on Jan 26, 2012 for music I actually did purchase--so somehow these purchases were made without any email being sent.  As soon as I logged into iTunes tonight I got a message that I needed to reset my password--so Apple definitely knew something was fishy on my account, but I never received any email message regarding the fact my account had been compromised.  I started a file with express lane but will call/chat tomorrow to get this resolved. 

  • by gingerCE12,

    gingerCE12 gingerCE12 Feb 21, 2012 2:32 AM in response to gingerCE12
    Level 1 (0 points)
    Feb 21, 2012 2:32 AM in response to gingerCE12

    After reading some of the other responses, I am going to post more details.  I have not made any purchases via itunes since July 2011.  I tend to purchase from Amazon but received 3 iTunes gift cards for Christmas 2011.  I added them to my account Jan 24, 2012 and purchased music on Jan 24 (received receipt in email Jan 26). On Jan 27 unauthorized game purchases were made on my acct wiping out most of my gift card balance.  Did not receive email.  Logged in Feb 20, 2012 to purchase music, and it was weird because immediately I was prompted to reset mt password--then I actually purchased some music with my small balance when I was prompted to download a free game app.  I then realized that something was wrong.

     

    I know there is no evidence, but in my opinion, there seems to be a definite link about redeeming a gift card and somehow the hacker(s) becoming aware of a gift card balance--it triggers something.  I say this because I have never been hacked on any other account and had never had iTunes gift cards before.  I doubt I was a victim of phishing--and if they suggest this, I will tell them I resent any implication that I was somehow responsible for this fraud, when I believe it was my redeeming a gift card that was the real cause of this effect.  I tend to be very responsible when it comes to my security.

  • by PatrickGSR94,

    PatrickGSR94 PatrickGSR94 Feb 21, 2012 5:09 AM in response to gingerCE12
    Level 1 (2 points)
    Feb 21, 2012 5:09 AM in response to gingerCE12

    Ginger, did you not receive any e-mail receipts for the purchases, as is normal with App Store purchases?  I received a receipt last night for the in-app purchase of 19.99 that happened just after midnight yesterday.  However Apple had alerted me to the activity just a couple of hours after the purchase happened, so I already knew what was happening when I got the e-mail receipt.

     

    I did get a respone back from Apple yesterday, but the guy said he needed the transaction number, even though I sent it previously.  I received that e-mail only about 5 minutes before he was scheduled to get off work (4:30 EST), so I expect a response back some time this morning.

  • by Jewman83,

    Jewman83 Jewman83 Feb 21, 2012 5:48 AM in response to stereocourier
    Level 1 (0 points)
    Feb 21, 2012 5:48 AM in response to stereocourier

    Same has happened to me. I had 34$ in my iTunes store credits now I only have $2. I'm furious I haven't gotten a response of any kind yet either

  • by dustinw82,

    dustinw82 dustinw82 Feb 21, 2012 6:06 AM in response to Jewman83
    Level 1 (0 points)
    Feb 21, 2012 6:06 AM in response to Jewman83

    The best way to get an immediate response from them is to live chat.  My issue was resolved in a matter of minutes.

  • by whicho17,

    whicho17 whicho17 Feb 21, 2012 6:12 AM in response to stereocourier
    Level 1 (0 points)
    Feb 21, 2012 6:12 AM in response to stereocourier

    I just found that this happened to me this morning only my address was not changed.  I have submitted an email to Apple and I'm hoping to get a response soon.  Has anybody noticed what was purchased.  I know for me it was a lot of Galaxy Empire apps and in app purchases along with one Metallica song.

     

    After reading some articles I'm wondering if Tap4Fun....the seller is responsible for this.

  • by sSickmann,

    sSickmann sSickmann Feb 21, 2012 6:31 AM in response to PatrickGSR94
    Level 1 (0 points)
    Feb 21, 2012 6:31 AM in response to PatrickGSR94

    I also failed to receive email notifcations for the fraudulent transactions . . I found out when I logged onto iTunes and the system told me my account was compromised and locked and to change my password !

  • by PatrickGSR94,

    PatrickGSR94 PatrickGSR94 Feb 21, 2012 6:32 AM in response to whicho17
    Level 1 (2 points)
    Feb 21, 2012 6:32 AM in response to whicho17

    I do not believe it is Tap4Fun who is responsible.  Their games have a pretty large online following, and I found this page yesterday on their blog: http://www.tap4fun.com/commitment-to-combating-fraud

     

    I think it just happens that these hacks are playing this game and want to buy whatever credits the game uses, and so they steal from other people's accounts.

  • by whicho17,

    whicho17 whicho17 Feb 21, 2012 6:44 AM in response to PatrickGSR94
    Level 1 (0 points)
    Feb 21, 2012 6:44 AM in response to PatrickGSR94

    Patrick - thanks for the link....you're right I jumped to conclusions based on the purchases and the other article I had read about some shady companies that create apps.

  • by PatrickGSR94,

    PatrickGSR94 PatrickGSR94 Feb 21, 2012 6:50 AM in response to whicho17
    Level 1 (2 points)
    Feb 21, 2012 6:50 AM in response to whicho17

    Yes I made the same conclusion about MyFitnessPal, which others say they were hacked after loading it.  However they have a HUGE online community and have been around for a number of years, it looks like.

  • by gingerCE12,

    gingerCE12 gingerCE12 Feb 21, 2012 9:52 AM in response to PatrickGSR94
    Level 1 (0 points)
    Feb 21, 2012 9:52 AM in response to PatrickGSR94

    Hi Patrick,

     

    I checked my email and was never sent a receipt for the unauthorized purchase or for the free download purchase made the next day.  I am not sure how that happened but I looked and all of my information settings were accurate.  

     

    I have never purchased an app (do not have iPhone or iPad or Touch) and have never purchased any kind of game or points for a game for a computer.  I did research the game that was purchased and contacted the game software company via email to let them know someone had used my account to purchase their game.  I doubt I will get a response but I felt better letting them know there is fraud regarding people playing their game.  The "hacker" purchased points for Army of Darkness Defense (which showed up as AODD). 

  • by gingerCE12,

    gingerCE12 gingerCE12 Feb 21, 2012 10:59 AM in response to PatrickGSR94
    Level 1 (0 points)
    Feb 21, 2012 10:59 AM in response to PatrickGSR94

    Hi Patrick, I want to add besides never buying any apps, I have never purchased/owned any video game or system--never even played an xbox or playstation-- I played a Wii once at a family member's house when it first came out was it 5 or 6 years ago (?).  My phone has no internet access.  I only purchase music via computer (no videos or shows etc).  Part of me doesn't think buying a certain app or download is the root cause.  It seems to be people with paypal accounts and people with gift card balances.  I am wondering if there is any time frame on when the hack occurs as I put the balance on my acct and within 2-3 days was when the unauthorized purchase was made. 

     

    My purchases were made at 11:36 pm when customer support is closed too.

     

    Message was edited by: gingerCE12

first Previous Page 77 of 131 last Next