stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 9 of 131 last Next
  • by Weedman,

    Weedman Weedman Mar 11, 2011 9:23 AM in response to stereocourier
    Level 1 (0 points)
    Mar 11, 2011 9:23 AM in response to stereocourier
    I also had unauthorized purchases made, nearly cleaning out my iTunes GC credit. The purchases were for AIM, Cartel Wars, and 1000 Cartel Wars points. No response from Apple to my email complaint, after >48hrs. It looks like they may have finally refunded my credit, though.
    I've changed to a more robust password, but don't know how effective that will be. Should I change my AppleID as well?
    Don't have any CC linked to my account, but do have my Paypal account linked.
    Hope to hear some resolution to this.
    Looks like maybe you should spend your GC credit as soon as possible, to avoid getting it cleaned out...
    -DW
  • by PBell,

    PBell PBell Mar 11, 2011 11:22 AM in response to Weedman
    Level 1 (0 points)
    Mar 11, 2011 11:22 AM in response to Weedman
    I was just hit by Hongbin Suo yesterday. First for the 1,700,000 Chips thing and then for 240,000 more chips. I have no idea what this is but I've sent an email to Apple to try to get it credited back. Thankfully, there is no credit card infromation on my account and these charges were deducted from my gift card balance.
  • by Terrence,

    Terrence Terrence Mar 11, 2011 11:27 AM in response to Teenie Sando
    Level 1 (10 points)
    Mar 11, 2011 11:27 AM in response to Teenie Sando
    You need to review your bank's statements or if you are able to review them online, to determine if those purchases actually went through on your CC and not someone else's. In my instance, the hacker had altered my CC information to such an extent such that my bank rejected the transactions, but the CC information that the hacker had used, showed that they were downloaded by my apple ID and billed to someone else. So, thats why you see it on your itunes history just as it was with mine. Apple for whatever reason chose NOT to remove these items from my download history from the pending status and when my Bank CC information was reinstated to the account, the history showed that they were no longer pending, but now is a part of my history to that apple ID. I would have preferred that these items be removed and they may yet be done at some future date (within 60/90 days), just my guess. A recheck of my bank CC biling information shows that I have not been charged for these unauthorized transactions.
    There is definitely a weakness in the Apple ID structure in which folks are having their accounts hacked and cleaned out as far as itunes gift cards go. Even though Im removing my payment information as a matter of practice, this is no assurance that ones Apple ID will be hacked and someone elses cracked CC information is installed to make purchases.
    Compounding this problem is the lack of being able to escalate these events to have a chat with a live person
  • by Perchance2Dream,

    Perchance2Dream Perchance2Dream Mar 11, 2011 4:22 PM in response to Perchance2Dream
    Level 1 (0 points)
    Mar 11, 2011 4:22 PM in response to Perchance2Dream
    Still no response from Apple!

    Maybe it's an inside job, with Apple or one of their agents? The thieves get on the credits pretty quick - it's like they know when and who activated a card.

    Left a message with FastCard, the gift card manufacturer, as well.

    If no response from Apple by Monday, will report to the RCMP. A class action suit is an alternative - imagine the contingency on this one!

    The terms of service will not protect Apple if their employees are stealing from people.
  • by JK73,

    JK73 JK73 Mar 13, 2011 4:01 PM in response to ashes123
    Level 1 (0 points)
    Mar 13, 2011 4:01 PM in response to ashes123
    I got hit with the Texas Hold Em fraud...$50 refunded relatively quickly from Apple.

    I had also downloaded Doodle Truck a few days before that.
  • by Carl Johnson,

    Carl Johnson Carl Johnson Mar 13, 2011 4:59 PM in response to stereocourier
    Level 1 (80 points)
    Mar 13, 2011 4:59 PM in response to stereocourier
    Same thing here. Had a LOT of money taken out of my account yesterday (I normally know better than to store much in my account, but I had a huge Coinstar redemption). Same thing with changing my address to Towson, MD, and the zip code, but they didn't change the phone number. I didn't have a credit card linked to my account, mercifully. But I also don't have a phone or anything other than my home computer that accesses the Apple store -- so the hack has to be getting the information from Apple. Let's see how they resolve it. I'm surprised I even noticed it so quickly, I don't look at the Apple store very often.
  • by bmerri19,

    bmerri19 bmerri19 Mar 13, 2011 10:10 PM in response to Carl Johnson
    Level 1 (0 points)
    Mar 13, 2011 10:10 PM in response to Carl Johnson
    Add me to the Hongbin Suo list for a fradulent "Texas Holdem" app purchase along with 1,700,000 chips. Luckily no credit card on file, only drained $50 worth of gift card credits. Requested a refund and changed my password.
  • by eryoung,

    eryoung eryoung Mar 14, 2011 7:42 AM in response to Carl Johnson
    Level 1 (0 points)
    Mar 14, 2011 7:42 AM in response to Carl Johnson
    I had my account hacked yesterday, but just got the email receipt this morning. $45 taken from my store credit! Three games all from gamesislive.
  • by Terrence,

