stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 96 of 131 last Next
  • by UndeadLemons,

    UndeadLemons UndeadLemons Mar 26, 2012 4:51 PM in response to UndeadLemons
    Level 1 (0 points)
    Mar 26, 2012 4:51 PM in response to UndeadLemons

    Following up, iTunes is taking care of my problem now (I emailed them yesturday)
    All though it is a one time exception, I got my money back and am in the process of having my account reenabled.

  • by keith37129,

    keith37129 keith37129 Mar 27, 2012 2:17 PM in response to stereocourier
    Level 1 (0 points)
    Mar 27, 2012 2:17 PM in response to stereocourier

    I got hit yesterday with the Kingdom Quest hack. I never downloaded the game and got hit for $90 for in-app charges. I have seen new post going back to June 2011 for this issue. Can some please fix this problem. 

  • by MadMacs0,

    MadMacs0 MadMacs0 Mar 27, 2012 2:21 PM in response to keith37129
    Level 5 (4,801 points)
    Mar 27, 2012 2:21 PM in response to keith37129

    keith37129 wrote:

     

    I got hit yesterday with the Kingdom Quest hack. I never downloaded the game and got hit for $90 for in-app charges. I have seen new post going back to June 2011 for this issue. Can some please fix this problem.

    Nobody that posts here, we're all users like you. Call Apple iTunes store.

  • by napuli,

    napuli napuli Mar 28, 2012 7:26 AM in response to stereocourier
    Level 1 (1 points)
    Mar 28, 2012 7:26 AM in response to stereocourier

    A very similar thing happen to me on Saturday March 24 2012

     

    1.  The first thing that happen on Saturday 24 is that I could not log into my iCloud Account.  I tried loging in using my iPad, iPhone, and Mac and they all failed.  Mail, iMessage, iCloud completely out.  The problem was that my password was incorrect but I was using the right password?

     

    2.  After several minutes of frustration I decided to reseat my password.  After doing this everything started working OK.

     

    3.  Three days later I get another error message asking that I update my credit card information in iTunes.

     

    4.  When I when to iTunes I noticed that some of the info like my name and street adress were right, BUT my zip and state were wrong and the last four digits of my credit card did not match what was on iTunes.

     

    5.  I decided to check my purchases and found two purchases on the 24th for two $20 gift cards that I had not authorized.

     

    6. I called my credit card company but we did not find the $40 charges so I am guessing that the gifts cards were not charge to my account.

     

    7.  I sent an email to Apple and they removed the credit card information and asked me to reset my password.

     

    8.  After reading this forum I plan to reset the secret question as well.

     

    9.  What is different about my case is that the unauthorized purchases were not charged to my credit card.

  • by pengmm,

    pengmm pengmm Mar 28, 2012 7:49 AM in response to stereocourier
    Level 1 (0 points)
    Mar 28, 2012 7:49 AM in response to stereocourier

    I just got hacked this morning. Apple was really good about giving me my credit back but I'm really concerned about the lack of information about this hack. Like many of the people here I'm more security conscious than average (firewalls, antivirus, scan my home comp and laptop weekly, never open attachments from people I don't know, have very secure passwords) yet was somehow hacked anyway. I've had my iTunes account for 10 years and have NEVER been hacked till now. Now I'm very wary about linking any kind of financial account to iTunes be it credit cards or paypal but I need to do that in order to make any kind of purchase. Not really sure what to do now. I've read on CNN that this has been going on for more than 6 months - is Apple taking any kind of action?

  • by akimbobyte,

    akimbobyte akimbobyte Mar 28, 2012 8:38 AM in response to napuli
    Level 1 (0 points)
    Mar 28, 2012 8:38 AM in response to napuli

    @napuli

     

    That's almost verbatim what happened to my account a couple of weeks ago.  What I *think* might be happening is that someone has hacked into iTunes and stolen a lot of account passwords and credit card information.  They are then hijacking the accounts and changing your contact information so you won't be notified of any purchases by iTunes.  They then try the credit card information on file with the password from your iTunes account.  If they match, their work is done and they can charge stuff to your account.  If, however, the credit card on file doesn't use the same password as iTunes, they change the credit card information to another (stolen?) credit card and change your city and state to match that credit card's billing information.  At that point, whether they succeed or fail, they are guaranteed that the account owner and the credit card owner will never see an email from iTunes since that email address has been altered.  Basically, they are using one person as a "mark" and the other person as the "fall guy".

     

    In my case, they renamed my email account then tried to use my credit card so I would never receive an email about it since it was changed to an email address that doesn't exist. 

     

    When they couldn't use my credit card (possibly because my credit card password is different than my iTunes password), I got notification from the credit card company (not from iTunes) that my billing agreement with iTunes had been terminated.  That was the tip off to me that something was wrong. 

     

    After going around with Apple and iTunes for hours, I was finally able to get in and view my account information.  That's when I found out that they renamed my email account and then linked my account to someone else's credit card and changed my street and state address (maybe to match the stolen credit card's billing address).  In this case, I was the "fall guy" and whoever's credit card they used was the "mark".

