stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 84 of 131 last Next
  • by totallybilal,

    totallybilal totallybilal Feb 29, 2012 5:21 PM in response to YUKON_HO
    Level 1 (0 points)
    Feb 29, 2012 5:21 PM in response to YUKON_HO

    The exact same thing happened to me this morning, this was Apple's response:-

     

    Dear xxxx,

     

    I am glad that you found your way to the iTunes Store Support, my name is Julian and I am going to assist you today.

     

    I am sorry to hear that there were unauthorized purchases made with your Store Credit

     

    To prevent further purchasing, I've disabled the iTunes account that was using your store credit.

     

    For specific instructions on how to authorize and deauthorize a computer to play your iTunes Store purchases, please read the following technical support article:

     

    http://support.apple.com/kb/HT1420

     

    If you need further assistance or if you are concerned about your account security,

    please feel free to contact me, I will be happy to help.

     

    Kind Regards,

     

    Julian

     

    iTunes Store/Mac App Store Customer Support

     

    What kind of response is this, I want my money back! I know for sure I'll probably never buy anything from Apple again.

  • by NightWine,

    NightWine NightWine Feb 29, 2012 6:49 PM in response to stereocourier
    Level 1 (0 points)
    Feb 29, 2012 6:49 PM in response to stereocourier

    I have now been Hacked first time ever, linked to my Paypal account. Pleasant afternoon of changing all passwords, scanning my system for possible intrusions. I found nothing. Email from Apple saying activity not linked to my account previously, so why did they authorize it? Sheeesh nearly 55 bucks lost, said they were gonna send it back to me though.

     

    Hackers got some stupid apps, in Chinese I don't have an Iphone so none of them would do anything for me IF I could read them.

  • by totallybilal,

    totallybilal totallybilal Feb 29, 2012 7:06 PM in response to NightWine
    Level 1 (0 points)
    Feb 29, 2012 7:06 PM in response to NightWine

    What did you do to genyour money back. They didn't credit me anything. The crook took about 55 from me too and it was some Chinese app from Adway Co.

  • by NightWine,

    NightWine NightWine Feb 29, 2012 7:27 PM in response to totallybilal
    Level 1 (0 points)
    Feb 29, 2012 7:27 PM in response to totallybilal

    I went into the account and reported the problem of fradulent charges. I haven't gotten the refund yet hope it will be soon. Also went into Paypal and did the complaint in the Resolution Center there.

  • by totallybilal,

    totallybilal totallybilal Feb 29, 2012 7:33 PM in response to NightWine
    Level 1 (0 points)
    Feb 29, 2012 7:33 PM in response to NightWine

    When I hit report a problem, it takes me to http://www.apple.com/support/itunes/

  • by bshreffler,

    bshreffler bshreffler Feb 29, 2012 7:42 PM in response to totallybilal
    Level 1 (0 points)
    Feb 29, 2012 7:42 PM in response to totallybilal

    That happened for me as well.  Report A Problem did not work correctly.

  • by bshreffler,

    bshreffler bshreffler Feb 29, 2012 7:43 PM in response to bshreffler
    Level 1 (0 points)
    Feb 29, 2012 7:43 PM in response to bshreffler

    My funds have been restored but my ID is still disabled.

  • by ChrisV88,

    ChrisV88 ChrisV88 Feb 29, 2012 10:48 PM in response to bshreffler
    Level 1 (0 points)
    Feb 29, 2012 10:48 PM in response to bshreffler

    Did Apple just automatically refund you? Or did you ask for it?

  • by AdiosAmigos,

    AdiosAmigos AdiosAmigos Mar 1, 2012 8:20 AM in response to ChrisV88
    Level 1 (0 points)
    Mar 1, 2012 8:20 AM in response to ChrisV88

    My iTunes account was just hacked, "Haypi Dragon" was downloaded, and $19.99 in in-app purchases were made via my PayPal account.

     

    When I learned of this, I was absolutely livid.  I despise Apple these days and didn't even remember that I HAD an itunes account (or that it was linked to my PayPal account).  I think the last time I used it was back in '06 or so.

     

    Apple of course locked my account after the fact, and now they are brushing me off because I've stated that I have no interest in it being unlocked (can you blame me? - I have no plans to purchase anything from Apple in the future, and I'd rather delete my account entirely, but that might be problematic for the whole resolution process.. plus, I couldn't post here).  At this point Apple keeps telling me to "talk to PayPal" to get my money back, that the ball is in PayPal's court.  *However*, I started a PayPal dispute within minutes of this happening and five days later PayPal is still "Awaiting other party's response."

     

    In terms of customer service, is acting like a two-bit eBay hustler of counterfeit products shipping from Hong Kong, not the world's most valuable company (yes, literally - it makes me cringe to type that). 

     

    The problem is that they simply think they are gods at this point, and with more and more money rolling in faster and faster each day, security breaches or no, why would they care to take a serious stand (especially when that would likely draw more attention to the matter) on the fraud? 

