stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 33 of 131 last Next
  • by Chris CA,

    Chris CA Chris CA Jul 4, 2011 9:07 PM in response to edstreiff
    Level 9 (79,692 points)
    iTunes
    Jul 4, 2011 9:07 PM in response to edstreiff

    Did you change your security questions also?

  • by edstreiff,

    edstreiff edstreiff Jul 5, 2011 5:20 AM in response to Chris CA
    Level 1 (0 points)
    Jul 5, 2011 5:20 AM in response to Chris CA

    Oh yes my security question was never a real answer its 32 characters that are totally random (me bashing the keyboard) it does include Capital Letters, Numbers, and Symbols.  I don't even know what it is but you raise a good point so I mashed the keyboard again and made it as long as Apple would allow me.

  • by wa1oui,

    wa1oui wa1oui Jul 5, 2011 5:23 AM in response to edstreiff
    Level 1 (13 points)
    iPhone
    Jul 5, 2011 5:23 AM in response to edstreiff

    Nice for security, but how are you going to reset your password when it asks  you to answer your security question? Of course you can use the email reply option, but you might be shooting yourself in the foot if you really can't answer the question...

  • by JeWoli,

    JeWoli JeWoli Jul 5, 2011 4:19 PM in response to stereocourier
    Level 1 (0 points)
    Jul 5, 2011 4:19 PM in response to stereocourier

    I received a $15 gift card purchased from a local drug store as an anniversary gift on June 10th, 2011.  On June 14th I attempted to redeem my gift.  I was unable to log in so attempted to retrieve instructions on how to reset my password via my email account.  I never got an email.  I tried having it sent to a different email account.  I never got an email.  I checked to see if my AppleID existed and was advised it did not.  I have been using the same account information since 2004.  So I tried to make a new account using the same information I had been using thinking it would get kicked back if that account already existed.  It let me sign up using ALL of the same information I have been using for years.  I attempted to redeem my gift card, but it told me it had already been used.  I wrote to support.  THREE days later I received a response that someone who had the user name beginning with 'super' had redeemed the card on the 11th (the day after my husband purchased it, but before I scratched off the redemption code).  They could not give me any more further information and they are sorry they couldn't help!!??  I replied that this was unacceptable and scanned the images of the back of the gift card along with the receipt of purchase.  THREE MORE days later I received an email apologizing, but asking if I could rescan the front and the back of the card along with the receipt at a higher quality (than PDF? ever hear of zoom?) I took them to my husband's architectural office and used their high resolution scanner and sent them back today.  I still haven't gotten any kind of refund and it's only $15!!!  I just wanted the Adele album.   For my 11th wedding anniversary   For the 10 hour car trip   'Super' and Apple can bite me, but I want compensation.

  • by indpndc_1969,

    indpndc_1969 indpndc_1969 Jul 6, 2011 6:55 PM in response to stereocourier
    Level 1 (0 points)
    Jul 6, 2011 6:55 PM in response to stereocourier

    Have not used iTunes in two months, have not even had my iPad on during that time.  This morning had an email saying I had changed my account info, so I logged in.  At the time of login, my balance was about 1/3 of what I had previously had for gift cards, which I had been saving and adding to for years.  Changed the password.  Literally watched my balance disappear after changing the password, while frantically clicking the link on each purchase to "report a problem" which just brought me to a generic contact us page with a variety of topics.  In the space of a few minutes, I went from hundreds of dollars of gift card money to $3.78.  During that time, I not only changed the password, but corrected the address, changed the reset question, and changed my email and login id.  Sent numerous emails to Apple, as of yet, not response.  Texas Hold 'em and chips are the purchase in this case, which I obviously did not make.  I am in IT, and am supremely careful with my user names and passwords as a result, but was not aware of the history on this problem since I do not allow Apple products in our organization.  Since I made no recent purchases, no recent downloads, no recent anything (even the gift cards ranged from probably 1 to 5 years old), I am baffled as to how this came to occur to me and so many others.  As Murphy would have it, I got nailed worse than the majority as well...

