stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 81 of 131 last Next
  • by El_Pulpo,

    El_Pulpo El_Pulpo Feb 25, 2012 6:09 AM in response to stereocourier
    Level 1 (0 points)
    Feb 25, 2012 6:09 AM in response to stereocourier

    Wow so many people.  Nice to know I'm not alone, misery loves company.

  • by MadScientistZ,

    MadScientistZ MadScientistZ Feb 25, 2012 8:09 AM in response to DerexV
    Level 1 (0 points)
    Feb 25, 2012 8:09 AM in response to DerexV

    That's what I wanted to point out: I've been with MS on XBOX Live for years withtout any problems.

    I've bought on Amazon for years withtout any problems.

     

    In fact the only time my user name and password have been hacked has been on Apple's iTunes servers.

     

    Indeed, if, as Apple claims, we were all victims of a phishing attack then ALL of our accounts would have been comprimised. This clearly shows the lie of Apple's response.

  • by Carlo TD,

    Carlo TD Carlo TD Feb 25, 2012 8:18 AM in response to MadScientistZ
    Level 3 (558 points)
    Feb 25, 2012 8:18 AM in response to MadScientistZ

    Just because you go to a thearter, and see a bad movie, does not mean all movies are bad. You really have no idea how phishing works! Just because you got hit in one store, does not mean you will be hit in any other store. Here is a link to report cyber crimes. http://www.ic3.gov/default.aspx

  • by CarrieLynn44,

    CarrieLynn44 CarrieLynn44 Feb 25, 2012 11:17 AM in response to stereocourier
    Level 1 (0 points)
    Feb 25, 2012 11:17 AM in response to stereocourier

    I got hacked this moring while I slept. This is the second time I have been hacked and this being the second time... itunes is not wanting to give me a refund since I have already requested a refund. Here is fingers crossed to them realizing that this purchase wasn't made on my computer or iphone. Very frustrating. I am going to change email account linked to iTunes and hopefully not get hacked for a third time.

  • by sherman0925,

    sherman0925 sherman0925 Feb 25, 2012 1:36 PM in response to stereocourier
    Level 1 (0 points)
    Feb 25, 2012 1:36 PM in response to stereocourier

    My account got hacked as well. I have only 53 cents left.

  • by sub187,

    sub187 sub187 Feb 25, 2012 1:56 PM in response to tekchic
    Level 1 (0 points)
    Feb 25, 2012 1:56 PM in response to tekchic

    another victim here.

     

    Your Apple ID, (XXXXX) was just used to download 宠物猎人 from the App Store on a computer or device that had not previously been associated with that Apple ID

     

    anyone here can tell me what the best course of action is? i tried doing a report but everything redirects me to express lane with really doesnt have a report unauthorized purchase option.

  • by MsB2U,

    MsB2U MsB2U Feb 25, 2012 3:01 PM in response to sub187
    Level 1 (0 points)
    Feb 25, 2012 3:01 PM in response to sub187

    Thats the same app that someone downloaded from my apple ID. You have to go through express lane and email apple the problem. You can't report a problem through iTunes because it was an in app purchase. The person who got me downloaded a free game and then bought 650 gold pieces for the game. Then another 10. In total they spent $25. I did get a refund from iTunes. They initially disabled my account. And when they enabled it again I changed my password & security questions.

  • by sub187,

    sub187 sub187 Feb 25, 2012 3:23 PM in response to MsB2U
    Level 1 (0 points)
    Feb 25, 2012 3:23 PM in response to MsB2U

    Thanks MsB2U, I just got an email from apple support and hopefully get resolved soon. Do you have any idea what compromised our accounts? i dont believe to be a victim of social engineering/phishing. I've already changed my passwords to almost ALL of my online accounts just in case(almost all of them already had different passwords), but i deemed it necessary to regenerate new random passwords.