     

    Theft is beyond the pale, though.  I'm going to take this as far as I can with PayPal.  I have the emails from itunes explaining that they've 'cancelled the charges,' when they've done absolutely nothing, and the withdrawal was posted to my bank account two days after they made that claim.

  • by Doc2Bx2,

    Doc2Bx2 Doc2Bx2 Mar 1, 2012 8:34 AM in response to AdiosAmigos
    Level 1 (0 points)
    Mar 1, 2012 8:34 AM in response to AdiosAmigos

    Just found out our account was hacked in the middle of the night.  I agree with several other posters that it is very frustrating to not be able to find a phone number, where you can talk to a live person instead of a computer.  We have filed the online "dispute" so hopefully that will get resolved quickly.  So far, we know of about $60 and are hoping no more charges show up.  Here is my larger concern.  My family uses icloud, so an unknown program showed up on all of our phones and computers with the "chinese" writing several others have mentioned.  I am now afraid that it is a Trojan horse of some kind and can't get a hold of anyone to find out.  I am posting this from an outside computer and a new AppleID because we don't want to use any of our Apple products for fear of what else might get hacked.  We use solely Apple products in large part to avoid these kind of issues.  We are very careful with passwords and do not open anything that is slightly fishy to try and avoid security issues.  With the number of people getting hacked.  It sounds like iTunes was what was hacked not the individuals, but again don't want to take any chances.  I plan to go the the Apple Store as soon as I get off work so they can hopefully give me more information about the downloaded program.  However, a lot of damage can be done in a matter of hours.  Does anyone have any additional information about the items being downloaded in "chinese" or whatever language it is?  Has anyone else had these programs show up?  Any other suggestions of what to do?  Obviously we have already changed passwords. 

  • by bshreffler,

    bshreffler bshreffler Mar 1, 2012 9:19 AM in response to ChrisV88
    Level 1 (0 points)
    Mar 1, 2012 9:19 AM in response to ChrisV88

    I had to ask for my refund. The only automatic thing that occurred is that I received a message letting me know that a purchase was made from an unauthorized device.  Weird that Apple let the purchase go through from an unauthorized device isn't it!! What is the point of authorizing them if that act means nothing.  If the purchase were rejected because the device was not registered, we wouldn't be having this discussion right now would we!

  • by YUKON_HO,

    YUKON_HO YUKON_HO Mar 1, 2012 9:21 AM in response to Doc2Bx2
    Level 1 (0 points)
    Mar 1, 2012 9:21 AM in response to Doc2Bx2

    @ Doc2Bx2

     

    Most certainly you delete the "chinese" program from icloud. More importantly untill Apple goes through the usual routine of enabling disabling your account you may want to remove all your credit card info from itunes and pay-pal .

     

    It seems like most of these hackings are taking place through itunes and pay-pal. It doesn't seem like a very sophisticated trojan type attack (but there are always buts).

     

    If you follow the begining of this thread you will find that this has been going on for some time now. It has been reported that at some point many itunes accounts were auctioned at nominal prices in China, I do not know how authentic that news is though.

     

    http://www.zdnetasia.com/chinese-auction-site-touts-hacked-itunes-accounts-62205 509.htm?tag=mncol%3Btxt

  • by MadScientistZ,

    MadScientistZ MadScientistZ Mar 1, 2012 12:14 PM in response to stereocourier
    Level 1 (0 points)
    Mar 1, 2012 12:14 PM in response to stereocourier

    Am I the only one to notice that every time this happens the money is used to buy a Chinese app on an 'unauthorized device'?

     

    Granted, I've got a PhD in computer science, but I think it would a very easy fix (2 lines of code max) to stop any transaction that is:

     

    1. A Chinese game
    2. Downloaded to unauthorized device
    3. When the account holder is located in the US or UK.

     

    Just sayin'.

     

    World's most valuable company, huh?

  • by sharon172,

    sharon172 sharon172 Mar 1, 2012 1:23 PM in response to Doc2Bx2
    Level 1 (0 points)
    Mar 1, 2012 1:23 PM in response to Doc2Bx2

    Doc - I had the same thing happen.  When I told the guys at the Apple Store, they were dismayed and a bit defensive.  I'm curious how your Apple Store people react.

  • by Doc2Bx2,

    Doc2Bx2 Doc2Bx2 Mar 1, 2012 2:33 PM in response to sharon172
    Level 1 (0 points)
    Mar 1, 2012 2:33 PM in response to sharon172

    Thanks to everyone that replied to my post.  Amazingly, we have already gotten a response from Apple to credit the money back.  So Kudos to them for that!  However, shame on them for continuing to allow this to happen.  I've seen comments going back 2 years about very similar incidents.  I agree with MadScientistZ that you would think it would be an easy fix.  If nothing else, how about an option that we can select that says if someone tries to access your account from an unknown device, would you like us to contact you for verification FIRST not after the fact!!!  Anyway....

     

    Sharon, were they able to provide any information?  I'm much more concerned about the download going to all our devices than anything else.  I'll update everyone after I've gone to the store.

first Previous Page 84 of 131 last Next