  • by timmyboi05,

    timmyboi05 timmyboi05 Jul 7, 2011 8:59 PM in response to stereocourier
    Level 1 (0 points)
    Jul 7, 2011 8:59 PM in response to stereocourier

    This just happened to me as well. I rarely make purchases on iTunes, maybe once a week, and only for small amounts. However, when I checked my bank statement Monday I found several large purchases. I logged into my purchase history on iTunes and found numerous purchases specifically "purchased as a gift for livemore4@qq.com. I used some software to search for the account user and was lead to a company profile in China, similar to our version of AOL. Among the purchases were Plants vs. Zombies, Street Fighter, Fish Odyssey, Pool Bar, TomTom US & Canada, and Scream 2. The purchases totaled $168.49. I've written tech support and all they've said at this point is to change my account info and cancel my card associated with the account, but they have not mentioned anything about a refund. Also, they claimed that it was somehow my fault because I must have accidentally filled out a false Apple, Inc. document. My questions is, if my account is only linked to my computer then how is it that Apple can allow someone in China make purchases using my information. I'm glad some of u have gotten a resolution, I'm hoping mine will come soon.

  • by Recrutazero,

    Recrutazero Recrutazero Jul 9, 2011 5:55 AM in response to timmyboi05
    Level 1 (0 points)
    Jul 9, 2011 5:55 AM in response to timmyboi05

    Yeah. It happen to me this morning. But they used the Texas Poker app. It is for free but the hacker used my credit (gift certificate) to buy ships to play. I never used to buy stuff from ITunes until I've got this gift and now is gone. I hope I can get it back.

    Just e-mail Apple, because their phones are out during the weekend. Waiting for the results...

  • by K@n@,

    K@n@ K@n@ Jul 10, 2011 6:39 AM in response to stereocourier
    Level 1 (0 points)
    Jul 10, 2011 6:39 AM in response to stereocourier

    Et un de plus !

     

    Des achats non autorisés ont étés effectués avec mon compte pour un montant de 48,77€ pour l'application Texas Poker v3.0.3 editeur: KAMAGAMES LTD.

     

    Je me suis aperçu du piratage de mon compte hier, suite à l'envoi de deux mails de la part Apple :

     

    "Chère/Cher JXXX GXXXX,

     

    Votre identifiant Apple, XXX@XXXXXX.fr, vient d'être utilisé pour acheter « Texas Poker » dans l'App Store à partir d'un ordinateur ou d'un appareil qui ne lui a pas été associé auparavant.

     

    Si vous êtes l'auteur de cet achat, vous pouvez ignorer ce courrier électronique. Il vous a été envoyé par mesure de précaution, afin de vous protéger d'éventuels achats non autorisés.

     

    Si vous n'êtes pas l'auteur de cet achat, nous vous conseillons de vous rendre sur la page http://iforgot.apple.com pour modifier votre mot de passe, puis de consulter les informations se trouvant sur la page Identifiant Apple : conseils pour la protection de la sécurité de votre compte pour obtenir de l'aide supplémentaire.

     

    Cordialement,

    Apple"

     

    Je me pose quelques questions:

     

    1) Pourquoi autoriser un achat sur un ordinateur ou appareil non associé auparavant ?

    2) Comment les hackers ont-ils eu mon mot de passe ?

    3) Pourquoi Apple ne supprime pas l'application en cause, compte tenu des nombreuses plaintes trouvées sur les forums et articles ?

     

    (iTunes piraté la contagion, Des comptes piratés en vente sur la toile, etc...,)

     

    e-mail envoyé à Apple en attente de réponse ...

  • by Brad Schurman,

    Brad Schurman Brad Schurman Jul 13, 2011 1:13 PM in response to indpndc_1969
    Level 1 (135 points)
    Jul 13, 2011 1:13 PM in response to indpndc_1969

    geez...very sorry this happened to you and all us other victims there is a lot of money being lost here....

     

    I tried a couple things with my Apple Store and iTunes Store accounts and made a vid. So far the protection measure has worked, and I am back to being able to get my free updates for purchased or 'free music Tuesday' items. I dont know why Apple doesnt insist on this being the standard new default set up for all 'payment info' profiles, other than I guess they wouldnt want to have CC info depart their premises so to speak.

     

    I have  not tried the quick "input CC, purchase, logout/login, remove CC" practice I mention in the YouTube vid but I am sure it is better than relying on all the other forms of payment trust in the hands of Apple, considering they have all been fully abused. It seems the local Tv news station is getting into it with investigating the ripoffs and anger some of us locals are feeling, and I only hope this brings more heat pressure and attention to APPLE'S issues, not letting the Apple iTunes Support Email dept. keep blaming us.

