Want to highlight a helpful answer? Upvote!

Did someone help you, or did an answer or User Tip resolve your issue? Upvote by selecting the upvote arrow. Your feedback helps others! Learn more about when to upvote >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

I just received an email...

I just received an email from iCloud customer care saying Dear User,


Your E-mail account has exceeded its limit

UPDATE HERE


Thanks.


I think it is very suspicious and I was just wondering if this a real email or do I just delete it. I have not clicked the link at all so I am not worried about that but I just think it is very weird.


Thanks for any help you can give me.

Posted on Jan 1, 2014 5:03 PM

Reply
10 replies

Jan 20, 2014 6:00 PM in response to emzjb

This one slipped right past iClod as legit.



Even fooled Mail's junk filter.



I hardly ever use @me.com, if at all.

I'm sticking with @mac.com.





From: Apple Support <ca.appleiiid@icloud.com>

Subject: There is a problem with your account !

Date: January 20, 2014 6:09:03 PM EST

To: @hotmail.com, @gmail.com, @gmail.com, @hotmail.com, @gmail.com, @autonum.ca, @gmail.com and 93 more…

Cc: Support@Apple.com

Return-Path: <ca.appleiiid@icloud.com>

Received: from st11p06mm-asmtp002.mac.com ([17.172.124.250]) by ms05541.mac.com (Oracle Communications Messaging Server 7u4-27.08 (7.0.4.27.7) 64bit (built Aug 22 2013)) with ESMTP id <0MZQ009ZZ2Z9HQB0@ms05541.mac.com> for ME@me.com; Mon, 20 Jan 2014 23:09:09 +0000 (GMT)

Received: from st11p06mm-spool002.mac.com ([17.172.125.244]) by st11p06mm-asmtp002.mac.com (Oracle Communications Messaging Server 7u4-27.08(7.0.4.27.7) 64bit (built Aug 22 2013)) with ESMTP id <0MZQ00GBU2Z8YI00@st11p06mm-asmtp002.mac.com> for ME@me.com (ORCPT ME@me.com); Mon, 20 Jan 2014 15:09:09 -0800 (PST)

Received: from localhost ([17.172.124.222]) by st11p06mm-spool002.mac.com (Oracle Communications Messaging Server 7u4-27.01(7.0.4.27.0) 64bit (built Aug 30 2012)) with ESMTP id <0MZQ009RJ2Z83K90@st11p06mm-spool002.mac.com> for ME@me.com (ORCPT ME@me.com); Mon, 20 Jan 2014 23:09:08 +0000 (GMT)

Original-Recipient: rfc822;ME@me.com

X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.11.87,1.0.14,0.0.0000 definitions=2014-01-20_03:2014-01-20,2014-01-20,1970-01-01 signatures=0

X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 suspectscore=0 phishscore=95 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=7.0.1-1308280000 definitions=main-1401200178

Sun-Java-System-Smtp-Warning: Lines longer than SMTP allows found and wrapped.

X-Mailer: iCloud MailClient1U43 MailServer1U25.15099

X-Originating-Ip: [41.141.9.159]

Message-Id: <22edd39c-c974-49b5-9407-7d96835d5393@me.com>

Content-Type: multipart/alternative; boundary=Apple-Webmail-42--5c302d6e-1063-4d8b-9b19-cbcd8f407af8

Mime-Version: 1.0





















Information Regarding Your account:





Dear Apple Member:



Attention! Your Apple account has been limited!



As part of our security measures, we regularly screen activity in the Apple system.We recently contacted you after noticing an issue on your account.We requested information from you for the following reason:



Our system detected unusual charges to a credit card linked to your Apple account.



Reference Number:

PP-259-187-991.



Once you log in, you will be provided with steps to restore your account access. We appreciate your understanding as we work to ensure account safety.



Click Reference Number to activate your account

May 18, 2014 11:22 AM in response to John Galt

I agree it does appear as spam and very possibly still is however, I have some variations which do not represent spam.


Initially I thought SPAM. However I looked closer at it as I have previously had issues with iplanet web server being affilated to my Mobile Phone Data Usage (I would try to set alerts and was prompted to enter a user name and password for an es.providername.com iplanet web server, which I believe is an earlier take on the Oracle communications Server). My service provider couldnt even answer what an iplanet web server was and why it was linked to data usage on my accounts and their platform. As it turned out my phone services were subject to a hack and my business call traffic filtered etc. Needless to say when I noticed the OCMS i immediatly watched every email header, returned my machine to factory settings and set up a new apple ID. Changing setting and not allowing various processes which my mac wanted me to confirm resulted in detailed information including IP details (among other info) of another provider & specific server details to which I am very familiar with as a result of my previous investigations. There is no way that this was spam as spam wouldnt be running through the provider nor the experts that were a part of my previous issues. To support this my ISP's SMTP address simply does not work. Infact the only SMTP that will allow mail to be sent is my icloud account. Knowing that the folks at the cause of my malicious BS have full access to apple ID's and telco records I had assumed that once again I was the subject of a hack...


While this explanation maybe flawed (im not a tech guru, just a business operator), it did make sence considering the links to previous issues and the high level access available to those attacking me. It also sounds like im a little nuts (im used to that - I have been dealing with this maliciosu BS for 2.5 years) the fact is that MY ISP is not the same as the one reflected by the IP & otehr data which links this event to a confirmed previous event. The 2nd ISP is CLEAN and is a datacentre for governement departments so is not a great choice for spamers. This being said though criminals all over the world ensure that they own such assets so it is possible that this datacentre is off...


Anyway, Im interested to hear what the EXPERTS on this chat think...

I just received an email...

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.