stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 25 of 131 last Next
  • by ap11,

    ap11 ap11 Jun 7, 2011 2:38 PM in response to pa_drumz
    Level 1 (0 points)
    Jun 7, 2011 2:38 PM in response to pa_drumz

    My Paypal account was linked also, but thankfully they didn't take more than what was on my giftcard.  Apple replied to my e-mail over the weekend saying they would refund my $14, but tried to blame me in standard form letter.  They told me that they may not refund the money again if it happens one more time.

     

    Also, I'd like to add that the way accounts are closed and then reverified does not seem very secure.  They shut down my account, and then I had to e-mail the guy back my address and something that I have purchased from the itunes store in the past.  If someone had hacked my account, they would have had the same information, enabling them to also gain access to the account again.  Does this seem weird to anyone else?

  • by EdOzJr,

    EdOzJr EdOzJr Jun 7, 2011 2:54 PM in response to ap11
    Level 1 (0 points)
    Jun 7, 2011 2:54 PM in response to ap11
  • by MomawNadon78,

    MomawNadon78 MomawNadon78 Jun 7, 2011 3:13 PM in response to EdOzJr
    Level 1 (0 points)
    Jun 7, 2011 3:13 PM in response to EdOzJr

    It is about time. Maybe we will finally see Apple owning up to the security breach.

     

    I hope everyone who has posted in this thread emails those folks at betanews.

  • by BeShiek,

    BeShiek BeShiek Jun 8, 2011 1:35 AM in response to stereocourier
    Level 1 (0 points)
    Jun 8, 2011 1:35 AM in response to stereocourier

    Yep, same issue here. Just had the unauthorized charges pop up, on the 7th. I've reported it to various news outlets honestly, including engadget. If Apple doesn't do something soon, they better get the Sony treatment. This is ridiculous for a company as big as Apple to have such security flaws. I no longer trust iTunes frankly.

  • by imurphy,

    imurphy imurphy Jun 8, 2011 3:36 AM in response to johnfromwilmington
    Level 1 (0 points)
    Jun 8, 2011 3:36 AM in response to johnfromwilmington

    Just had he same thing happen to me.  The sequence of events;

    Unauthorised txn happened June 3rd with recweipt date of June 4th for this "Texas Poker, 1.5M chips, Developer: KAMAGAMES LTD", took €15.99 from my iTunes account. Rarely use iTunes store so spotted it accidentally & I reported it to Apple June 5th via web form & changed my password. Conf email from apple re unauthorised purchase June 7th. Reported it to Apple again via telephone support June 7th. Apple disabled my iTunes account for security reasons June 8th & I am still waiting for refund.

  • by gheidorn,

    gheidorn gheidorn Jun 8, 2011 10:27 AM in response to stereocourier
    Level 1 (0 points)
    Jun 8, 2011 10:27 AM in response to stereocourier

    I just had the same thing happen to me with KINGDOM CONQUEST by SEGA CORPORATION.

     

    Free download turned into $42 addon ... total of $46.74 after tax.  All done without my knowledge and with no device having it downloaded.

     

    I reported via email web form and haven't heard back yet.

  • by Craig Williams,

    Craig Williams Craig Williams Jun 8, 2011 10:37 AM in response to gheidorn
    Level 1 (0 points)
    Jun 8, 2011 10:37 AM in response to gheidorn

    So you willingly downloaded Kingdom Conquest and then got hacked.  My situation was that I was hacked and then the hacker downloaded KC and purchased credits for the game (using my iTunes balance and PayPal account). 

     

    I still have the KC app in my download folder, so it was never even installed. Why would they download that first if they could just buy the credits anyway.  (I'm not going to install it, BTW, but can't seem to get rid of the download.  Apparently that has to be cleared out by Apple.)

     

    Apple reimbursed my iTunes balance quickly, but I've yet to hear from PayPal/Apple on my $100 lost there.

  • by gheidorn,

    gheidorn gheidorn Jun 8, 2011 10:44 AM in response to Craig Williams
    Level 1 (0 points)
    Jun 8, 2011 10:44 AM in response to Craig Williams

    No, I didn't download KC willingly.

     

    I don't have that game anywhere on any device.

