My iMessage has been hacked

I went into the messages app on my computer recently and found out that more than 20 messages had been sent. The messages were all to Chinese numbers, and the messages in Chinese. User uploaded file


Has anyone experienced the same? is my account hacked?

MacBook Air, OS X El Capitan (10.11.3)

Posted on Mar 7, 2016 2:39 PM

Reply
188 replies

Oct 2, 2016 2:48 AM in response to Alex53135

This happened to me yesterday too - over 50 messages sent to a Chinese number, same as the screenshots. Reset my password and changed the email address I use but half hour later my apple ID said my new password was incorrect so had to reset it again. Messages sent as iMessage so hoping no data charge? Whilst signing in and out of all Apple ID things on my phone I seem to have lost all my photos too annoyingly!

Oct 2, 2016 12:33 PM in response to HodgeR3

Hi,


iMessages can be sent whilst the iPhone or device used is on WiFi or a good enough Carrier service.

WiFi is the most likely as most people are not likely to have arranged roaming in China.


The out going iMessages show as Blue ballooned background (iMessages) and not green SMS ones.

NOTE: Green messages on a Mac can also mean Yahoo, AIM Jabber or Bonjour chats but we are not talking about those.


Currently iMessages has not way to block other devices being added.

Denying the pop ups only stops any Alternative Number or ID being active in the app (it still gets added)

As these devices are not using Alternatives but the actual Apple ID you have that on your devices already.



User uploaded file

8:33 pm Sunday; October 2, 2016


 iMac 2.5Ghz i5 2011 (El Capitan)
 G4/1GhzDual MDD (Leopard 10.5.8)
 MacBookPro 2Gb (Snow Leopard 10.6.8)
 Mac OS X (10.6.8),
 iPhone and an iPad (2)

Oct 2, 2016 1:47 PM in response to Alex53135

Add another one to the list of unfortunates. I woke this morning to a notification that a 13" MacBook Pro "macen" had accessed my Apple ID, and I had 80-some Mandarin messages sent to 80-some different Chinese numbers with country code +86. Apple caught it and locked my Apple ID before I was even aware (this all happened between 1:00 and 2:00 this morning), and I was able to recover it. I changed my password and security questions for Apple as well as the Gmail address I use as my Apple ID, and everything is working fine.


In my case, I suspect it's from the Linked In hack. I stupidly used to use the same password occasionally, and my Apple ID was very close to what I think I used on Linked In before I canceled my account back in 2012.


I've done everything I can to lock things down, but I'm very frustrated that they're now forcing a three-day delay after changing your password before you can activate two-factor authentication. I can't do it until October 5 according to the Apple ID site, so I guess I just have to keep my fingers crossed my account isn't compromised again before then.


I called my mobile carrier to notify them, and they confirmed that since the messages were sent using data, there will be no international charges applied. Since I have unlimited data, I don't have anything to worry about there, but those on very limited data plans might want to call their carriers just to be safe. Also, it may be an overreaction, but I called the credit card companies for the cards I had in my Apple Wallet and had the accounts shut down and new ones reissued. Maybe we're just being hacked to send spam, but I felt nervous about a larger plot to harvest data, and I don't feel confident they couldn't have accessed my card info. I'd rather deal with a few days of inconvenience to have that peace of mind.

Oct 3, 2016 3:13 AM in response to Alex53135

Same thing happened here:

Your Apple Id was used to sign into IMessage from “8gepc的Mac (18)“.

Since I don't have an iPhone or any other Apple-mobile device and haven't seen any SMS's going out on my Android phone I think I good what concerns the extra cost.

But I am still very concerned how somebody got access to my Apple ID. I immediately changed the Password and now I also have to wait 3 days until I can activate the 2-step authentication.

But I also find really odd, that I can not activate the iCloud-Service on my Mac anymore. After I enter the Password it works for 2 second and then asked me for my password again, without saying, that the previously entered one was wrong.

Oct 3, 2016 10:46 PM in response to Alex53135

Another hacked Apple ID here. I got an email from Apple saying that my Apple ID was used to sign into iCloud via a Web Browser (IE on Windows), then another notification that an iMessage sign-in came from an iMac with a computer name that is not one of mine. I changed my password. I don't have an iPhone, but found many of those spam Messages sent from my account on my iPad and iMac. It looks like they went on for about an hour or so and had already stopped when I changed my password.


One interesting observation: the first spoofed Conversation in Messages was like a few messages containing the character "1" then after that one, many of these identical spam messages. I wonder if the first number belongs to the spammer and is used as their test to see if the hacked Apple ID Message works, then they start spamming the foreign numbers in regular increments?

User uploaded file


http://www.iphonetricks.org/how-to-fix-the-chinese-imessage-hack/

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

My iMessage has been hacked

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.