stereocourier

Q: iTunes store account hacked

I'm posting this just to share my story and get reactions. It's a little detailed but I thought worth sharing.

On November 23, 2010 I purchased a single song from the iTunes store for .99. I used store credit that I had from a gift card I received last year. It was the first purchase I had made since July 2010.

On November 25, 2010 I received a receipt for 2 more separate orders to my account. These were for over $50 in iPhones apps. Here's a sampling of some of the purchases:

1 eREAD isoshu, v1.5, Seller: ChengDu YueTong Internet Information Co. Ltd (17+)
2 Plants vs. Zombies, v1.3, Seller: PopCap Games, Inc. (iDP)
3 Monkey Island 2 Special Edition: LeChuck's Revenge, v1.1, Seller: Lucasfilm International Services Inc.
4 Asphalt 5, v1.2.6, Seller: Gameloft (9+)
5 Let's Golf!® 2, v1.0.1, Seller: Gameloft (4+)
6 Frames & FX for Photos, v2.5.1, Seller: Imikimi, LLC (12+)
7 Stenches: A Zombie Tale of Trenches, v1.0.1, Seller: Thunder Game Works (9+)

I do not have a credit card linked to my account, so these were made using my store credit.

I have only 1 computer authorized for my account (my personal home computer). I live alone and no one else touches my Powerbook but me. I also DO NOT own an iPhone, so I would have no interest in apps.

After I saw these bizarre purchases, I checked my account. I noticed 2 strange things: My account information had changed: My street address was correct, but city, state and zip had changed to: Towson, MD 21286-7840. I have never lived in Maryland. Also, I noticed that my password recovery answer had changed to "Murray" in response to a question about my mother's maiden name. That's decidedly NOT my mother's maiden name. Also, my birthdate had changed to an incorrect month and day.

I immediately changed my password and my recovery question/answer challenge.

I reported problems on all of these purchases and also contacted iTunes Account Support by e-mail.

Within 24 hours I received an e-mail from "Vicki" at iTunes Customer Support. She wrote:

"When reviewing over your account "name@domain.net" and the two reported orders, it shows that the content purchased within them was acquired from the computer that is currently authorized for your iTunes account. So I strongly advise that you do consult with those in your household regarding the purchases made, and the charges that resulted from those purchases."

Further:

"I have gone and reversed the charges for the two orders....You will see a store credit in three to five business days....Please note that this is a one-time exception, as the iTunes Store Terms and Conditions state that all sales are final."

I am pleased that Apple is refunding my store credit and replied so quickly.

However, it is simply impossible that these purchases were made from my computer. Again, my Powerbook is the only computer I have ever authorized to access my account, and I am the only person with access to it.

I am not sure how this happened. Any thoughts or similar experiences?

Powerbook G4, Mac OS X (10.5.8)

Posted on Nov 28, 2010 3:45 PM

Close

Q: iTunes store account hacked

  • All replies
  • Helpful answers

first Previous Page 67 of 131 last Next
  • by Tedology,

    Tedology Tedology Dec 29, 2011 9:35 AM in response to lizzie_012
    Level 1 (5 points)
    Dec 29, 2011 9:35 AM in response to lizzie_012

    Sadly, there is no phone number.

     

    I was informed that all iTunes support is "Internet-based". Translation: we can only contact them (and them through us) via email.

     

    That's just how much they value us as customers.

  • by SimonJester753,

    SimonJester753 SimonJester753 Dec 29, 2011 10:46 AM in response to Tedology
    Level 1 (68 points)
    Desktops
    Dec 29, 2011 10:46 AM in response to Tedology

    Actually, someone who posted to this thread a bit earlier got through by phone and was very satisfied with the results.

     

    Just scroll back and find the number.

  • by Tedology,

    Tedology Tedology Dec 29, 2011 4:24 PM in response to SimonJester753
    Level 1 (5 points)
    Dec 29, 2011 4:24 PM in response to SimonJester753

    That is true. When I called that number, I was connected with their general Apple store. I asked to speak to somebody in iTunes and was told that it was Internet-based only.

     

    However, perhaps it was just a case of bad luck. Maybe you'll find somebody who can get you somewhere. I certainly hope so... as nobody should have to deal with this junk.

  • by John Kranz,

    John Kranz John Kranz Dec 29, 2011 4:39 PM in response to Tedology
    Level 1 (6 points)
    Dec 29, 2011 4:39 PM in response to Tedology

    I can raise my hand and emphatically state, "I've been there." I had my iTunes/AppleID account hacked for several hundred dollars recently, as first reported here. It appears the problems are occurring either with iTunes Gift Cards or as in my case, to linked iTunes/Apple store accounts.