     

    (tried to update my previous post and got an error)

  • by rupertfrombournemouth,

    rupertfrombournemouth rupertfrombournemouth Jun 8, 2011 11:48 AM in response to ironMB
    Level 1 (0 points)
    Jun 8, 2011 11:48 AM in response to ironMB

    You guys think you got it bad, I got taken for over £1000 UK pounds this afternoon, fortunately my amazing bank got to me in time and have been able to stop it, I think.  Can't talk to apple on these matters, they don't have anyone to talk to, you have to send an email to which they promise a reply within 24 hours.  24 hours?  The hackers will have emptied my bank account by then.  Thank God I have got a good bank on this.

  • by CK_Alamuru,

    CK_Alamuru CK_Alamuru Jun 8, 2011 1:55 PM in response to stereocourier
    Level 1 (0 points)
    Jun 8, 2011 1:55 PM in response to stereocourier

    The very same thing has happened to me too.... I just loaded a $25 gift card over the weekend and it got ripped off completely. Guess what was the app purchased

     

    Kingdom Conquest by SegaApple_UnAuthorized_Purchases_v1.jpg

     

     

    I am waiting for Apple to respond. This is good reality check to see how good apple is on its support


  • by lordkaosu,

    lordkaosu lordkaosu Jun 8, 2011 3:45 PM in response to stereocourier
    Level 1 (0 points)
    Jun 8, 2011 3:45 PM in response to stereocourier

    I'd really like to know why it's gift card balances and Paypal being effected and not credit cards linked to the accounts.

  • by Craig Williams,

    Craig Williams Craig Williams Jun 8, 2011 4:19 PM in response to gheidorn
    Level 1 (0 points)
    Jun 8, 2011 4:19 PM in response to gheidorn

    @gheidorn: Ah, I see.  That would have been a twist in the story if you had downloaded it yourself. 

    @Rupert: Can you remove the funding source (your bank) from your iTunes account?  1000 pounds--that is bad. 

    @lordkaosu:  Apparently it is more than gift cards and PayPal.  I think any funding source tied to an iTunes account is vulnerable.

  • by cordy39,

    cordy39 cordy39 Jun 8, 2011 4:48 PM in response to stereocourier
    Level 1 (0 points)
    Jun 8, 2011 4:48 PM in response to stereocourier

    Posted this in other forum but basically same thing has happened to me.

     

    I received an itunes receipt for £10.98 for points for 'SEGA Kingdom Quest', I have never heard of this app let alone downloaded it. Luckily that was all the balance on my gift card but still shouldn't have happened and Apple better credit it back. I still don't understand how this can be happening to so many people, I only ever use that password for my itunes account and am extremely careful regarding phishing attempts and spyware.

     

    Apple had better get on top of this soon or their reputation will be in tatters for protecting customers data. This is now happening to so many people who have never downloaded any of these apps.

     

    This has totally shaken my trust in using itunes, I thought better of Apple.

  • by BeShiek,

    BeShiek BeShiek Jun 8, 2011 4:52 PM in response to cordy39
    Level 1 (0 points)
    Jun 8, 2011 4:52 PM in response to cordy39

    I no longer trust iTunes either...which is unfortunate because I've supported their software since I bought an eMac years ago. I noticed a security update and an iTunes update today on my Mac, hopefully this fixes any security holes that may have been existing...

     

    I still won't be buying any music through Apple anymore though, and this story has led to many of my friends on Facebook removing credit information from their accounts as well. You made a noob move Apple, and you aren't even trying to help us...

  • by ayogeezy,

    ayogeezy ayogeezy Jun 9, 2011 8:42 AM in response to stereocourier
    Level 1 (0 points)
    Jun 9, 2011 8:42 AM in response to stereocourier

    Same thing happened to me on the 6th of June. Same app.. Kingdom Conquest. 3 seperate transactions.

    $8.99, 65.96, and 28.95.

    i filed a dispute with paypal and contacted apple right away.

    i'm mad/sad because all of that money was just recently subtracted from my banking account, since i have it as backup on paypal. :|

     

    i contacted paypal and they cancelled all paypal authorizations and they said the chargeback will happen by atleast next week. they mentioned that it will take awhile through the bank because they have to go through federal reserve and such.

     

    hope i get the refund soon..or i will have to survive a week with just 20 dollars. college student living in a dorm over here.

first Previous Page 25 of 131 last Next