    Terrence Terrence Mar 14, 2011 12:22 PM in response to elsieraven
    Level 1 (10 points)
    Mar 14, 2011 12:22 PM in response to elsieraven
    Could you post for the rest of us what version of itunes that you are running when this happend? In the past 2 weeks a updated version of itunes was pushed out. I am running version 10.2.1(1) currently. When I had updated from the previous version of itunes, I think I recall reading that this latest version has 60 some odd security fixes.
  • by Carl Johnson,

    Carl Johnson Carl Johnson Mar 14, 2011 12:29 PM in response to Terrence
    Level 1 (80 points)
    Mar 14, 2011 12:29 PM in response to Terrence
    I had just upgraded to 10.2.1(1) the day before this pilferage, so the problem was not fixed by this update. I can't imagine that the hacking takes place anywhere other than at Apple's end. Or is the iTunes connection not secured?
  • by Terrence,

    Terrence Terrence Mar 14, 2011 12:44 PM in response to Carl Johnson
    Level 1 (10 points)
    Mar 14, 2011 12:44 PM in response to Carl Johnson
    Hi Carl. Thanks for the quick response. I was curious knowing that there was a recently updated version of itunes that was pushed out. apparently the app didnt fix that. The next question is what AV software do you use? I use MacScan to see if some sort of spyware was installed. I did run iAntiVirus, but didn't recall if it had picked up anything. My event happened around the 1st week of Nov of 2010 when I was traveling in China. When in China, i tried to download a track or 2, but that was when the Apple software balked at me downloading any track displaying that my apple id had been disabled. This didnt become an issue for me until i purchased an iphone4 and could not download any free apps for my itunes saying that my apple id had a problem. To fix that, I had to deal with applecare and do this email back and forth to resolve. My situation appears to have been resolved as of this date and probably before the end of the day is for me to document all the stuff that I have done to secure my system, and then.. to buy a small gift card to see if I can lure someone to take the bait. A continuing story. BTW. I was interviewed for a story that threatpost(dot)com is doing on what we have been experiencing here. Apparently something similar had happened in itunes a year ago. I make copies of the thread here on a frequent basis, so I have a hard copy backup. The purpose is should this be yanked, I have something more than my word and recollection as to what is going on here. It is my hope that I the local apple sales rep will come to the local Apple users group and have an official statement from Apple about what is going on here.
  • by brad p,

    brad p brad p Mar 14, 2011 1:02 PM in response to Terrence
    Level 1 (4 points)
    Mac OS X
    Mar 14, 2011 1:02 PM in response to Terrence
    i was using mac and windows of itunes
    mac 7.x
    window xp, latest ver. of itunes

    i think its the gift card thing, that seems to be a common thread in the hacks

    i still cannot use the itunes store... on mac or ipod, but i can log in using a mac that was not involved with my fraud buys..this may not be connected.. not sure..

    Message was edited by: brad p
  • by Terrence,

    Terrence Terrence Mar 14, 2011 1:06 PM in response to brad p
    Level 1 (10 points)
    Mar 14, 2011 1:06 PM in response to brad p
    That is my observation. While someone may get into your account and poke around, the only way for them to easily to use up any money that may be sitting in the account is from the gift card. When unauthorized purchases were made on my account, the hacker had changed my CC information to a MasterCard that belonged to someone else. But my big beef is, how is someone able to log into my apple user id in the 1st place. Is this an inside job? Is access to ones account being done with spyware? That is the real issue for me.
  • by Carl Johnson,

    Carl Johnson Carl Johnson Mar 14, 2011 1:13 PM in response to Terrence
    Level 1 (80 points)
    Mar 14, 2011 1:13 PM in response to Terrence
    I haven't run an antivirus since I switched to OS X about 10 years ago. It's a good suggestion since I'm having a problem (maybe), so I'll let you know after I've run a scan if it finds anything.
  • by Jerremy Jones,

    Jerremy Jones Jerremy Jones Mar 14, 2011 1:36 PM in response to Carl Johnson
    Level 1 (55 points)
    Mar 14, 2011 1:36 PM in response to Carl Johnson
    Hi all,

    My dad just received an email receipt from the iTunes store for 2 purchases of the same $19.99 app that others have listed:

    帝國 Online, 23400銀幣禮包, Seller: GAMEISLIVE CORPORATION LIMITED

    He also had a gift card balance that covered the purchase. He used the iTunes Store purchase history section to report the problem.

    Looks like this guy figured something out - many of you are having the same issue. This app, and a gift card balance.

    Hope Apple takes care of this quickly - and reverses this fraudulent charge on my dad's account.

    J
first Previous Page 9 of 131 last Next