My devices have been hacked. What do I do?

i was using my ipad a short while ago when suddenly it locked itself, and was askiwhich I'd never previously set up. I went to check my phone and there was a message on the screen (it's still there) saying that my device(s) had been hacked by 'Oleg Pliss' and he/she/they demanded $100 USD/EUR (sent by paypal to ****) to return them to me.


I have no idea how this has happened. I am not aware of having been exposed to malware or anything else, although i did recently purchase some new apps - perhaps one of these has something to do with it? I don't know. I am not sure what avenue has been used to reach my devices - I'm about to use my husband's laptop to check through some of my accounts (gmail, etc) and see if there is any clue there.


Has this happened to anyone else? What can or should I do? Many thanks

<Email Edited by Host>

iPhone 5

Posted on May 26, 2014 4:57 AM

Reply
456 replies

May 27, 2014 8:23 PM in response to veritylikestea

Let collect somewhere information together to understand trends.

My information:

4 Apple devices on one Apple ID account (macbook, iphone #1, iphone #2, ipad). Find My Phone enabled.


iphone #1 was bought into UK 4 years ago and activated overseas - no attempts to lock it

iphone #2 was bought in Sydney and activated in Australia 1.5 years ago and was hacked and locked

ipad was bought in the USA and activated overseas (5 years ago) - no attempts to hack it

macbook was bought in USA and activated in Australia less than year ago - was attempt to lock it


So I clearly see that devices which were hacked are not connected to Apple ID and password. Even if hacker had access to my Apple ID, he locked only devices which were activated in Australia. Devices on this Apple account which were activated overseas were not locked.


Becase it was a massive attack, they couldn't use manual access... Looks like they use some script and used list of devices to do it.

My personal opinion - may be Apple API was hacked and hacker didn't actually had passwords?

May 27, 2014 8:42 PM in response to marumurak

To marumurak:

no, iphone was activated into home network, but macbook was activated in work network (our corporate network doesn't have connection to internet in Australia, it connected to USA via VPN and has Internet gateway there).

All my devices are working in my home wifi and in work network both, so devices which were not hacked also work in both these networks.

Also I travelled a lot in different countries during last several years and used there 2 my devices in different places - hotel wifi, restaurant wifi and so on. I used both devices - iphone which was not hacked and macbook which had lock attempt.

Never used something like unblock or other strange things - very common list of software, mostly for office/email work.

May 27, 2014 8:37 PM in response to iBenjaminCrowley

Thank you for that Benjamin - glad to see there's something like that out there.


I only just got around to resetting my appleID after it was disabled by Apple... Very tedious...


I've gone through all my passwords - thank god for eWallet is all I can say - and although I have been a bit lax with some security I had recently changed a bunch of stuff thanks to heartbleed my appleID was not unique and also a very old password. That's been remedied now.


Re common denominators: eBay is definitely not a factor for me; I occasionally watch things on ABC iView on my iPad/phone but have never streamed anything via unblock.us or used a VPN to the best of my knowledge (but I don't really understand the layers of servers and things so I don't think I can really say?). Generally I only make use of our private wifi at home, very rarely at my local library, although I think over the weekend I was connected to a public wifi while I was out somewhere - at fed square maybe? I can't quite remember.


All our devices are acquired new, purchased either directly from Apple (iPad) or under contract from a carrier (Telstra, Vodafone). I have never shared my AppleID with anyone.


It all seems rather confusing.

May 27, 2014 8:45 PM in response to iBenjaminCrowley

Oh dear, there is alot of missinformation being posted in here. Talk to Apple directly if you are effected and do not follow any instructions being posted here if you are not confident. You need to be sure that your iOS backups are valid and recent.


Just as a data point, I look after litterally hundereds of Apple users in an Australian enterprise environment and have seen a total of 1 person effected. Anecdotally the issue appears to be effecting a very limited number of people.

May 27, 2014 8:50 PM in response to veritylikestea

I am also in Australia.


I would appreciate some advice being as I am out of my depth here. The permutations and combinations of causes, effects and possible solutions have me a bit perplexed.