     

    I will post only the relevant instructional video link to iTunes:

     

    Its 3 mins. long, the practical walk through is barely a minute and some of the total, and is at http://youtu.be/BQe7xJ7qZ14

     

    Its too bad only the very small percentage of the ripped off people would know to look in this small discussion forum, and only after the attack, as opposed to someone taking precautions before they get hacked

  • by Zenobius,

    Zenobius Zenobius Jul 14, 2011 1:54 AM in response to edstreiff
    Level 1 (0 points)
    Jul 14, 2011 1:54 AM in response to edstreiff

    I just saw this thread.

     

    I also today got hit with this crap. and the same App Kingdom conquest...

    I checked the app out on iTunes, looks like many people are getting hit somehow and dinged by this app.

    But it looks like i changed my password before my $49 iTunes balance was drained...

     

    2 Hours AFTER i changed my password... Only using the new password once on my MBP to check the history and verify the credit still there... I get ANOTHER email from apple. Same story.

     

    This time it's order and chaos... and drained my balance dry before my password was reset.

     

    Sent two emails to Apple support, hope I can get my balance back.

  • by batucaves,

    batucaves batucaves Jul 15, 2011 4:01 AM in response to stereocourier
    Level 1 (0 points)
    Jul 15, 2011 4:01 AM in response to stereocourier

    I got robbed too! Had about $30 bucks in my a/c last week; only to discover yesterday I was down to $0.40. Some A*****e spent $29.97 on an "in-App purchase" after installing some game in Chinese that translates to "Romance of the Three Kingdoms".

     

    It's ridiculous that accounts still get robbed even AFTER changing the password. I've tried to "Report a problem" to Apple but that link doesn't work! At least I have no credit card linked; so the damage was limited but I'm not redeeming any cards until it is clear that the accounts are safe.

  • by modester,

    modester modester Jul 15, 2011 8:49 AM in response to stereocourier
    Level 1 (75 points)
    Jul 15, 2011 8:49 AM in response to stereocourier

    This happened to me as well.  Got the warning e-mails from Apple and checked out.  Luckily I only had about $4 in my account (no credit card linked) and they only bought 2 apps of $0.99 each.  Immediately changed my password and security question and contacted Apple to see about credit (I know, it's $1.98 but it's the principle of the thing).  No word back yet.

  • by coolspot,

    coolspot coolspot Jul 15, 2011 10:51 AM in response to modester
    Level 1 (4 points)
    Jul 15, 2011 10:51 AM in response to modester

    I just got hacked! 100.00 withdrawn from my account...

     

     

    Your Apple ID, xxx.xxx@xxx.com, was just used to purchase 明珠三国OL from the App Store on a computer or device that had not previously been associated with that Apple ID.

     

    How do I get the charges reversed?

  • by shoeman6,

    shoeman6 shoeman6 Jul 15, 2011 3:37 PM in response to stereocourier
    Level 1 (0 points)
    Jul 15, 2011 3:37 PM in response to stereocourier

    I just got hit by this.I check my email quite frequently so I saw the change in information about 5 minutes after it occured. At first I thought it might be a phishing scheme, as it directed to a different site, but then the purchases came.

     

    It seems like it's been going on for a while, apple really needs to inform its users if theres such a massive breach of security!

    Luckily i did not have my account attached to a credit card, but I lost $60 worth of GC credit I had bought and accumulated over the year, saving for apps for a new ipod touch. The thieves purchased the Order and Chaos app and then made a 56 dollar in app purchase. Leaving behind 3 cents. I changed my password, although I doubt that does much to portect the security, and emailed the situation. I also filed a complaint in the purchases through iTunes.

     

    Not only is this fustrating, it seems like it's widespread. I'm really hoping apple fixes this unnaceptable issue and reimburses us for our losses!

     

    -Update, I couldn't post this last night when I wrote  No word back from apple yet and my balance is still a glaring .03cents

  • by Faithxox,

    Faithxox Faithxox Jul 15, 2011 7:04 PM in response to stereocourier
    Level 1 (0 points)
    Jul 15, 2011 7:04 PM in response to stereocourier

    For my birthday, I got a $50 dollar iTunes card. I used about 10 dollars of it. The next morning, I checked my email, and see that 2 purchases from Texas Poker were made. Thinking my mom purchased a few apps, I went on with my day. Then, when I tried to make a purchase for another album, it said "Insufficent Amount" I then checked to see how much money I had left: 33 cents. Worried, I checked my mom's iPod. She doesn't even have Texas Poker on there. I told my mom what happened, and we called Apple, where we found out they can only handle this stuff on E-mail. We wrote Apple an email about 2 days ago, and its almost 3 days now. They said it would be within 24 hours. Should I send them another email? I really want my money back.

first Previous Page 33 of 131 last Next