  • by ArdenEden,

    ArdenEden ArdenEden Mar 28, 2012 9:03 AM in response to stereocourier
    Level 1 (0 points)
    Mar 28, 2012 9:03 AM in response to stereocourier

    This is a huge problem and I hope you all get your issues resolved. I also hope they track this problem down and kill it at the root because this is getting beyond silly.

     

    Having contacted billing services via chat my issues have been resolved quickly and agreeably. Even had a bit of fun mocking the hacker's taste in crappy games with the representative who helped me. XD

     

    Good luck to you all!

  • by napuli,

    napuli napuli Mar 28, 2012 9:21 AM in response to akimbobyte
    Level 1 (1 points)
    Mar 28, 2012 9:21 AM in response to akimbobyte

    @akimbobyte

     

    Can you please explain what you mean by credit card password?  In iTunes you only need 1 password to get access to credit card info.

     

    What is clear is that someone got in, plug a new credit card in my account, and purchased two $20 gift cards.  My guess is that they copy the codes to make store purchases.

     

    My fear is that my credit card info got plug into another account just like someone else's card got plug into my account

     

    Maybe the thing to do is to call whatever wrong credit card company and number show up in your account and let them know what happen.

     

    I will not be able to do this now because Apple deleted the wrong credit card info

  • by akimbobyte,

    akimbobyte akimbobyte Mar 28, 2012 9:54 AM in response to stereocourier
    Level 1 (0 points)
    Mar 28, 2012 9:54 AM in response to stereocourier

    @napuli

     

    I may be wrong about that - but, for a lot of purchases, I use PayPal to check out.  To finish the check out, you have to log into PayPal to okay the purchase before the transaction completes.  I'm thinking now that doesn't happen when you buy from iTunes since they have (had) my credit card information online.

    In any event, I'm assuming they tried to use my credit card and were unsuccessful since my billing agreement with iTunes got canceled by PayPal.  OR, maybe the agreement was canceled because whoever hacked my account changed the credit card information to someone else's card.  Because, when I was finally able to look at my iTunes account information online, it showed the last 4 digits of a credit card that I don't own.  Again, I'm assuming that's why they changed the street and state address - possibly to match the information that went with that credit card.

     

    Long story short:  There's something going on and iTunes appears to be trying to cover it up.  There are too many similar posts on here for them to not be aware of it - even though they continue to tell users that the fault lies with them.  Perhaps a few Tweets to CNN or the New York Times might get some attention.

  • by MTRoads,

    MTRoads MTRoads Mar 28, 2012 12:31 PM in response to stereocourier
    Level 1 (0 points)
    Mar 28, 2012 12:31 PM in response to stereocourier

    My apple account was unsecured as well. someone made an itunes purchase for $23 to KindomConquest by sega.

  • by Carlo TD,

    Carlo TD Carlo TD Mar 28, 2012 12:51 PM in response to stereocourier
    Level 3 (558 points)
    Mar 28, 2012 12:51 PM in response to stereocourier

    I would suggest you go to the horse directly and submit a request asking them to open the topic for discussion, and investigate this matter otherwise, utimately Sega will be reported to the Japanese Authorities.

     

    https://segaofamerica.zendesk.com/entries/20589273-unauthorized-charges-to-an-it unes-account

  • by MTRoads,

    MTRoads MTRoads Mar 28, 2012 12:56 PM in response to Carlo TD
    Level 1 (0 points)
    Mar 28, 2012 12:56 PM in response to Carlo TD

    thanks for the link. that's just what I was looking for. I only lost $23. But it's looks like so many other people have as well. you'd think apple would want retribution as well.

  • by Carlo TD,

    Carlo TD Carlo TD Mar 28, 2012 1:00 PM in response to MTRoads
    Level 3 (558 points)
    Mar 28, 2012 1:00 PM in response to MTRoads

    To report crimes to the Japanese National Police the link is this:

     

    http://translate.google.com/translate?hl=en&sl=auto&tl=en&u=http%3A%2F%2Fwww.npa .go.jp%2F

  • by Carlo TD,

    Carlo TD Carlo TD Mar 28, 2012 1:28 PM in response to Carlo TD
    Level 3 (558 points)
    Mar 28, 2012 1:28 PM in response to Carlo TD

    This might be of more usefull for everyone since there is an email on this site: http://www.first.org/members/teams/cfc

     

    Message was edited by: Carlo TD

  • by MTRoads,

    MTRoads MTRoads Mar 28, 2012 1:55 PM in response to Carlo TD
    Level 1 (0 points)
    Mar 28, 2012 1:55 PM in response to Carlo TD

    Sega's Response

     

    Hi,

    This is a result of your iTunes account being hacked and the hacker using it to make unauthorized purchases. It has nothing to do with our game other than being what the hacker chose to spend your money on. You will have to contact Apple Support to get this resolved as we have no access to iTunes billing.

    Best Regards,
    SEGA Customer Support

first Previous Page 96 of 131 last Next