veritylikestea

Q: My devices have been hacked. What do I do?

i was using my ipad a short while ago when suddenly it locked itself, and was askiwhich I'd never previously set up. I went to check my phone and there was a message on the screen (it's still there) saying that my device(s) had been hacked by 'Oleg Pliss' and he/she/they demanded $100 USD/EUR (sent by paypal to lock404(at)hotmail.com) to return them to me.

 

I have no idea how this has happened. I am not aware of having been exposed to malware or anything else, although i did recently purchase some new apps - perhaps one of these has something to do with it? I don't know. I am not sure what avenue has been used to reach my devices - I'm about to use my husband's laptop to check through some of my accounts (gmail, etc) and see if there is any clue there.

 

Has this happened to anyone else? What can or should I do? Many thanks

iPhone 5

Posted on May 26, 2014 4:57 AM

Close

Q: My devices have been hacked. What do I do?

  • All replies
  • Helpful answers

first Previous Page 18 of 32 last Next
  • by wheelman2188,

    wheelman2188 wheelman2188 May 27, 2014 5:42 AM in response to Tigerlily75
    Level 1 (0 points)
    May 27, 2014 5:42 AM in response to Tigerlily75

    Tigerlily75 wrote:

     

    No, I'm very protective of it, but that said I was also a bit slack in that a) it was very old - same password for years, and b) as stated earlier it was the same password I'd used for eBay which I didn't even realize until today.

     

    I think you may be on to something there. I had the ebay issue as well, and had the same password.

  • by Andrew J,

    Andrew J Andrew J May 27, 2014 5:42 AM in response to Tigerlily75
    Level 3 (790 points)
    May 27, 2014 5:42 AM in response to Tigerlily75

    Tigerlily75 wrote:

     

    No, I'm very protective of it, but that said I was also a bit slack in that a) it was very old - same password for years, and b) as stated earlier it was the same password I'd used for eBay which I didn't even realize until today.

    It may or may not be relevent, but by narrowing down all the possiblities, we can find the cause, and end this sooner rather than later.

  • by Loonbeam1,

    Loonbeam1 Loonbeam1 May 27, 2014 5:55 AM in response to Andrew J
    Level 1 (0 points)
    May 27, 2014 5:55 AM in response to Andrew J

    As far as she knows, my wife did not sign up for Ebay....

  • by ShellsBells57,

    ShellsBells57 ShellsBells57 May 27, 2014 6:16 AM in response to Loonbeam1
    Level 1 (0 points)
    May 27, 2014 6:16 AM in response to Loonbeam1

    For those collecting common threads. I am in Australia, I don't use Testra (I use Optus for phone and TPG for internet). I never use a VPN. I have never used Ebay and don't have an account there. And I bought my phone directly from Apple.

  • by Stefarn,

    Stefarn Stefarn May 27, 2014 6:16 AM in response to Andrew J
    Level 1 (0 points)
    May 27, 2014 6:16 AM in response to Andrew J

    Thanks Andrew

     

    I was able to use Recovery Mode and update to my last Back up - My devices that already had Passcodes set were Ok. Now learnt my lesson to always have a passcode set.

  • by Andrew J,

    Andrew J Andrew J May 27, 2014 6:17 AM in response to Loonbeam1
    Level 3 (790 points)
    May 27, 2014 6:17 AM in response to Loonbeam1

    Loonbeam1 wrote:

     

    As far as she knows, my wife did not sign up for Ebay....

    It's a process of elimination, so we can probably discount eBay for now. There has to be a common thread to this problem, as the hacker would only use a one stop method of harvesting account details. If we can find out where the messages originated, it may give a clue to who.

  • by Andrew J,

    Andrew J Andrew J May 27, 2014 6:19 AM in response to Stefarn
    Level 3 (790 points)
    May 27, 2014 6:19 AM in response to Stefarn

    Stefarn wrote:

     

    Thanks Andrew

     

    I was able to use Recovery Mode and update to my last Back up - My devices that already had Passcodes set were Ok. Now learnt my lesson to always have a passcode set.

    Great news. If you haven't already, change your Apple ID password to something unique, and use it for that single purpose.

     

    Good luck.

  • by kkneufeld,

    kkneufeld kkneufeld May 27, 2014 6:22 AM in response to Andrew J
    Level 1 (0 points)
    May 27, 2014 6:22 AM in response to Andrew J

    I know it's unlikely, but the other account I had with the same details as my Apple ID was my Catch of the Day account. I tried to find whether the company that owns Catch of the Day has any international links,  but couldn't. I'll keep thinking of others.

  • by Foaming Draught,

    Foaming Draught Foaming Draught May 27, 2014 6:34 AM in response to veritylikestea
    Level 1 (0 points)
    May 27, 2014 6:34 AM in response to veritylikestea

    My wife and I haven't been hacked (in Australia, 2 iPhones, an iPad and an iPod). We have passcode set on our devices. Find my iDevice is on.  We don't share Apple IDs.  I've received phishing emails purporting to be from my mail provider, Fastmail, recently, but I think that's coincidental. I recognised them for what they were. My eBay password was (I write "was" because I changed it last week) different to my Apple ID password.
    I've looked at my iCloud settings. The only major app which iCloud is disabled for is Mail.  I use Thunderbird on my (Mac) desktops, my wife uses a web interface on hers.

