stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 48 of 131 last Next
  • by coelomate,

    coelomate coelomate Sep 19, 2011 10:57 AM in response to stereocourier
    Level 1 (0 points)
    Sep 19, 2011 10:57 AM in response to stereocourier

    This happened to me just now, with a zipcode entered into my billing information that matched info posted from mid-August. It was a Kingdom sometrhing digital purchase, and it drained my giftcard balance. I've changed PWs and gotten in touch with apple. Scary stuff.

  • by POdatApple,

    POdatApple POdatApple Sep 19, 2011 3:40 PM in response to coelomate
    Level 1 (0 points)
    Sep 19, 2011 3:40 PM in response to coelomate

    Straight from the iTunes Terms and Conditions:

     

    "Apple does not represent or guarantee that the itunes service will be free from loss, corruption, attack, viruses, interference, hacking or other security intrusion, and Apple disclaims any liability relating thereto."

     

    Imagine if your bank said that! 

     

    Ordered our new Droid phones yesterday!  Bye Apple.

  • by kwmcc,

    kwmcc kwmcc Sep 19, 2011 4:56 PM in response to POdatApple
    Level 1 (0 points)
    Sep 19, 2011 4:56 PM in response to POdatApple

    In my case, I woke up on Labor Day (September 5th) to find two emails telling me that my iTunes account information had been changed.

     

    email 1:  Shipping and/or billing address, Phone number(s), Credit cards

    email 2:  Apple ID, Password, Email address(es)

     

    I couldn't log in, the password had been changed, the change password emails were being sent to some other address (not mine), and the secret question had been changed.

     

    By the end of the day, Apple had restored my control and reset all of the data.  I find that sort of funny ... as they didn't ask for any proof on my part.  Makes me suspect they know exactly what's going on and don't question complaints like this.

     

    I cancelled the credit card linked to the account, and they found no transactions.

     

    The next day, I received an iTunes receipt.  According to that receipt, a John ************ in Menlo Park (the name and address match a real person ... who's a director of a corporation) sent an Amy ********** a $50 iTunes gift certificate, using a credit card that doesn't match any of my cards.  "Amy's" email address is with a Chinese internet provider (jindomail).  (Why does "Peggy" in those credit card commercials come to mind?)

     

    I filed a report with the local police, who said it's outside their jurisdiction, and too small to interest anyone higher up the food chain.  So, it appears that between Apple and the authorities, there's nothing to be done.

  • by budabob07,

    budabob07 budabob07 Sep 19, 2011 7:31 PM in response to funwakinmade
    Level 1 (0 points)
    Sep 19, 2011 7:31 PM in response to funwakinmade

    I also had this happen to me.  I put a 50$ gift card and a 10$ gift card on the account.  I recieved two charges which drained my account from 60 to 0.01$.  Reporting the problem to apple has been useless.  I hope this gets resolved soon

  • by UnbrknCh8n,

    UnbrknCh8n UnbrknCh8n Sep 19, 2011 10:24 PM in response to stereocourier
    Level 1 (0 points)
    Sep 19, 2011 10:24 PM in response to stereocourier

    I've previously reported here how I had $50 in gift card money taken (Texas Poker).  Apple refunded the money.  At that time, a had a Visa debit card associated with the account, but there was no activity on the card.  I removed any credit card information from the account.

     

    Today, I heard from my bank that there has been fraudulant activity on this card (in California, not where I live).  However, it appears that these weren't on-line transactions but someone was able to use the card/number in various stores.  None of my cards are missing, and the bank is following up.

     

    While there could be a number of ways that that card number could have been stolen (through on-line purchases), I still wonder whether it is possible that it is connected to the iTunes problems.  Apple consistently says that hackers shouldn't be able to access credit card info from accounts, but a number of the thefts reported on this thread suggest that there could be more than just phishing going on, and some of these thefts could involve deeper access into the iTunes system (e.g., knowing when people have redeemed iTunes gift cards), and it does make one wonder whether credit card info could have been accessed.

     

    At this point, this is just random conjecture, but I would certainly be interested in hearing whether other victims of iTunes theft have later had problems with fraudulant activity on their credit cards.

  • by samuelfromro,

    samuelfromro samuelfromro Sep 20, 2011 7:34 AM in response to SimonJester753
    Level 1 (0 points)
    Sep 20, 2011 7:34 AM in response to SimonJester753

    Just got an email this morning that I had downloaded Kingdom Conquest when I had never heard of that app. I looked up my account and no money had been taken from the iTune card I recently added to my account (yet), but I changed my password anyway. I'm wondering if the problem is associated with another app I downloaded that stole my account info. But if so, which one? And if that is the case, won't it just steal my new password?

