stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 80 of 131 last Next
  • by wampdog29,

    wampdog29 wampdog29 Feb 22, 2012 8:13 PM in response to camice
    Level 1 (0 points)
    Feb 22, 2012 8:13 PM in response to camice

    That's exactly why I didn't change anything on my iTunes accoutn after the first hack (wel, that and I wasn't sure the first one was a true iTunes charge as they don't even show in my iTunes purchase list). Now, after this second hack, I may have proven that the two may be linked and I am curious to see if anyone else is in the exact same boat as myself.

  • by Wisdom01,

    Wisdom01 Wisdom01 Feb 23, 2012 3:16 AM in response to stereocourier
    Level 1 (0 points)
    Feb 23, 2012 3:16 AM in response to stereocourier

    My account has also been hacked.  I am very careful and so very shocked that this has happened and that Apple do not seem to be taking this seriously.   Very concerned that my personal data available to Apple has been compromised.  Noticed that there is an article on the Huffington Post at http://www.huffingtonpost.com/2012/02/10/itunes-hack-unauthorized-charges-apple_ n_1268593.html.  Feel that this should be investigated seriously by Apple.

  • by j_romeo_2000,

    j_romeo_2000 j_romeo_2000 Feb 23, 2012 6:33 AM in response to stereocourier
    Level 1 (0 points)
    Feb 23, 2012 6:33 AM in response to stereocourier

    Yet another victum here.  I had unlinked my Paypal account but still someone was able to charge $21.94 For HaypiDragon Coins.  Luckily, I realized it in time and unlinked Paypal yet again.  The hacker continued to try to purchase more HaypiDragon Coins totaling 39.47.  Apple Store shows that the payment didn't go through and I now OWE then the $39.47 !  I can't add a funding source now because when I do they will charge that.  There is NO option to cancel these transactions either.  I was not Phished!!  Someone working at Apple or a very good hacker has managed to get into the Apple Store's computers.  I can not get anyone to help me on the phone whatsoever.  ALL I can do is send emails and wait.  VERY frustrating and I will probably Never trust the Apple Store ever again.

  • by dustinw82,

    dustinw82 dustinw82 Feb 23, 2012 7:04 AM in response to j_romeo_2000
    Level 1 (0 points)
    Feb 23, 2012 7:04 AM in response to j_romeo_2000

    j_romeo-  This same exact thing happened to me.  HaypiDragon Coins were purchased on my account using PayPal.  I didn't catch it in time to remove my PayPal account, but it had still showed that there was an error in processing and wanted me to update my payment information.  Lucky for me!  Here's what I did.  I went through the online express lane and did an online chat.  The issue was resolved this way.  The charges still appeared on my iTunes account history, but nothing came out of my PayPal account.  I've made purchases since and everytime I've completed my purchase, I remove my credit card.  I have never been charged for the HaypiDragon in-app purchase.  I suggest you log on and get someone to help via online chat.  From now on, whenever I make a purchase, I remove my payment information ASAP.  I'm one of the lucky ones that caught this before it actually affected my finances. 

  • by j_romeo_2000,

    j_romeo_2000 j_romeo_2000 Feb 23, 2012 7:22 AM in response to dustinw82
    Level 1 (0 points)
    Feb 23, 2012 7:22 AM in response to dustinw82

    Thanks, In defense of Apple I recieved an email already from support.  I will come back on here and let everyone know if they resolved my issues and refunded me.  Crazy thing is I had disabled Paypal as a payment option because my iPod has been broken.  I even took out the paypal email account that I use to use for payments from Paypal.  I do not know how they managed to charge anything to my Paypal unless they somehow accessed Apple computer records.  If the iTunes Store would make a faster way of contacting them of unauthroized transactions maybe they could track down the culprits.  I caught them the VERY second they were trying to make more purchases but I spent a couple hours trying to get ahold of the apple Store.   Crazy!  I don't only want my money back I want these people prosecuted!

  • by tekchic,

    tekchic tekchic Feb 23, 2012 12:56 PM in response to stereocourier
    Level 1 (0 points)
    Feb 23, 2012 12:56 PM in response to stereocourier

    Apple Customer Support was very helpful -- I had a reply within minutes of my email (they had to disable then reenable my account), and the $55 credit back to my account happened sometime overnight, as it was there this morning.

     

    I deauthorized all of my iTunes machines and have since reauthorized one. I used a custom security question before the hack, and a unique to iTunes password. I created a new custom security question again. The new password is also more than 17 characters made up of several words and/or phrases, mixed case, numbers, special characters, the whole works. I have always used a unique long password with mixed case/characters anyway though -- I'd love to know how I got hacked in the first place.

     

    If Apple is able to send me an email notifying me of a purchase from an UNAUTHORIZED device, shouldn't they be capable of stopping that purchase from any unauthorized device? Even a simple "confirm via email link" would have prevented this. I'd love to see some changes in regards to allowing purchases from unauthorized devices.