In our house we have

Two iPad 2 [both have wifi only]

One iPhone 4 [Telstra carrier]

One iPhone 5S [Optus carrier]

All have iOS 7.0.6

One iMac with OS X 10.9.2


I have cancelled iCloud accounts from each device [thus Find my Phone also] and all devices have Passcode lock active. I realise I shall need to change Apple IDs and iCloud passwords.


So far I appear to have dodged the bullet. Telephony on the iPhones still operating.


Three questions:

1 Is there anything else I need to do to stay safe until all this blows over or something definite comes from Apple,

2 Is use of wifi on all devices through my router OK to use.

3 Anything needed to protect the iMac.


Thanks for any advice

May 27, 2014 8:51 PM in response to gimpsley

I think about easy case - what if I am overseas during holidays or business trip and my computer with iOS backup is in home. It will be painful, so I don't like this case to happen again...

I have 1 device locked, it can't connect to iTunes because it lost connectivity to Find My Phone and I am unable to move it out from Stolen mode. Apple unable to help me except totally clear it. I have several photos there which were not backuped from family event, I don't wish to lost it... Will wait couple of days for any official announcement from the Apple...

May 27, 2014 9:08 PM in response to Peter Sealy1

Peter Sealy1 wrote:


I am also in Australia.


I would appreciate some advice being as I am out of my depth here. The permutations and combinations of causes, effects and possible solutions have me a bit perplexed.


In our house we have

Two iPad 2 [both have wifi only]

One iPhone 4 [Telstra carrier]

One iPhone 5S [Optus carrier]

All have iOS 7.0.6

One iMac with OS X 10.9.2


I have cancelled iCloud accounts from each device [thus Find my Phone also] and all devices have Passcode lock active. I realise I shall need to change Apple IDs and iCloud passwords.


So far I appear to have dodged the bullet. Telephony on the iPhones still operating.


Three questions:

1 Is there anything else I need to do to stay safe until all this blows over or something definite comes from Apple,

2 Is use of wifi on all devices through my router OK to use.

3 Anything needed to protect the iMac.


Thanks for any advice


The only thing you need to do is:


* have a good backup procedure in place for all your devices

* have a strong password.

* keep all your software up to date (I notice you're on iOS 7.0.6 and OS X 10.9.2. Both are old versions — update asap!)


All the other steps you have already taken were unnecessary, you might as well undo them.


Here's a good article on passwords, compare his advice to your own password and adjust accordingly: https://www.schneier.com/blog/archives/2014/03/choosing_secure_1.html

May 27, 2014 9:13 PM in response to MidniteDaydream

From what I've been able to piece together, I think that the assumption that the hacker has compromised user credentials (user/pass) is premature and perhaps mistaken.


I think rather that the "lock that device" message is being forged somehow. Given the geographic clustering so far, I also suspect that either manipulating network traffic is necessary (DNS poisoning, routing hijinks, etc.), or key information for the forged message is coming from an Australian source (website logs, sniffer parked on an Australia backbone, etc.) In theory, the device should only accept a "lock" message that the device can cryptographically authenticate as coming from an Apple server; I SPECULATE with no data that either Apple didn't do this, had a critical certificate stolen somehow (e.g. Heartbleed) or botched it.


I suspect an interested security researcher who monitored the IP traffic to a device as it is remotely locked and unlocked could shed more light on this.

May 27, 2014 10:58 PM in response to kap_australia

Passcode advice question:


My wife hates having passcode set on her iPad and iPhone. In the current situation I have persuaded her to set passcode on both, but with activation after the maximum option of four hours.


In the event of being hacked would this allow recovery of control? or is the device at risk during the four hours?



Two factor authentication question:


This is not instant and I suspect Apple are likely to be swamped with people doing this...which may cause short term overload problems. Any comment?


Thanks

May 27, 2014 11:17 PM in response to mikebhm

To address the current security breach, you simply need another way to make your device accessible. Either of the two options you have mentioined will work.



If you have a passcode set regardless of its duration, a find my phone user cannot override it with another password.


Two factor authentication will allow you to use a trusted device or your secret key to access your device. It should be instant unless you have recently change your apple id password which will mean that you will have to wait 3 days.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

My devices have been hacked. What do I do?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.