     

    I was able to remedy my situation with the financial instiution and Apple via e-mail as I'm sure most of you will hopefully find to be true, but it does take several days.

     

    The point I want to make, at least for linked accounts, is the lesson I learned from someone who posted here earlier. It's critical to NOT have your iTunes/Apple ID linked to any credit card or paypal account for automatic payment. That is an automatic killer and is where fraud will occur (besides gift cards).

     

    The solution offered which I now follow is a great one...although granted it takes a bit more time to do. When wishing to order something through Apple ID, go ahead and link your account to a method of auto-payment JUST FOR THAT TRANSACTION ONLY. But once you are done with that transaction, be sure to REMOVE your linked credit card/paypal account immediately so no further charges can occur without your knowledge.

     

    Yes, I understand this means it's an inconvenience to have to enter your CC information and link to your Apple ID store accound/etc., and then you have to quickly unlink it which takes a few seconds once your order is placed, but the peace of mind in not having a linked account for auto-payment is what helps me sleep much better at night.

     

    I have told all my colleagues at work to make sure they have no linked accounts for purchases (or in-app purchases). Quite a few folks did change this based on my recommendation, and none of them have been hacked ;-)

     

    I hope those of you who haven't been hacked yet and do link your accounts, will immediately unlink them. This will help keep the hackers from getting to you.

     

    Happy Holidays.

     

    John

  • by rebeccafromsm,

    rebeccafromsm rebeccafromsm Dec 29, 2011 6:38 PM in response to lizzie_012
    Level 1 (0 points)
    Dec 29, 2011 6:38 PM in response to lizzie_012

    Well, I have joined this unfortunate club. 

    I redeemed $60 in gift cards and within 24hr all but .02 was acquired

    by "Haypi Dragon coin pks."

    Not only an app I didn't have, but the 2 charges happened while I was out.

    Still trying to work this out in email land with Apple - thanks to those who have delt with this

    for the advice!

    Happy New Year!

    R

  • by swede#1,

    swede#1 swede#1 Dec 29, 2011 8:53 PM in response to rebeccafromsm
    Level 1 (0 points)
    Dec 29, 2011 8:53 PM in response to rebeccafromsm

    I find it interesting that it seems like apple is t doing anything about this, I get the feeling that the mentality they have is to just accept it and pay people back when their accounts are getting hacked, instead of doing something about it.

     

    I finally got my money back from apple/iTunes, after several hours on the phone and endless emails they finally managed to refund me.

     

    Like John said in a previous post to not have any cc or PayPal linked to your iTunes account is a good idea, not the most convenient way maybe but unfortunately the only way to be safe dealing with apple, you would think that apple would be able to find a safe way to do business with, it's almost 2012 and they can't figure out how to secure their business.

  • by Tedology,

    Tedology Tedology Dec 30, 2011 6:37 AM in response to swede#1
    Level 1 (5 points)
    Dec 30, 2011 6:37 AM in response to swede#1

    Well, I did get my $100 refunded, but now my account is deactivated still so that no unauthorized purchases can be made.

     

    In fact, no AUTHORIZED purchases, either.

     

    I've sent in an email twice now hoping they'll give me access to the money that is actually owned by ME.

     

    Glad to know the hackers have easier access to my account than I do.

     

    As I've said before...shame on Apple for not dealing with this more seriously. Or, perhaps iTunes isn't really their "money-making" department, so they don't give it as much attention as their computers, etc.

     

    In any case, I'm extremely disenchanted. If I could get my $100 back in cash, I would in a heartbeat! As it is, I'm looking to spend it as fast as possible so that future hackers won't have access to it.

  • by rebeccafromsm,

    rebeccafromsm rebeccafromsm Dec 30, 2011 8:55 AM in response to Tedology
    Level 1 (0 points)
    Dec 30, 2011 8:55 AM in response to Tedology

    Welll, according to this mornings email, they will refund the money - but have deactivated my account and chided me for not properly securing my account. 

    ***!!

    Since the first iPod came out I have had an account and NEVER had an issue!

    My electronics were home with the cat (hum... crazed kitty hacker?) when the charges were placed. 

    Um... Who's security should we be reviewing?

    I with you Tedology, extremely disenchanted.

    Now to try to reactive my account...

