stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 41 of 131 last Next
  • by sstarlight,

    sstarlight sstarlight Aug 16, 2011 4:30 PM in response to stereocourier
    Level 1 (0 points)
    Aug 16, 2011 4:30 PM in response to stereocourier

    For me, $56.98 was used to buy the app Order and Chaos and 320 runes, whatever that means. They left my street address as it was but changed the city to Palmdale, CA 93551-1929. They also removed the credit card that was on file, presumably to get around entering the security code and charged the amount to my store credit. Heard back from Apple after I sent in a report but nothing since then and my account still only has 2 bucks left in it.

  • by lewisfromprenteg,

    lewisfromprenteg lewisfromprenteg Aug 17, 2011 1:42 AM in response to stereocourier
    Level 1 (0 points)
    Aug 17, 2011 1:42 AM in response to stereocourier

    yet another person being hacked. i woke up this morning to find some emails saying that i'd purchased KingdomConquest and some in app purchases during the night on a different device. Waiting to hear back from apple but have changed my password and now feel very paranoid about the info i give apple. SOmeone needs to feature this story to get it some press attention then Apple might do something to protect it's "clean" image. I'll be emailing all the techie blogs i subscribe to!

  • by Carlo TD,

    Carlo TD Carlo TD Aug 17, 2011 1:52 AM in response to stereocourier
    Level 3 (558 points)
    Aug 17, 2011 1:52 AM in response to stereocourier

    maybe some one has access to your wifi. And as a result was able to find out your username and password, Then that neighbor logged onto your account as if it was you and orderded these things.

  • by chryselephantine,

    chryselephantine chryselephantine Aug 17, 2011 5:30 AM in response to stereocourier
    Level 1 (0 points)
    Aug 17, 2011 5:30 AM in response to stereocourier

    Another victim here. I just got an email this morning informing me that someone had made made an in-game purchase in the app "明珠三国OL", so there's $10 gone from my account (unless I get a refund). I've changed my password and security question, but I'm still pretty glad that haven't got my credit card info submitted to my apple id.

    You'd think there'd be some form of region locking or authentication - how would a Canadian resident suddenly be buying apps from China? Maybe Steam has just spoiled me for good account security.

  • by lewisfromprenteg,

    lewisfromprenteg lewisfromprenteg Aug 17, 2011 6:08 AM in response to stereocourier
    Level 1 (0 points)
    Aug 17, 2011 6:08 AM in response to stereocourier

    it looks as though it is only effecting those people who have gift card credit on their accounts. Correct me if im wrong but there must be something (at least) stopping them from using the card details saved on the account. They just end up getting cleared like mine did, but they didn't spend any money on my card, just nicked all my gift card credit!

  • by taiganambrai,

    taiganambrai taiganambrai Aug 17, 2011 6:32 AM in response to lewisfromprenteg
    Level 1 (0 points)
    Aug 17, 2011 6:32 AM in response to lewisfromprenteg

    I didn't have a gift card attached to my iTunes account, although it was set up to pay by Paypal. In a way, this seems easier, since I don't have to worry about Apple taking forever to refund my money; Paypal already has.

  • by aircool,

    aircool aircool Aug 17, 2011 11:20 PM in response to stereocourier
    Level 1 (0 points)
    Aug 17, 2011 11:20 PM in response to stereocourier

    The saga continues, my lates response to Apple/Itunes.

    Amadeus,

     

    It is fast approaching 2 weeks since Apple allowed a security breech and my account was compromised, accepted about a week ago a credit appeared on my account but this is worthless if my account has been deactivated.

     

    How can it possibly take this long to rectify this problem?

     

    I have re supplied all the information you have requested and still I cannot use my account.

     

    You will appreciate that this has occurred through no fault of my own, the responsibility for this breech sits squarely on the shoulders of Apple/Itunes and yet the response is both tardy and disjointed.

     

    Will you please activate my account and fix your security problems.

     

    Steve

     

    This really has made up my mind, before this problem I would have advocated the Apple product but now I don't really want to pick up my IPhone or Ipod, this has left a bad taste in my mouth. I accept that Apple have a major security problem but the attitude and response time is rubbish, coupled with the lack of telephone or text chat facility it makes this kind of problem a nightmare, I would have thought that Apple would appriciate their clients much more than this. I know Android is not as polished as Apple but I am never again going to purchase another of their products and I will relay my experience everywhere the subject arises.

     

    Bye bye Apple...

     

  • by lewisfromprenteg,

    lewisfromprenteg lewisfromprenteg Aug 18, 2011 5:54 AM in response to stereocourier
    Level 1 (0 points)
    Aug 18, 2011 5:54 AM in response to stereocourier

    ok so today i looged on and my Itunes account had been disabled. So i changed my password and hey presto i had my money back and had to authorise my machine again. but no reply from apple. It seems they've given up relplying to emails and just resigned to giving refunds. At least I've got my moneys back....now to spend it before it happens again!

