My devices have been hacked. What do I do?

i was using my ipad a short while ago when suddenly it locked itself, and was askiwhich I'd never previously set up. I went to check my phone and there was a message on the screen (it's still there) saying that my device(s) had been hacked by 'Oleg Pliss' and he/she/they demanded $100 USD/EUR (sent by paypal to ****) to return them to me.


I have no idea how this has happened. I am not aware of having been exposed to malware or anything else, although i did recently purchase some new apps - perhaps one of these has something to do with it? I don't know. I am not sure what avenue has been used to reach my devices - I'm about to use my husband's laptop to check through some of my accounts (gmail, etc) and see if there is any clue there.


Has this happened to anyone else? What can or should I do? Many thanks

<Email Edited by Host>

iPhone 5

Posted on May 26, 2014 4:57 AM

Reply
456 replies

May 28, 2014 6:11 PM in response to MajorIP4

Apple's services are not hacked:


Today Apple issued a statement on the problem, noting that—as suspected—the iCloud service itself was not actually breached, but individual user accounts may have been compromised through password reuse or social engineering:


http://9to5mac.com/2014/05/27/apple-denies-icloud-breach-was-responsible-for-dev ice-lockout-attack-advises-users-to-change-passwords/


Basically don't "give away" your password and don't reuse it. And then use Apple's Two-Step Verification process and you'll be fine.

May 28, 2014 8:47 PM in response to Foaming Draught

Telling people that you don't believe them, based on nothing but your opinion is offensive. Several devices in my family were hacked and I manage the accounts. NONE had duplicated passwords, all were unique, as are all passwords under my control. I work in an area when security is of very real concern and use a password system that is very secure. I do not know what the answer is, and the only commonality I can find between those in my family and those reported by our corporate IT dept., is that all the devices had used a VPN unblocking server. How that leads to an ability to hack I do not know. My only thought is that there is a window of several minutes between when a legitimate access is made to a the app store - in app purchase etc., and accessing the VPN server, or when the server is already in use and a purchase is made. My kids used an unblocking VPN to access and stream material that is Geo blocked here and would sometimes make a purchase via that VPN to access that material. The iTunes store in Australia geo-blocks a lot of content. You have to use a VPN and switch to a US iTunes account to access it.

May 28, 2014 8:55 PM in response to MidniteDaydream

"My kids used an unblocking VPN to access and stream material that is Geo blocked here and would sometimes make a purchase via that VPN to access that material. The iTunes store in Australia geo-blocks a lot of content. You have to use a VPN and switch to a US iTunes account to access it."


So it's okay for you to access iTunes against Apple's terms of service?

May 28, 2014 9:08 PM in response to veritylikestea

Chris CA,


You must be an American. I dont use any geoblocking, but you should not criticise people for going down that path. What people like you dont realise is, in Australia, we pay double the price for the same thing you get in the USA. Songs on Itunes are twice the price. We often cannot even get certain movies or TV shows because FOX has the rights in Australia and their subscription prices are a joke relative to the USA. If you are an Aussie you should know better.

May 28, 2014 9:26 PM in response to Chris CA

Sorry - I didn't realise I was communicating with someone who is intellectually challenged. The two issues have nothing in common. One is well discussed and politically challenged corporate malfeasance involving Amazon, Microsoft, Apple, etc., who are overcharging one specific country, where the parties involved have been summoned and asked to explain by the Australian Government, the other a criminal act.

May 28, 2014 11:17 PM in response to veritylikestea

My take on this:


This has been a 2 stage process.


1.

The harvesting phase. Someone in Autralia has managed to manipulate the BGP routing table. A peer injecting a 17.x.x.x route more specific than Apple's own routes. By doing so inpersonating one of Apple auth servers, maybe based on the same hack as the one capable of impersonating Apple's activation process. Somehow I would not be surprised to see some of Apple's private keys out in the wild too. DNS poisoning is probably unrealistic due to widespread use og globally located dns servers.


2. The attack phase.

The least interesting part of course as to trying to find the origin. This is most likely controlled by bots.


I was hoping this tread would focus more on the harvesting phase.

May 29, 2014 3:25 AM in response to lundkeman

lundkeman wrote:


It would not be a stretch for hackers to go from unlocking stolen devices with a hack, too locking them.


There is absolutely nothing about the Dutch unlocking hack that is applicable to this situation. That hack requires the hackers to have the devices being unlocked in their physical possession. Due to the methods used, it cannot be applied remotely, and cannot be used to remotely lock devices.

May 29, 2014 5:18 AM in response to veritylikestea

I live in the UK and I myself haven't been hacked, but I have turned off my Find My service on both my IPhone and IPod (It wasn't enabled on my macbook) as this seems to be how the hackers are getting onto people's devices. I have had a different password for all the various things I use ever since the Heartbleed bug was first reported and I changed my password after Ebay was hacked. However, with all these hacking stories flying around it almost feels like nowhere on the internet is safe and it is just a matter of time before I am a victim

May 29, 2014 5:38 AM in response to garthur79

I live in the UK and I myself haven't been hacked, but I have turned off my Find My service


Although I myself have recommended doing that, it's important to understand the potential problems with doing that. Turning that off decreases the chances of protecting your phone and its data in case it is stolen. If that's not something you're comfortable with, just keep your phone backed up so that if you do get hacked, you can restore the phone without incident or serious inconvenience.


it almost feels like nowhere on the internet is safe and it is just a matter of time before I am a victim


Yup. If that's what you've learned from this, that's a good thing. Keep that attitude in the front of your mind with everything you do with your electronic devices. That knowledge is the best thing for protecting you against being a victim, just as keeping a close eye on your surroundings can keep you from being mugged.

May 29, 2014 5:59 AM in response to thomas_r.

Both my IPhone and IPod backup to to ICloud and all my music, photos and documents are all on my macbook as well which gets backed up with Time Machine onto an external hard drive. The thing that most scares me is if someone gets hold of my card details and starts spending ny money or creates some Facebook or Twitter account and starts posting nasty messages

May 29, 2014 6:23 AM in response to garthur79

The thing that most scares me is if someone gets hold of my card details and starts spending ny money


They can't get your card details from your Apple ID. They could spend your money in Apple's online stores, but that's it. That's fairly easily solved... it's easy to refute purchases with Apple, and you can turn to your credit card company if Apple fails you.


or creates some Facebook or Twitter account and starts posting nasty messages


There's nothing about hacking your Apple ID that makes that any easier. If someone wanted to do that, they could just do it. They wouldn't need to hack anything.

May 29, 2014 7:27 AM in response to Tlix

Good, because there is nothing criminal about using unblocking servers, it is simply doing something that annoys a Corporation, not breaking law, and I did not start this nonsense. All my posts prior Chris deciding to be judgmental in an area where he has no knowledge were related to the problem being discussed.


The current Apple response here this evening is still that it must be lax security on the part of those hacked - or that it is a case of one person making an erroneous claim and a lot of others doing a "me too" and making false claims. No possibility that Apple could be even partially at fault. That won't fly with people like me and many in our corporate organisation who are security conscious and who have not used passwords in other places.


The puzzling thing, and one that makes it seem more of of a vandalistic attack than an true attempt to make money, is that PayPal says no such person has an account with them. If they did, the banking details held by PayPal would lead law enforcement staright to their door. I'd guess at teenagers using a bunch of opportunistically acquired passwords. Acquired from where or how, I have no idea, but as too many have not used compromised passwords there has to be a weakness or flaw somewhere.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

My devices have been hacked. What do I do?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.