stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 27 of 131 last Next
  • by zerg1234,

    zerg1234 zerg1234 Jun 13, 2011 5:56 AM in response to freddiegrover
    Level 1 (0 points)
    Jun 13, 2011 5:56 AM in response to freddiegrover

    I kind of wonder about brute force though (at least after the initial hack).  My account was restored to me a few days after I reported my hacking to apple.  I changed my password and logged in to make certain that everything was correct with my account (which it was).  Then I logged off and didn't try to access my account for several days.  The next time I logged on to my account I had a message from Apple that stated that my account was locked because too many access attempts had been made.

  • by freddiegrover,

    freddiegrover freddiegrover Jun 13, 2011 6:15 AM in response to zerg1234
    Level 1 (0 points)
    Jun 13, 2011 6:15 AM in response to zerg1234

    If it only got locked once  it was probably them just trying to guess the password hoping you may only have changed one letter or something. On a different note apple still have replied to me.

  • by Chris CA,

    Chris CA Chris CA Jun 13, 2011 10:19 AM in response to zerg1234
    Level 9 (79,692 points)
    iTunes
    Jun 13, 2011 10:19 AM in response to zerg1234

    When you change your password, you also need to change your security questions.

  • by 9rabbit,

    9rabbit 9rabbit Jun 13, 2011 1:30 PM in response to zerg1234
    Level 1 (4 points)
    Jun 13, 2011 1:30 PM in response to zerg1234

    @zerg1234--

     

    My email should be on my profile -- I would love to chat with you at greater length about your experience here with APple and iTunes (and anyone else who sees this as well). I'm a reporter writing this up and the sense I am getting is that while Apple is good about compensating people a preventative measure of some kind would be appreciated. But someone tell me if I am reading this wrong.

  • by GeneS13,

    GeneS13 GeneS13 Jun 14, 2011 3:30 AM in response to zerg1234
    Level 1 (0 points)
    Jun 14, 2011 3:30 AM in response to zerg1234

    I don't think I did anything to get my iTunes account drained. I believe it's something on their end that got compromised.

     

    My password was one of those "non character repeating, number, upper case, lower case, and special character", kind of passwords. The only time I ever use my iTunes password, is when I make a purchase in either iTunes, my IPhone or iPad.

     

    If someone has the brains or resources to not only replicate iTunes or an Apple iOS App, AND trick Apple into sending me what I bought, well then I guess they deserve some praise.

     

    But again, ultimately, I believe the blame is on Apples side of the connection, not mine.

  • by donikatz,

    donikatz donikatz Jun 14, 2011 8:56 AM in response to stereocourier
    Level 1 (0 points)
    Jun 14, 2011 8:56 AM in response to stereocourier

    Another "me too". A few minutes ago I watched KingdomConquest install itself in front of my eyes and suddenly all my iTunes Store credit was gone. Grrr.

  • by freddiegrover,

    freddiegrover freddiegrover Jun 14, 2011 9:05 AM in response to stereocourier
    Level 1 (0 points)
    Jun 14, 2011 9:05 AM in response to stereocourier

    My account just got locked randomly after I changed my password. I think whoever hacked my accounts still trying into access mine. kinda worrying.

  • by kitten4444,

    kitten4444 kitten4444 Jun 15, 2011 9:55 AM in response to stereocourier
    Level 1 (0 points)
    Jun 15, 2011 9:55 AM in response to stereocourier

    I just had the same thing !!!!  Couldnt get email from my account off my iPhone, so logged on to the account from my work computer and got the error that my account was locked due to too many tries to access...I got a hold of Apple help in chat but she didnt say anything to me about this or to change my password...

     

    Then I got up the next morning and BAM - Kingdom Conquest (5 times) were purchased (but not downloaded) and all my store credit gone...I did notice my credit card info was delete and i kept it that way...

     

    So what is going on -- is it just iTunes being hacked into or is it our apple accounts?

  • by Mustangjac,

    Mustangjac Mustangjac Jun 15, 2011 10:58 AM in response to kitten4444
    Level 1 (0 points)
    Jun 15, 2011 10:58 AM in response to kitten4444

    Looks like I'm in the same boat.  Got notice this AM about some purchases on my iTunes account from Paypal, with no info as to what they were.  So I logged into iTunes and found several in-app purchases for Kingdoms at war. Totaling around $120.  I changed my password and called Apple.

     

    The rep I spoke with couldn't help me, but offered to report the incident to the iTunes support folks, and I got a confirmation email from them shortly after.

     

    I also filed a dispute with Paypal.  Hopefully I'll be refunded without too much hassle. 

     

    This whole incident is rather disturbing...

  • by 41down,

    41down 41down Jun 16, 2011 6:00 PM in response to stereocourier
    Level 1 (0 points)
    Jun 16, 2011 6:00 PM in response to stereocourier

    Well you can add me to the list of people who had their account hacked. I have no idea exactly how my account got hacked, but here I am. Though I am a bit more fortunate that most of the people here, and so far they have only purchased a single application, but they may have gotten my CC info. Reported to iTunes and my CC company, and hopefully this issue gets resolved quickly.