  • by lexfrommanalapan,

    lexfrommanalapan lexfrommanalapan Aug 18, 2011 8:25 AM in response to stereocourier
    Level 1 (0 points)
    Aug 18, 2011 8:25 AM in response to stereocourier

    I'm a staff writer for Macworld. We're prepping a story on this gift card issue, and would apprecaite hearing from an affected user or two who's willing to speak on the record and for attribution. (That is, "John Smith, an iTunes customer from Nebraska, told Macworld...")

     

    Interested?

     

    Email me: lfriedman, at macworld.com.

     

    Thanks.

  • by bdrums83,

    bdrums83 bdrums83 Aug 18, 2011 9:05 AM in response to bdrums83
    Level 1 (0 points)
    Aug 18, 2011 9:05 AM in response to bdrums83

    Just an update to my situation, after using ExpressWay on the Apple site, within 48 hours I was reimbursed the transaction (this included them disabling my account and asking for verification information). By the time I had re-enabled my account, they credited me the stolen gift card just in time to purchase Lion! Overall, I had a very good support experience regarding the unauthorized transactions.

  • by lexfrommanalapan,

    lexfrommanalapan lexfrommanalapan Aug 18, 2011 9:19 AM in response to lexfrommanalapan
    Level 1 (0 points)
    Aug 18, 2011 9:19 AM in response to lexfrommanalapan

    Update: I've been inundated with folks contacting me for Macworld. I'm all set now—thanks!

  • by netguard,

    netguard netguard Aug 18, 2011 9:49 AM in response to lexfrommanalapan
    Level 1 (0 points)
    Aug 18, 2011 9:49 AM in response to lexfrommanalapan

    My account got hacked too! I lost 11.19 of the $15 gift card my aunt gave me. This happened days after I reactivated my itune store account. I was so mad until I found this forum and found out that refund is actually possible. What email should I contact apple with regarding this issue?

  • by lewisfromprenteg,

    lewisfromprenteg lewisfromprenteg Aug 18, 2011 9:53 AM in response to stereocourier
    Level 1 (0 points)
    Aug 18, 2011 9:53 AM in response to stereocourier

    go to here and follow the step by step process to get to the right place. It's an email form you fill out, they dont give you an adress!

  • by christophfromstuttgart,

    christophfromstuttgart christophfromstuttgart Aug 18, 2011 9:08 PM in response to stereocourier
    Level 1 (0 points)
    Aug 18, 2011 9:08 PM in response to stereocourier

    Also i've got several mails today in the morning, that some orders where made by my itunes store.

    all buyed apps are from KAMAGAMES LTD ... Chip15M, Chip150M, Chip150M and some Texas Poker PRO...

     

    all in all there's are a amount of 211 EUR

     

    I have deaktivated all Computers in iTunes and reset the Apple-ID Password... but what can i doo since?

  • by bdellasc,

    bdellasc bdellasc Aug 18, 2011 11:15 PM in response to stereocourier
    Level 1 (0 points)
    Aug 18, 2011 11:15 PM in response to stereocourier

    Before heading to bed tonight, I saw a few e-mails from Apple verifying my recent purchases on iTunes. I hadn't ordered anything recently from iTunes. I lost about $74 in GCs from my account - ERRRRR.

     

    When I launched iTunes to verify my account balance, over 150 tracks of music began downloading to my library...I paused all the downloads, got right onto apple's site, and changed my password.

     

    I also had an e-mail saying:

    "iTunes Store has cancelled a Billing Agreement with you.


    Description: iTunes Music Store purchases.


    To manage your Billing Agreement, log in to your PayPal account, go to your Profile, and click My money. You can choose your payment method and, if you wish, cancel your Billing Agreement in the "My preapproved payments" section..."

     

    And another:

     

    "Hello,

     

    The following information for your Apple ID xxxxxxx@xxxxxxx.com was updated on 08/19/2011:

     

    Shipping and/or billing address
    Credit card

    If these changes were made in error, or if you believe an unauthorized person accessed your account, please reset your account password immediately by going to iforgot.apple.com.

     

    To review and update your security settings, sign in to appleid.apple.com.

     

    This is an automated message. Please do not reply to this email. If you need additional help, visit Apple Support."

     

    And a third:

    "

    Dear xxxxxxxxxxxx,

     

    Your Apple ID, xxxxxxx@xxxxxxx.com, was just used to purchase The Matrix (Music from the Motion Picture) by Various Artists from the iTunes Store on a computer or device that had not previously been associated with that Apple ID.

     

    If you made this purchase, you can disregard this email. This email was sent as a safeguard designed to protect you against unauthorized purchases.

     

    If you did not make this purchase, we recommend that you go to iforgot.apple.com to change your password, then see Apple ID: Tips for protecting the security of your account for further assistance.

     

    Regards,

    Apple"

     

    I have since reset my iTunes password and e-mailed them via the Express Lane page posted earlier in this thread. This is so maddening! I'm just glad it was GCs and not a credit card on file.

     

    Where is this security breach???

first Previous Page 41 of 131 last Next