My devices have been hacked. What do I do?

i was using my ipad a short while ago when suddenly it locked itself, and was askiwhich I'd never previously set up. I went to check my phone and there was a message on the screen (it's still there) saying that my device(s) had been hacked by 'Oleg Pliss' and he/she/they demanded $100 USD/EUR (sent by paypal to ****) to return them to me.


I have no idea how this has happened. I am not aware of having been exposed to malware or anything else, although i did recently purchase some new apps - perhaps one of these has something to do with it? I don't know. I am not sure what avenue has been used to reach my devices - I'm about to use my husband's laptop to check through some of my accounts (gmail, etc) and see if there is any clue there.


Has this happened to anyone else? What can or should I do? Many thanks

<Email Edited by Host>

iPhone 5

Posted on May 26, 2014 4:57 AM

Reply
456 replies

May 29, 2014 5:39 PM in response to MidniteDaydream

"Well, if you can read a newspaper, real or online.... You do know what a newspaper is?"


lol. huffy kinda. oh well. maybe should have put smiley faces in my previous response. didn't mean to attack you. but just observed a difference with articles and pictures seen by me. oh well, you are more closer to the situation. was kindly hoping for links in return for articles with paypal in the screenshots, but me guess me have to look up the definition of newspaper and try to figure out the wisdom you have bestowed upon me. thanks. :-) :-) :-)

May 29, 2014 7:26 PM in response to lundkeman

It's not really the process the hackers used to unlock the devices that is interesting, but more the fact that icloud was compromised by the hackers, and apparently Apple didn't admit publicly that the system was compromised.


Now, Apple have said that the icloud was not compromised in this instance. Really?


It seems to me that icloud was compromised, how in the heck could they allow a bot to access many user accounts, in a short period of time, and put heaps of devices in lost mode, along with applying a screen message?


This attack didn't occur over a number of days, but in a relatively short period of time, when Apple could surely expect most of their customers were asleep - not madly realising they had 'lost' all their devices, and whilst the locked screen message has varied slightly, there are common words. Isn't this unsual activity? why was it not discovered by Apple until, possibly 6-8 hours later when we all woke up and started visiting Apple stores, and contacting support?

May 30, 2014 9:22 AM in response to lotsasmiles

lotsasmiles wrote:


OK - I am not as 'tech savvy' as most on this board, so excuse me if I sound basic.


I cannot understand this ....


Why can't Apple issue a 'fix' - they must have some way of getting around their own security systems. My iPad is locked by a number I do not know - there is a message on there 'saying' that I have been hacked. Why can't I put in an over-ride code? (and for all you who say Apple won't do that as the device may be stolen - my ipad has a serial number ... itunes identifies my ipad when I log in .... itunes identifies my identitiy with my Apple ID - it is MY ipad - **** even Amazon knows which of my 2 ipad's I want to send books to)


Is this waaay to simple?


Even if I have to take my device to a Apple store, why can't they back it up from their own systems even if it is locked? It is own of their own devices. Back it up - check my name, DOB, photo ID and itunes password then restore it and reload with all my information intact. Simple? You bet - so how come it isn't happening?


Very very frustrating. Maybe someone out there can enlighten me? Just don't use big words - I can get very confused 😉


Other than speculation has there been any proof provided anywhere that iCloud was indeed compromised?

May 30, 2014 9:50 AM in response to pogster

Other than speculation has there been any proof provided anywhere that iCloud was indeed compromised?


None.


It's important to understand what it means to say that iCloud was compromised. Many people don't seem to quite understand it. If iCloud were compromised, that would mean that hackers had been able to get access to iCloud as a whole somehow, and obtain access to user accounts through that illicit access. A good example is the eBay breach in which hackers obtained usernames and passwords by hacking eBay directly.


There is no evidence at all of such a breach. In fact, such a breach is not logical, based on the localized nature of the attack. What has happened in this case is that individual user accounts have been breached somehow. How that has happened is unclear at this point, but it probably involves some kind of localized network compromise or something along those lines.

May 30, 2014 10:42 AM in response to 007Aston

007Aston wrote:


It's not really the process the hackers used to unlock the devices that is interesting, but more the fact that icloud was compromised by the hackers, and apparently Apple didn't admit publicly that the system was compromised.


Now, Apple have said that the icloud was not compromised in this instance. Really?


It seems to me that icloud was compromised, how in the heck could they allow a bot to access many user accounts, in a short period of time, and put heaps of devices in lost mode, along with applying a screen message?


This attack didn't occur over a number of days, but in a relatively short period of time, when Apple could surely expect most of their customers were asleep - not madly realising they had 'lost' all their devices, and whilst the locked screen message has varied slightly, there are common words. Isn't this unsual activity? why was it not discovered by Apple until, possibly 6-8 hours later when we all woke up and started visiting Apple stores, and contacting support?