     

    Is this a tie in to all the other places being hacked recently, or a completely different group of hackers?

  • by NightOwl9,

    NightOwl9 NightOwl9 Jun 16, 2011 8:57 PM in response to stereocourier
    Level 1 (0 points)
    Jun 16, 2011 8:57 PM in response to stereocourier

    twice in 2 days for me!

    Kingdom Conquest cleaned out my account 2 days ago...got an email from Apple this morning saying they had refunded me, then a few hours later got another receipt from KC saying it had cleaned out my account AGAIN!

     

    I hadn't even logged back in after the refund....but had changed my password after the inital attack.

    So whatever it is, is NOT using a password to get in...must be some backdoor/inside Apple issue.

     

    Awaiting to see if I will be refunded again.

  • by TheGuyintheProjectionBooth,

    TheGuyintheProjectionBooth TheGuyintheProjectionBooth Jun 16, 2011 9:31 PM in response to stereocourier
    Level 2 (208 points)
    Mac OS X
    Jun 16, 2011 9:31 PM in response to stereocourier

    I never noticed a "None" button on the payments page for method of payment. Good it's there, because I just used it.

     

    With all this current negative activity on a platform that was supose to be buttoned up a long time ago. I don't have ANY confidence in iCloud. That will be a hackers paradise.

  • by Brad Schurman,

    Brad Schurman Brad Schurman Jun 16, 2011 11:25 PM in response to TheGuyintheProjectionBooth
    Level 1 (135 points)
    Jun 16, 2011 11:25 PM in response to TheGuyintheProjectionBooth

    Thats because you arent ALLOWED to see it when you set up the account the first time: it isnt shown.

     

    I just set up my niece on a new iPad she got for graduating... told her right off the bat to never give Apple CC info and DO NOT use the gift card I bought her for xmas until she had nearly the total amount of songs/apps/software in a wishlist in iTunes... and once she got that figure then only then to buy with the gift card or it will be stolen.

     

    It is not a matter of IF but WHEN you will get ripped off, for anyone using iTunes... its multiple rip offs each day by the recording of this thread alone.

     

    But back to the NONE button: you cannot have an iTunes account without first giving Apple your CC info.

     

    I hate that fact.

     

    But atleast what you can do when setting up a new account or one for your loved ones you can give a (has to be valid, it is checked before your account is activated) CC card and then IMMEDIATELY go back into your profile specs and then you see the NONE button.

     

    I deleted the CC info and chose NONE, logged out, logged back in to make sure there was no CC info and that NONE was still selected, and have been ok ever since.

     

    Whatever freaking lousy pretend EULA that Apple wants to push in my face now that apparently waives all responsibility of them for anything that goes wrong with my account or credit line if I get hacked again, they can go stuff themselves with it as I will not be paying for any song or app and not be giving them the data to allow the hackers to freely use.

     

    If I 'cant live without that song' I will do the "CC data in, purchase, confirmation slip, remove CC data right away again" routine. Apple will have no recourse and no excuse then; and they also wont be giving me the 'you were hacked once, we dont refund for hacks more than once" excuse.

     

    the stinking hackers can use their own CC info if they want to so easily and brazenly use my account to do something ********.

  • by Baba,

    Baba Baba Jun 17, 2011 6:07 AM in response to stereocourier
    Level 1 (41 points)
    Jun 17, 2011 6:07 AM in response to stereocourier

    OK! This is a big deal. I was a little naive in thinking that it was an isolated incident a year or so ago, but I have switched off the CC info button on my account page. I just went to my 'Purchased' section of iTunes and found that I have a Christian music thief (ironic or oxymoron) hacking my account. I have no idea who these artists are. The hacker must have gotten in when I had a PayPal account set up for a very short time about 4 months ago. I decided to go back to a CC for simplicity. I am going to try and retrieve the info from that period. It is creepy.

  • by donikatz,

    donikatz donikatz Jun 17, 2011 6:53 AM in response to donikatz
    Level 1 (0 points)
    Jun 17, 2011 6:53 AM in response to donikatz

    Got an email from Apple the other day that they'll be refunding me the stolen credit in 5-7 business days. But they disabled my account pending an "investigation" that "could take several days". So now I'm locked out of my iTunes account and can't even download updates to things I've already purchased!

     

    What the heck, Apple? Not only is your security garbage, but the customer is the one who gets penalized?? I already changed my password, why would you need to lock my account? Any investigation shouldn't need my account to be locked out. I am furious!

     

    I've been strongly considering switching to Android, yet been reluctant because of all the iApps I'd already bought for my iPhone. But I guess now there's nothing holding me back. Goodbye, Apple.

first Previous Page 27 of 131 last Next