stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 31 of 131 last Next
  • by Peter from Islington,

    Peter from Islington Peter from Islington Jun 28, 2011 5:05 AM in response to Peter from Islington
    Level 1 (0 points)
    Jun 28, 2011 5:05 AM in response to Peter from Islington

    UPDATE!

    I have had all my credit re-embursed, and so far...no more "attacks"

  • by BMC517,

    BMC517 BMC517 Jun 28, 2011 5:49 AM in response to Peter from Islington
    Level 1 (0 points)
    Jun 28, 2011 5:49 AM in response to Peter from Islington

    Peter - How long did it take?

  • by Peter from Islington,

    Peter from Islington Peter from Islington Jun 28, 2011 6:37 AM in response to BMC517
    Level 1 (0 points)
    Jun 28, 2011 6:37 AM in response to BMC517

    I made the first report on the 25th, and got a reply on the 26th instructing me what to do.

    I made a second report of the second attack on the 26th.

    Had no response on the 27th

    Got everything sorted...so far....on the 28th

  • by mom2bret,

    mom2bret mom2bret Jun 28, 2011 10:23 AM in response to stereocourier
    Level 1 (0 points)
    Jun 28, 2011 10:23 AM in response to stereocourier

    Update--

     

    I notice the fraudulant charges on my account Sunday the 26th and reported them. Today the 28th all the money has been credited to my account and they are in the process of reenabling my account.

  • by jmattwills,

    jmattwills jmattwills Jun 28, 2011 11:19 AM in response to stereocourier
    Level 1 (0 points)
    Jun 28, 2011 11:19 AM in response to stereocourier

    UPDATE: I received an Email from Apple about 36 hrs later(reported 25th). Basically saying that they would refund my purchases despite the "all sales are final" clause.   They have reactivated my Itunes Account but I think someone has been trying again to break my password.  PAYPAL has not fixed it it on their end yet nor have they tried to take it from my Checking Account.    I mentioned in my response to Apple that they have a problem and need to address it.   Their response in Re-Activating my Itunes did not mention any Security concerns I raised with them.   

     

    I will not be keeping any payment info with them.

     

    I was hit with 3 purchases around $114. There would have been more if I hadn't been close to my phone to see the purchases.

  • by emjava,

    emjava emjava Jun 28, 2011 12:59 PM in response to stereocourier
    Level 1 (0 points)
    Jun 28, 2011 12:59 PM in response to stereocourier

    This happend to me at the end of May (KAMAGAMES Texas Poker).  Account got hacked, stole the rest of my gift card.  Worked with Apple, got reimbursed, changed my password, security question, removed my CC info...

     

    HOWEVER:  I can no longer update any of my apps, which were legitimately purchased by me, and have been working for weeks to get an answer as to why from my customer support person, Jessie.  We now have this ridiculous email relationship where she is ever so sorry for my frustration and ignores my basic question of why I can't update my apps--and how can that be fixed.  I'm sure it can't be at this point, right?  Otherwise she would have explained it.

     

    Can any of you still update your apps after your hacking?  If so, how did it work?  Just like normal--before you got hacked?

     

    It's completely angrifying that Apple is ignoring this major breach.  I am beyond ******.  I wish I had another option besides iTunes....  Sigh. 

  • by Brian13732,

    Brian13732 Brian13732 Jun 28, 2011 7:06 PM in response to stereocourier
    Level 1 (0 points)
    Jun 28, 2011 7:06 PM in response to stereocourier

    I just realized today that my account was hacked similar to the others (purchases on 6/27, 6/28, and 6/29 [tomorrow?]), all being paid through my PayPal.  Good thing PayPal noticed the odd transactions and halted payment.  They each were for about $40+, probably trying to keep below a $50 gift card style limit.  There are also currently $36 in queue, so I guess a total of five attempts at slightly less than $50 each.

     

    I called Apple, spent a long time trying to talk to a human, finally got one and she just directed me to the web site / send an email, which I did.  Now I wait 24 hours to determine the resolution.

     

    I called PayPal, and they are stopping all payment to Apple.  Yay PayPal!  From this point forward, I will be removing PayPal from my iTunes account (no fault of PayPal, they are great) and using store purchased iTunes gift cards.  Just want to limit my exposure in the future.

     

    Changed all my passwords, so that should stop any future bleeding.  Unfortunately, there are a total of four computers authorized for my Apple ID, and I only have three, so I am going to try to find one more PC to install so I can de-authorize all.  Seems odd that I can't kick one off, like I can with Netflix.

     

    On top of all this, I am out of town on vacation.

     

    The common thread was the World War app, v1.54, Seller:  Storm8 LLC was common to every one of my unauthorized purchases.  I remember updating my apps and the list showed accurate on my iPad, but somehow the app (?) must've sent my info to someone and they've been trying to buy stuff.

     

    I have not updated my apps and won't until I get this resolved through Apple and transfer over to iTunes gift cards.

     

    Good luck to all, I'm going to do some housecleaning on my apps.

  • by Brian13732,

    Brian13732 Brian13732 Jun 28, 2011 7:23 PM in response to stereocourier
    Level 1 (0 points)
    Jun 28, 2011 7:23 PM in response to stereocourier

    Couldn't edit my previous post, found this link:

    http://www.tuaw.com/2011/06/08/itunes-fraud-surge-hits-gift-card-balances-paypal -accounts/

     

    At least it makes me feel less targetted... 

  • by meimeifromhell,

    meimeifromhell meimeifromhell Jun 28, 2011 11:10 PM in response to meimeifromhell
    Level 1 (0 points)
    Jun 28, 2011 11:10 PM in response to meimeifromhell

    Update: I received my credit back within 2-3 days and the customer service was very nice even emailed back after everything to make sure everything is working fine. I am very happy!  