To your first point, since the unlocking uses a Man-in-the-middle attack, this does not mean that icloud was compromised. It means they successfully created a fake apple server, that can communicate with a device and potentially icloud (we do not know this for sure.) Basically unlocking a device, which should only be unlocked by the original Apple ID and password, which they do not possess. Either the hack can extract this in the exchange somehow, or the password is not needed, just say the Apple ID and some generated hash or not and some specific info that find my device is expecting.


Regarding the bot and putting heaps of users into safe mode. Once again goes along the lines of the unlock hack. If you could unlock a phone without knowing the credentials, you could surely lock a phone, establish a passcode, then send a ransom message without credentials. More likely they have hacked the find my device programs (if you turn it off, I believe the hack is stopped) and potentially icloud. The doulCi guys claimed 5700 unlocks in 5 minutes, thats 19 devices a second. Considering router times in the sub 100 ms, this seems plausible to me. If it really is this quick, I do not know that major decryption/encryption can be done in this short period of time, but since processors operate in Ghz maybe it is.


Too your last comment, If all these device were subject to a MITM attack or some sort of injection, it could/would be a one way communcation. Meaning the spoofed server sent the device their instructions, if the devices do send responses back to Apple, they would have been intercepted as well and could be dropped, thus Apple would never know anything happened at all.


The other weird thing are reports that people have reset their devices, only to be locked again moments later. Too me this implies that their reset potentially occurred through the spoofed sever and more data could have been mined from people. If turning off the find my device service prevents the attack, that is good, but authorities need to ascertain whether more data was compromised from many people changing/resetting their Apple ID and passwords. These could be compromised, but not used until a later time.


I would also be curious if the attack is against all device or the spoofed server only does a certain percentage of the devices. Meaning lets say it infects/locks only 10% of devices, by allowing 90% of normal apple traffic through and only truly redirecting or injecting a smaller percentage. This could represent why some device are reset with no further effects and others are immediately locked again.

May 30, 2014 10:38 PM in response to MidniteDaydream

despite my ignorance about not knowing what a newspaper is (according to midnitedaydream), me found a report with a screenshot of a lockscreen ransom demand that says paypal. it's in japanese. apparently hitting an iphone on softbank which is a japanese cellular carrier. scroll down the linked page to see screenshot.

http://gigazine.net/news/20140528-ios-held-to-ransom/

Jun 9, 2014 11:54 AM in response to Greg Earle

Greg Earle wrote:


Update:


Hackers accused of holding Apple devices to ransom detained in Russia


That may not be related. There was apparently a similar incident specific to Russia, which wasn't reported in the western news and which had some significant differences. For example, it did not mention Oleg Pliss, and the message was followed up with an e-mail message scam. The lock message said (translated from Russian by Google):


"Your device is locked in relation to the complaint. And can help you unlock it. Check your email!"


It's possible these folks may have been behind the Australian hack as well, but it's also possible they are completely unrelated and just used a similar technique. Since we still don't have any idea what caused the Australian hack, it's impossible to say.


We'll have to wait and see what other developments - if any - come from this arrest.

Jun 9, 2014 8:45 PM in response to marumurak

veritylikestea (whom you responded to) did not comment on copyright.


Because one of us is worth two of you 🙂

Which is why you should pay double.🙂

If you want to clutch at straws you go for it.

You seem to be the one clutching at straws.

I have no issue with the price.

Copyright laws and fees in western countries are very similar.

Similar yes, but there is no global copyright.

Anyway you are off topic

Why did you go off-topic?

Jun 9, 2014 8:48 PM in response to Chris CA

Similar but not identical.


His comment on the wage structure is on target.


The copyright holder determines what they are going to charge, Apple is merely a conduit in this case. If you and everyone else in Australia think they charge too much vote with your wallet and quit buying anything from them.


Have you ever written to any of the copyright holders and asked them why they price is set as it is?

Jun 9, 2014 9:06 PM in response to veritylikestea

I dont buy anything from the Itunes Store. Never have for that exact reason. I think if you research things you might find Apple were called into a parliamentary review in Australia and asked about their prices. While they hid behind their confidentiality clauses in their contracts it was very obvious to all and sundry that they were milking things. As a point of fact I have done the work for you and provided a link


www.abc.net.au/news/2013-07-29/geo-blocking-mps-committee-price-report-apple-ado be-microsoft/4850484


Link may not work but you can google it.


Amazingly the Australian Parliamentary Report on this issue recommended the Australian public learn how to use Geo-blocking to overcome the unjustified prices we are being charged. Neither Apple, Adobe or Microsoft could convincingly justify their pricing.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

My devices have been hacked. What do I do?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.