stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 62 of 131 last Next
  • by ck08,

    ck08 ck08 Dec 8, 2011 7:56 PM in response to Carlo TD
    Level 1 (15 points)
    Dec 8, 2011 7:56 PM in response to Carlo TD

    And I am sick and tired of you spewing the same garbage.  I was NOT phished, what do you not understand??  The same with most others on here.  We are not tech neophytes withs passwords called apple123.

     

    I did not click on an email asking me to reveal my password and user id so some nigerian princess can send me a million dollars.  Why cant you get this through your head????  The problem is with Apple. Do a Google search.  Amazon does not have this problem why does Apple?

     

    P.S.  Apple is more than a retailer.  If you can't figure this out for yourself you have no business giving others advice!

  • by Carlo TD,

    Carlo TD Carlo TD Dec 9, 2011 12:19 AM in response to ck08
    Level 3 (558 points)
    Dec 9, 2011 12:19 AM in response to ck08

    Really??,How do you think I feel! Phishing is not only done through an email but also as a a fake web site. And NO you would not know if your infomation is phished unless you have money stolen from you, regardless if you have a gift card, visa, mastercard, paypal, discover, or amex card. And Yes, i believe that is what is going on here. I understand you are calling me ignorant, but that is ok, because by the definition of the word, I have

    lack of knowledge or information: he acted in ignorance of basic procedures.

    But that is fine, I am willing to learn and change, so therefore my ignorance is not a bad thing.

    Perhaps you should do a search on the web. Below are some (recent) links I found:

     

    * New Scams use fake Amazon gift cards, Adobe updates to lure victims (12/06/2011)

     

    * Be on the lookout for Apple iTunes phishing email (10/31/2011)

     

    * Identifying fraudulent "phishing" email (10/12/2011)

     

    * New Phishing Attack Targets Apple iTunes, Security Firm Says (10/05/2011)

     

    * How to avoid or remove Mac Defender malware (6/8/2011)

     

    * Phishing primary cause of bogus iTunes charges (8/27/2010)

     

    * The Real iTunes Fraud Vulnerability: Gullible Users (8/23/2010)

     

    * Spam/Phishing email impersonating iTunes store (n.d.)

  • by aircool,

    aircool aircool Dec 9, 2011 1:09 AM in response to Carlo TD
    Level 1 (0 points)
    Dec 9, 2011 1:09 AM in response to Carlo TD

    Carlo TD,

     

    You obviously have some kind of connection with Apple, either that or you have failed to read through this and other threads, this is NOT Phishing that is painfully clear even to the most inexperienced.

     

    The fault is with Apple security (admitted in confidence by Apple themselves through one of their high street outlets - whether you believe that or not is of no consequence).

     

    Security is one issue and a major one at that, however the undisputed and underlying fact is that Apple are faceless with no one to speak to once their customers have lost money through their system, if I have a problem with a credit card, Paypal, Ebay or whoever there is someone there for me to speak to, Apple refuse to implement this service and in the light of this situation if they were blameless then it would be intrest to do so but they wll not.

     

    Don't you think that the fact that they instantly refund lost money an admission of liability? - Take a reality check and stop annoying people who are justly frustrated by this issue.

  • by Carlo TD,

    Carlo TD Carlo TD Dec 9, 2011 1:43 AM in response to aircool
    Level 3 (558 points)
    Dec 9, 2011 1:43 AM in response to aircool

    No. Not affiliated with Apple.

  • by aircool,

    aircool aircool Dec 9, 2011 3:17 AM in response to Carlo TD
    Level 1 (0 points)
    Dec 9, 2011 3:17 AM in response to Carlo TD

    Must be the other reason then...

  • by JaneApple,

    JaneApple JaneApple Dec 9, 2011 9:50 AM in response to stereocourier
    Level 1 (0 points)
    Dec 9, 2011 9:50 AM in response to stereocourier

    I was hacked this morning, too... same deal, Kingdom Conquest, drained my brand new gift card leaving 92cents. I have emailed Apple Support and now I see this is widespread they had better do something about it. I got an email from Apple telling me I'd made a purchase from a computer not previously authorized, so I checked. In my account, it says 1 Item Waiting to Be Downloaded... which i have not clicked on, But I can see it's a Kingdom Conquest... Same deal, I have a strong password, not shared, not phished...so Apple has a big problem here ... and they need to refund everyone this has happened to.!!

  • by CaptSkeezix,

    CaptSkeezix CaptSkeezix Dec 9, 2011 10:22 AM in response to sandyfromel paso
    Level 1 (0 points)
    Dec 9, 2011 10:22 AM in response to sandyfromel paso

    You need to contact iTunes support.  iTunes support can only be accessed via email.

  • by CaptSkeezix,

    CaptSkeezix CaptSkeezix Dec 9, 2011 10:40 AM in response to stereocourier
    Level 1 (0 points)
    Dec 9, 2011 10:40 AM in response to stereocourier

    Just took the support survey that they sent to me.

     

    Let's just say I held nothing back.

  • by hackerhunter,

    hackerhunter hackerhunter Dec 9, 2011 11:15 AM in response to aircool
    Level 1 (0 points)
    Dec 9, 2011 11:15 AM in response to aircool

    Hi,

     

    after so many inputs I get by e-mail day by day I resume:

    There is no sence to attack each other.