     

    I will say this, to be safe. Always buy a pre-paid gift card to make any purchases, that way, it is easier to take care of if anything goes wrong.

  • by lordkaosu,

    lordkaosu lordkaosu Jun 29, 2011 5:55 AM in response to meimeifromhell
    Level 1 (0 points)
    Jun 29, 2011 5:55 AM in response to meimeifromhell

    How is it safer to always use a gift card when this issue is only happening to gift card balances (and Paypal linked accounts)?

  • by lorifromharrisburg,

    lorifromharrisburg lorifromharrisburg Jun 29, 2011 6:09 AM in response to lordkaosu
    Level 1 (0 points)
    Jun 29, 2011 6:09 AM in response to lordkaosu

    Go back through the thread.  I posted on May 28/29th.  It IS happening to gift cards as evidenced by my account.  Daughter went to download songs/apps using a giftcard balance, we are trying to live on cash basis only, and it was drained.  ITunes did refund within 24 hours, I reactivated account, but as previous posters have stated and I've started doing.  We now keep a "wish list" and when we have enough to use a balance on a card we enter and purchase. 

     

    I buy a pack of smaller denominations at Sam's  Club and when we have $10 we use  a $10 card, of course you can use other amounts but that works for us with one teen and 2 adults purchasing so no loss.

  • by lordkaosu,

    lordkaosu lordkaosu Jun 29, 2011 7:46 AM in response to lorifromharrisburg
    Level 1 (0 points)
    Jun 29, 2011 7:46 AM in response to lorifromharrisburg

    I'm not real sure why you replied to me about this. That's exactly what I said; this is happening to gift card balances (in response to the previous poster saying they were going to combat this problem by using gift cards).

  • by lorifromharrisburg,

    lorifromharrisburg lorifromharrisburg Jun 29, 2011 8:11 AM in response to lordkaosu
    Level 1 (0 points)
    Jun 29, 2011 8:11 AM in response to lordkaosu

      Near the time frame I was hacked and started researching, before it became so "epidemic", credit cards were hacked as well, reading through the posts there was a trend of purchases on hacked accounts being traced to Maryland. 

     

    However the original point still stands - not having a linked account prevents any additional loss and it IS better/safer to use a gift card if used all at once, and if not, you only stand to lose the remaining balance and it involves one email/call to fix, and hopefully get your refund.

  • by Craig Williams,

    Craig Williams Craig Williams Jun 29, 2011 9:07 AM in response to lorifromharrisburg
    Level 1 (0 points)
    Jun 29, 2011 9:07 AM in response to lorifromharrisburg

    Lori is absolutely right.  Use a gift card with just as much as you need to make your purchases and do not have any additional funding sources tied to your iTunes account.  Since my account was hacked a few weeks ago, I have read horror stories about funds being drained from debit cards, credit cards (Visa and Amex) and PayPal.  If you are linked to any other funding sources besides your iTunes balance, you are vulnerable.

     

    Let me say that after my account was hacked, Apple did me right by refunding my iTunes balance (plus a couple of bucks, for some reason) and PayPal reversed the $90+ bucks that was stolen.  So I'm good now, with a new user name, changed password and security questions and no outside funding sources.  This is still troubling for so many reasons, though, mainly that this keeps happening to so many people and that Apple doesn't seem to have any comment. 

     

    I'm afraid that the story at http://china.globaltimes.cn/society/2011-01/609351.html is accurate, because it seems to follow the modus operandi of these hackers: get in, spend a little bit in small increments, and get out, without causing a disturbance.  The accounts aren't being individually hacked, but hacked in large scale and then sold one by one in China.  At first I thought that maybe the points/coins/credits within the games were being sold for profit.

  • by John Sowden,

    John Sowden John Sowden Jun 30, 2011 1:21 AM in response to stereocourier
    Level 1 (15 points)
    Jun 30, 2011 1:21 AM in response to stereocourier

    Hello everyone,

    Sadly, I have to add to the list. I awoke this morning with three e-mails from Apple.

    1)

    Hello,

     

    The following information for your Apple ID XXXXXXX was updated on 29/06/2011:

     

    Credit card

    If these changes were made in error, or if you believe an unauthorised person accessed your account, please reset your account password immediately by going to iforgot.apple.com.

     

    To review and update your security settings, sign in to appleid.apple.com.

     

    This is an automated message. Please do not reply to this email. If you need additional help, please visit Apple Support.

     

    Thanks,

    Apple Customer Support

     

    2) & 3)

    Dear XXXXXXXX,

     

    Your Apple ID, XXXXXXXXXX, was just used to purchase 帝國 Online from the App Store on a computer or device that had not previously been associated with that Apple ID.

     

    If you made this purchase, you can disregard this email. This email was sent as a safeguard designed to protect you against unauthorised purchases.

     

    If you did not make this purchase, we recommend that you go toiforgot.apple.com to change your password, then see Apple ID: Tips for protecting the security of your account for further assistance.

     

    Regards,

    Apple

     

    I know that I have not responded to any phishing e-mails or could have compromised my account in any other way. This must have been a direct hack on the iTunes Store. My credit card details were deleted and $23.99 was stolen to make this in-app purchase. Of course, I have immediately changed my password and e-mailed Apple - not easy to find out how to do this - except thanks to this thread. I phoned Apple Australia but they were powerless to help. Thankfully, no credit card transactions have resulted. I await a reply from Apple.

     

    This is a very worrying situation. I am already unhappy with Apple over dropping some vital features as a result of closing MobileMe, so now will stop being an Apple evangelist....at least until they start looking after their faithful customers better!  Let you know if I get my credit back!

first Previous Page 31 of 131 last Next