  • by Uncle Tio,

    Uncle Tio Uncle Tio Feb 23, 2012 6:02 PM in response to stereocourier
    Level 1 (0 points)
    Feb 23, 2012 6:02 PM in response to stereocourier

    Today I had an unauthorized attempt to purchase from the Apple store.  It appears that it was linked between my credit card and Apple only.  Still tracking down on my end why.  Apple did call to let me know there was an attempt to purchase a Mac Book Pro.  They cancelled it and I notified my card company, cancelling that account.  The card company fraud department said they were going to work with Apple.  Will let you know the rest of the story.

  • by MsB2U,

    MsB2U MsB2U Feb 24, 2012 2:31 AM in response to stereocourier
    Level 1 (0 points)
    Feb 24, 2012 2:31 AM in response to stereocourier

    My account was hacked as well. I woke up and saw two new games on my iPhone. Then I had an email from Apple about a purchase from an iDevice that wasn't associated with my Apple ID. Whoever hacked my account spent $25. I had a $25 dollar gift card added to my account, but I had already used 5 dollars of it. The games were in Chinese. I couldn't read any of it. I contacted Apple IMMEDIATELY. Within a resonible amount of time, I got a reply from Apple. They said they carefully reviewed my case and they will refund me a credit of $25. They did disable my account. From reading these previous post I see that most people's accounts were hacked if they had a credit from an iTunes gift card. I've had an iPhone since 2008 and NOT once have I had a problem until now. If I ever add a gift card again, I will only do so when I am ready to make a purchase right then & there. I hope Apple can fix this problem because it is such a hassle.

  • by Joneal,

    Joneal Joneal Feb 24, 2012 1:46 PM in response to stereocourier
    Level 1 (0 points)
    Feb 24, 2012 1:46 PM in response to stereocourier

    I was hacked overnight also.  Woke up.  Checked iPod and there was that mysterious chinese app and tons of in-app purchases.  Lost $30 worth of credit.

  • by Xenosnake,

    Xenosnake Xenosnake Feb 24, 2012 2:48 PM in response to stereocourier
    Level 1 (0 points)
    Feb 24, 2012 2:48 PM in response to stereocourier

    Wow, it happened to me a second time. Bunch of chinese apps were bought, so I talked to Apple and got my store credit back yesterday. I changed my password and security question after i talked to Apple, but I just got another receipt saying I bought more chinese apps 15 minutes ago.

  • by PatrickGSR94,

    PatrickGSR94 PatrickGSR94 Feb 24, 2012 2:51 PM in response to Xenosnake
    Level 1 (2 points)
    Feb 24, 2012 2:51 PM in response to Xenosnake

    OMG that is ubelievable!!!  How the heck is Apple not onto this by now?!?!!

     

    They NEED to release a new version of iTunes that only allows purchases from authorized devices ASAP!!!!

  • by camice,

    camice camice Feb 24, 2012 2:58 PM in response to PatrickGSR94
    Level 1 (0 points)
    Feb 24, 2012 2:58 PM in response to PatrickGSR94

    Although Apple has refunded all $199.90 of charges to my credit card without any argument (which tell's me they know what's going on).

     

    Now what I find truly disturbing is that Apple is actually breaking federal law by not notifying us as their customers that their system has been compomised! There is NO WAY that they can't be aware of this and denying it is not only UNETHICAL it is ILLEGAL! It this really the way Apple is doing business now?!

  • by camice,

    camice camice Feb 24, 2012 2:59 PM in response to camice
    Level 1 (0 points)
    Feb 24, 2012 2:59 PM in response to camice

    Sorry, I meant "Is this" not "It this", my annoyance is effecting my grammer.

  • by DerexV,

    DerexV DerexV Feb 24, 2012 7:38 PM in response to stereocourier
    Level 1 (0 points)
    Feb 24, 2012 7:38 PM in response to stereocourier

    This is too bad that it's happening. Especially now that there are so many devices out there, I can see it becoming more of an issue. I recently got my account hacked for $40 total for in-app purchases for the game Galaxy Empire. I know it wasn't me because I disabled in-app purchases and the kids don't touch that game. I noticed a bunch of Korean characters in the chat panel when I logged in to see who/what/where this hack was coming from.

     

    I hope I get my money back with the dispute I put through with Paypal. It's too bad this is happending with these minor virtual goods. Just imagine in 20 years when everything is virtual good and things get stolen left and right without a trace.

     

    If this can happend to Apple, it's going to be a scary world then.

  • by DerexV,

    DerexV DerexV Feb 24, 2012 7:49 PM in response to Eagerbob
    Level 1 (0 points)
    Feb 24, 2012 7:49 PM in response to Eagerbob

    I've been with MS on Xbox Live since its inception in 2001. NEVER ONCE had I been hacked to buying virtual goods. Apple has dropped the ball on this one. I hope I get my refund soon.

first Previous Page 80 of 131 last Next