    The only sence is to ask apple for a statement, what about doing, to find some dayly e-mail-appearence in a normal size.

    The members of this thread are just the neck of a body with unknown volume!

    I told you: 50.000 I-tunes-accounts habe been offered at a chinese website at the beginnig of the year!

    I have not been informed about that!

    That is not ok!

     

    I did not know, that giftcards could be the aim of a hacker, now I am told and it is a serious problem.

     

    Credit-card-dates are often storaged in the account like the automatically connection with paypal and other pay-services.

     

    If one of the hackers has the possibility to browse two accounts with storaged credit card dates, the person is able to mix the creditcard-dates. So someone in Frisco pays the bill of someone in Paris all hacked by an unknown person.

     

    If you ever had your credit card dates storaged at I-tunes cancel your card for ever and ask for another card! The hackers know the numbers and some other important individual dates!

    I repeat:

    Never let the dates of your service storaged longer than your business belongs!

    After that: set to none!

     

    Your e-mail-adress:

    It is common for unserious people now!

    It is better to change for another.

     

     

    The-email-adress is not a good idea for a ID!

    I told you it is better to keep it behind and send a code for every download.

     

     

     

    This is my opinion getting e-mails day by day from this thread!

     

    But I miss an official e-mail from apple to all users, to do something like that!  

    I repeat: It is a scandal!

  • by joh3,

    joh3 joh3 Dec 10, 2011 2:57 PM in response to stereocourier
    Level 1 (0 points)
    Dec 10, 2011 2:57 PM in response to stereocourier

    My itunes account was used to purchase something called Order Chaos twice during the night for a total of about $150.  I use paypal for all itunes purchases.  Paypal was very helpful and told me I could expect a full refund.  Can anyone tell me how this could have happened and how I can prevent it from happening again?  Thanks

  • by CaptSkeezix,

    CaptSkeezix CaptSkeezix Dec 11, 2011 9:04 AM in response to stereocourier
    Level 1 (0 points)
    Dec 11, 2011 9:04 AM in response to stereocourier

    Two of my posts that have been critical of Carlo TD's comments have been removed.

     

    I didn't call Carlo names nor did I use foul language.

     

    What I did do, is suggest that Carlo stop commenting on a subject that he has no personal experience. 

     

    Thanks Apple again for stopping freedom of speech.

  • by Zenobius,

    Zenobius Zenobius Dec 11, 2011 9:26 AM in response to CaptSkeezix
    Level 1 (0 points)
    Dec 11, 2011 9:26 AM in response to CaptSkeezix

    Just a little pet peeve of mine.... the "freedom of speech" argument people throw around.... DOES NOT APPLY to companies.

    learn to read the constitution.

    Apple is not the government. Apple is a private company, they can restrict "speech" here all they want.

     

    I really need to unsub from this thread... 90%+ of the posts are total ignorance.

    Carlo is dead wrong, it's not phishing... I'll admit that *some* phishing may have been the cause of some of the account drains, but phishing is not the end-all answer.

     

    when my account was hit for the $43, until I went to apple.com to come to the support discussions... i had NEVER input the itunes password outside the APP STORE on my iPad/iPhone/iMac. Never put in my account anywhere in any website. until the APPLE website with a problem on my iMac (that was fixed) the $43 was pulled a week or so after that. Leads me to think the apple website was hacked, anonymous etc hacked others so it's possible (they warned apple of a problem also), or something with the gift cards themselves. which has happened before with many other gift cards.

     

    Apple got me the $43 back after a week or so, i'm happy. not happy it happened.. but glad it's over and has not happened since. Apple's handling of the problem after it happens, is great. but apple needs to focus on prevention though..

  • by Deborah Thacker,

    Deborah Thacker Deborah Thacker Dec 11, 2011 11:32 AM in response to Zenobius
    Level 1 (10 points)
    Dec 11, 2011 11:32 AM in response to Zenobius

    My account was also hacked. All items were for "Gift for dsadsa or sdadas", with chinese writing under it, Developer: Gameloft, Jian Lin, Beijing Elinasoft, EA Swiss Sari and RealIusion, Inc., Date 10/28/11 06:16PM, charge $29.91. My only payment for my account is a card, (no Paypal). The charge was applied to my card on 12/9/11. That's how I found it.

     

    Also had to reactivate my account recently because I wanted to updat my iPhone. Does anyone know if iPhones/iPads are suseptible?

     

    Sent email today to apple support (no human could be found), and alerted my credit card company.

     

    Deb

  • by Carlo TD,

    Carlo TD Carlo TD Dec 11, 2011 12:46 PM in response to Deborah Thacker
    Level 3 (558 points)
    Dec 11, 2011 12:46 PM in response to Deborah Thacker

    You could also file a complaint with INTERNET CRIME COMPLAINT CENTER located at http://www.ic3.gov/default.aspx (This organization works with cybercrime.)

  • by sommersc,

    sommersc sommersc Dec 11, 2011 12:55 PM in response to stereocourier
    Level 1 (0 points)
    Dec 11, 2011 12:55 PM in response to stereocourier

    Just received 2 emails stating that I downloaded/purchased Kingdom Conquest on a never before registered device. Sounds like someone either phished a ton of accounts from iTunes or hacked into quite a few from some other site (PSN break-in, etc).

     

    I contacted Apple as well as some major Apple news websites.

first Previous Page 62 of 131 last Next