  • by MsB2U,

    MsB2U MsB2U Feb 25, 2012 3:43 PM in response to sub187
    Level 1 (0 points)
    Feb 25, 2012 3:43 PM in response to sub187

    From reading all the previous post. It seems as if the link is gift cards on people's iTunes account. It looks like the gift card numbers have compromised. It seems as if they are being compromised during manufacturing because most of the games that are being downloaded are from china. That's just my theory.

  • by sub187,

    sub187 sub187 Feb 25, 2012 3:46 PM in response to MsB2U
    Level 1 (0 points)
    Feb 25, 2012 3:46 PM in response to MsB2U

    hmmm, thanks. i've never bought any gift cards though.

  • by MsB2U,

    MsB2U MsB2U Feb 25, 2012 3:48 PM in response to sub187
    Level 1 (0 points)
    Feb 25, 2012 3:48 PM in response to sub187

    Wow! Well hopefully iTunes gives you your refund. This whole hacking situation is clearly out of control!

  • by isabel23,

    isabel23 isabel23 Feb 25, 2012 7:10 PM in response to MsB2U
    Level 1 (0 points)
    Feb 25, 2012 7:10 PM in response to MsB2U

    My iTunes account got hacked this morning too. They bought a game called 神仙道HD, then made $27 worth of in-app purchases (I assume they would have made more, but I ran out of money on my gift-card).

     

    Apple sent the following email shortly after the app was purchased:

     

    Dear [name],

    Your Apple ID, [email], was just used to purchase 神仙道HD from the App Store on a computer or device that had not previously been associated with that Apple ID.

     

    If you made this purchase, you can disregard this email. It was only sent to alert you in case you did not make the purchase yourself.

     

    If you did not make this purchase, we recommend that you go to iforgot.apple.com to change your password, then see Apple ID: Tips for protecting the security of your account for further assistance.

     

    Regards,

    Apple

     

    What I don't understand is, if they knew that it was likely an unauthorized purchase, why did they let the purchase go through? It seems like a serious flaw to me, considering how many people are getting hacked.

     

    It also makes me annoyed that the hackers are buying such stupid games.

  • by Muh,

    Muh Muh Feb 25, 2012 7:14 PM in response to stereocourier
    Level 1 (0 points)
    Feb 25, 2012 7:14 PM in response to stereocourier

    I got hacked last week as well. They got $9.65 in Dark Matter for Galaxy Empire.  Fortunately, it was only gift card money, and Apple credited back next day.  I don't even recall actually requesting a refund.  Now my account is locked and I have to figure out re-enable it.

     

    One thing I am wondering is where is this "computer or device that had not previously been associated with that Apple ID." located at? Also, how can this be gift card related?  I already entered in the gift card to my iTunes account, wouldn't the number be worthless after that?  Also, how does having a gift card # get someone access to my Apple ID and password? Just some thoughts.

  • by isabel23,

    isabel23 isabel23 Feb 25, 2012 7:17 PM in response to Muh
    Level 1 (0 points)
    Feb 25, 2012 7:17 PM in response to Muh

    There should be some sort of "only authorized devices are allowed to make purchases" option. Apple DID shut down my account, but it was already too late by then.

     

    I think you have to reset your Apple ID through iforgot.apple.com

  • by jmeharker,

    jmeharker jmeharker Feb 25, 2012 10:07 PM in response to Carlo TD
    Level 1 (0 points)
    Feb 25, 2012 10:07 PM in response to Carlo TD

    Carlo TD wrote:

     

    Just because you go to a thearter, and see a bad movie, does not mean all movies are bad. You really have no idea how phishing works! Just because you got hit in one store, does not mean you will be hit in any other store. Here is a link to report cyber crimes. http://www.ic3.gov/default.aspx

     

    Carlo, have you been reading this thread, or do you just keep popping in to troll people?

     

    My PC has not been hacked, nor am I a victim of phishing. Knowing that, how do you explain what has happened?

first Previous Page 81 of 131 last Next