     

    Anyway, I'll be monitoring my bank account very closely for a while. It ***** that I have to do that, but that's the risk we take for partaking in the wonders of the digital age. As long as Apple refunds whatever money might get stolen, I'm good.

  • by OxtonWayne,

    OxtonWayne OxtonWayne Sep 20, 2011 9:14 AM in response to samuelfromro
    Level 1 (0 points)
    Sep 20, 2011 9:14 AM in response to samuelfromro

    The same has happened to me this afternoon!

     

    Very upset ive lost £15. does anyone know who i could get in touch with at apple?

     

    Thanks

  • by Peddlewin,

    Peddlewin Peddlewin Sep 20, 2011 9:23 AM in response to OxtonWayne
    Level 1 (0 points)
    Sep 20, 2011 9:23 AM in response to OxtonWayne

    I used their contact form. I have the link and some more detail here: http://opensourcemarketer.com/9314/how-is-apple-itunes-being-hacked/

  • by OxtonWayne,

    OxtonWayne OxtonWayne Sep 20, 2011 9:31 AM in response to Peddlewin
    Level 1 (0 points)
    Sep 20, 2011 9:31 AM in response to Peddlewin

    Thank you for the information. Does anyone know where i can get to the contact form to report this please?

     

     

    Thanks again

  • by Peddlewin,

    Peddlewin Peddlewin Sep 20, 2011 10:10 AM in response to OxtonWayne
    Level 1 (0 points)
    Sep 20, 2011 10:10 AM in response to OxtonWayne

    wow. I just checked and the form I used now redirects to the "express lane" page. I searched but could not find the same form again.

  • by msacha1121,

    msacha1121 msacha1121 Sep 20, 2011 3:26 PM in response to Peddlewin
    Level 1 (0 points)
    Sep 20, 2011 3:26 PM in response to Peddlewin

    Another hacked account here. Woke up this morning to discover that someone had updated my billing address to the mythical city of "Flushing, California", and credited ~$80 worth of store credit to "Kingdom Conquest". No activity on my credit card, which is a good sign... also hoping that Apple is receptive to giving me my money back.

     

    ...I don't think I'm storing credit card information on iTunes anymore.

  • by jevonfromantelope,

    jevonfromantelope jevonfromantelope Sep 20, 2011 9:18 PM in response to gte222s
    Level 1 (0 points)
    Sep 20, 2011 9:18 PM in response to gte222s

    I got hit with over $600 in charges this morning!  I had paypal tied to my account instead of my credit card.  I already put in disputes with paypal and my bank is monitoring my account.  Apple rep tells me I need to show proof of the charges.  Its like WHAT?! Don't you have the records in my Apple ID?!  Way to lose a customer,  I wish I hadn't bought my MBP and my iPod now!

  • by blue_val,

    blue_val blue_val Sep 21, 2011 12:53 AM in response to stereocourier
    Level 1 (0 points)
    Sep 21, 2011 12:53 AM in response to stereocourier

    Hi, i live in France, and yesterday i've also received an email that said i had bought japan life.

    But i didn't even know it would exist!!!

    Last week i bought a new macbook pro, my credit card didn't work soi took my mother's one.

    So, after this i was lucky to delete my credit information.

    Unluckely, i had a gift card of 75€ credit on my account. So I can't make opposition on it.

    How can i do, because it makes a lot of money for a student...
    Thanks for your help...

  • by jackwheelerjr,

    jackwheelerjr jackwheelerjr Sep 21, 2011 7:23 AM in response to SocalNatv
    Level 1 (0 points)
    Sep 21, 2011 7:23 AM in response to SocalNatv

    Add me to the list as well.  They bought Pearl-in-Palm on my iPhone 4 twice for $9.99 each on 9/20/11 at 10:57pm.  I have also emailed iTunes support.  My billing address was changed to 1517 baythorn drive wesley chapel, fl. 33543-7870.  How do I get chredited back my money?  Why does Apple not just get rid of the Pearl-in-Palm game?  Is there a phone number I can called?  I have changed my iTunes Password, but it seems from the posts above that they still can access your account.  What do I do other than email support and wait?

  • by switcher98223,

    switcher98223 switcher98223 Sep 21, 2011 3:31 PM in response to blue_val
    Level 1 (15 points)
    Sep 21, 2011 3:31 PM in response to blue_val

    This happened to my daughter this week. She had a $100 gift card after purchasing a MacBook Air. Someone bought a game and in-app purchase for nearly $70.  Apple has refunded the loss, but doesn't seem to want to admit there is a security issue.  In fact, the seem to have blamed her for making an inadvertant in-app purchase.

first Previous Page 48 of 131 last Next