    I don't use a VPN.

    I wonder if an app provider is the source? We don't have games on our devices.

    This ramble is just to add to the detective data.

  • by Opsystem,

    Opsystem Opsystem May 27, 2014 6:40 AM in response to veritylikestea
    Level 1 (0 points)
    May 27, 2014 6:40 AM in response to veritylikestea

    According to news sites around the world reporting on this attack. The exploit uses the “Find My iPhone” feature, which allows users to remotely lock their iPhones and iPads via iCloud in case the devices are lost or stolen.

  • by Andrew J,

    Andrew J Andrew J May 27, 2014 6:41 AM in response to Foaming Draught
    Level 3 (790 points)
    May 27, 2014 6:41 AM in response to Foaming Draught

    Foaming Draught wrote:

     

    My wife and I haven't been hacked (in Australia, 2 iPhones, an iPad and an iPod). We have passcode set on our devices. Find my iDevice is on.  We don't share Apple IDs.  I've received phishing emails purporting to be from my mail provider, Fastmail, recently, but I think that's coincidental. I recognised them for what they were. My eBay password was (I write "was" because I changed it last week) different to my Apple ID password.
    I've looked at my iCloud settings. The only major app which iCloud is disabled for is Mail.  I use Thunderbird on my (Mac) desktops, my wife uses a web interface on hers.

    I don't use a VPN.

    I wonder if an app provider is the source? We don't have games on our devices.

    This ramble is just to add to the detective data.

    Follow the recovery mode instructions if you can't unlock your devices.

     

    Follow these steps if you never synced your device with iTunes, if you don't have Find My iPhone set up, or if you can't get to your own computer. You'll need to put your device in recovery mode to erase the device and its passcode. Then you'll restore your device.

    1. Disconnect all cables from your device.
    2. Turn off your device.
    3. Press and hold the Home button. While holding the Home button, connect your device to iTunes. If your device doesn't turn on automatically, turn it on.
    4. Continue holding the Home button until you see the Connect to iTunes screen.
    5. iTunes will alert you that it has detected a device in recovery mode. Click OK, then restore the device.

    Apps are sandboxed from accessing your account details. Your account has been harvested in some way, how, we're trying to figure that out. Change your Apple ID password if you haven't already. Just a question, do you use the Apple ID email address and password with any other login account?

  • by Tigerlily75,

    Tigerlily75 Tigerlily75 May 27, 2014 6:48 AM in response to veritylikestea
    Level 1 (0 points)
    May 27, 2014 6:48 AM in response to veritylikestea

    Like others have said, Apple just booted me out of my AppleID right then and made me change my password again.  Thinking up all these unique and strong passwords is exhausting!  No wonder hackers have a field day.

  • by Foaming Draught,

    Foaming Draught Foaming Draught May 27, 2014 6:50 AM in response to Andrew J
    Level 1 (0 points)
    May 27, 2014 6:50 AM in response to Andrew J

    Thanks for the reply, Andrew J, but I started off by writing that our devices have NOT been compromised. Then I rambled on in the hope that someone would see a common thread (a negative thread in our case) to those devices that are borked.

    I can't remember now  -  has anyone posted anything about jailbreaking? Our (unharmed) devices aren't jailbroken, bog standard latest iOS.

  • by Andrew J,

    Andrew J Andrew J May 27, 2014 7:02 AM in response to Foaming Draught
    Level 3 (790 points)
    May 27, 2014 7:02 AM in response to Foaming Draught

    Foaming Draught wrote:

     

    Thanks for the reply, Andrew J, but I started off by writing that our devices have NOT been compromised. Then I rambled on in the hope that someone would see a common thread (a negative thread in our case) to those devices that are borked.

    I can't remember now  -  has anyone posted anything about jailbreaking? Our (unharmed) devices aren't jailbroken, bog standard latest iOS.

    Got blind sided there, I though you were commenting because you were hacked. Skipping text to get to the details is an old speed reading habit of mine.

     

    Jailbreaking hasn't been a common thread, as others have stated on other forums.

     

    It seems like the accounts have been harvested via an outside source where user details have been intercepted. Because it hasn't affected a great multitude, one can assume there is a minor connection between those affected.

     

    My theory is a user account details used to log into other web services, is identical to their Apple ID. It's almost impossible for a snotty nosed hacker like this one, being able to access Apples servers. These details have been intercepted in some way via a third party server.

  • by Greg Earle,

    Greg Earle Greg Earle May 27, 2014 7:22 AM in response to veritylikestea
    Level 2 (158 points)
    Windows Software
    May 27, 2014 7:22 AM in response to veritylikestea

    At the top of the page/thread I'm seeing

     

    Branched to a new discussion.

     

    with a link to a different thread, but when I try to click on that link/thread, I get a page saying "Unauthorized" and (in pinkish red)

     

    It appears you're not allowed to view what you requested. You might contact your administrator if you think this is a mistake.

     

    Anyone else seeing this?

     

    (Also wondering why this thread is dying down - no other US people affected?)

first Previous Page 18 of 32 last Next