  • by Deborah Thacker,

    Deborah Thacker Deborah Thacker Dec 30, 2011 9:09 AM in response to rebeccafromsm
    Level 1 (10 points)
    Dec 30, 2011 9:09 AM in response to rebeccafromsm

    I just learned my apple ID has been deactivated. I'm on chat help right now to try and get activated...

  • by Tedology,

    Tedology Tedology Dec 30, 2011 9:28 AM in response to Deborah Thacker
    Level 1 (5 points)
    Dec 30, 2011 9:28 AM in response to Deborah Thacker

    Deborah,

     

    Mind sharing how/where you got the "chat" option?

     

    I went to Express Apple (or whatever it's called) and actually put in I wanted my account reactivated. And who should respond?...but the same person who had been helping me all along... but he said, "I'll need more information." Um...YOU are the one who's been helping me! Grrr...!

     

    I called 1-800-676-2775 and angrily told them I wanted to speak to a Tier 2 Senior Advisor (they can allegedly talk to various departments).

     

    It's sad, but we need to get ANGRY and demand that they treat us like valued customers.

     

    I did speak with a supervisor...and then emailed his superiors my praise. We need to show praise when it's due....but we shouldn't have to argue to get our money out of hock.

     

    Very sad.

  • by ituneslies,

    ituneslies ituneslies Dec 30, 2011 10:02 PM in response to Tedology
    Level 1 (0 points)
    Dec 30, 2011 10:02 PM in response to Tedology

    great remove of the posts mods,

    ban me as well? might as well....

  • by swede#1,

    swede#1 swede#1 Dec 30, 2011 11:21 PM in response to ituneslies
    Level 1 (0 points)
    Dec 30, 2011 11:21 PM in response to ituneslies

    @ituneslies: agreed! It's funny how the mods on apples forums always delete posts that are " uncomfortable " :-) as long as you praise apple or their products you are fine, but as soon as you have some negative input they either delete your post, give you warnings or just ban you.

     

    I have been an apple fanboy for some time now but I'm more and more leaning towards other brands and android, tomorrow I will more than likely get a Samsung galaxy s2 and ditch my iphone4, I will also get rid of my ipad2 and get an android based tablet instead, apples products just starts to feel " old " and boring to me, I was surprised that when they released the iphone4s that people stood in line to upgrade to something that really wasn't anything new!

     

    And remember, make sure to spread the word to everybody to NOT have any credit cards or PayPal linked to your iTunes account! As long as apple can't figure out a simple thing as to prevent unauthorized purchases it's too risky.

  • by ituneslies,

    ituneslies ituneslies Dec 30, 2011 11:40 PM in response to swede#1
    Level 1 (0 points)
    Dec 30, 2011 11:40 PM in response to swede#1

    well, at least now i know how its being done, it was lesson to be learned, there is no point in me

    posting the way its being done, just to have it removed. i can understand removing the accs i posted,

    as this was just to get their attention. but to have other posts removed.... (if there was nothing to hide, why remove it) God forbid if someone is trying to help in theft prevention..

  • by RMUNSON01,

    RMUNSON01 RMUNSON01 Dec 31, 2011 7:57 AM in response to ituneslies
    Level 1 (0 points)
    Dec 31, 2011 7:57 AM in response to ituneslies

    ituneslies - You keep saying 'now I know how it is being done' but I still don't get it.

     

    I saw your post where you said you were in China and being offered IDs/passwords for sale (and listed them to show specific examples).  Interesting.  But it still doesn't say HOW it is being done.  Two commets from your deleted post are: ITS YOU, thats right, ITS ALL OF YOU making the mistakes. AGAIN THIS IS YOU NOT ITUNES!!!!!!!!!!!!!!!!!!!!!!!!!!!

     

    I still want to know how it is done.  Any additional information you can provide would be most useful to the rest of us clueless folks.

  • by RMUNSON01,

    RMUNSON01 RMUNSON01 Dec 31, 2011 8:06 AM in response to RMUNSON01
    Level 1 (0 points)
    Dec 31, 2011 8:06 AM in response to RMUNSON01

    Another post that appears to have been removed (can't imagine why) was from Karen.R.

     

    In it she said 'open networks' - if people don't secure their networks, Apple can't do anything about it.  This is true.  If the vehicle they use to obtain IDs/passwords is sniffing in unsecured open networks, that would explain it.  But I never saw whereituneslies provided any explanation.  Was that in a separate post or did you just deduce it?

first Previous Page 67 of 131 last Next