apple id hacked, Imac locked, ransom

So while I was sleeping, i got some emails from apple support (actually my husband saw it while i was still sleeping) telling me that "lost mode enabled on my iphone", second one was that my iphone was found near my actual location... And then my husband woke me up asking me if i did something in my sleep ???

We found another email that someone logged in to my apple id from chrome, windows ( we do not have or use any windows, pc and we never signed in on any pc/ windows )

We changed my apple id password, everything looked fine until we tried to turn my Imac (27 inch late 2011)...

we saw this

User uploaded file


after one minute there was this

User uploaded file




No one ever put any password ( except the admin / account password which is not 4 digit ). Also as you can see there is email unlock.device@gmx.com


I tried everything, searching for solutions online, and on this forum, chat with apple USA they couldn't help so they suggested a call, which I did and it lasted more then one hour then I was redirected to senior / advanced manager or something similar from apple in California...and after 3-4 hours my imac is still locked.


I will try to explain everything that we tried (me and apple support ) over that 3-4 hours ( chat one operator, call from another operator and then call from senior advanced support). In an email was sent to that address left under code ... I got this


unlock.device@gmx.com via mout-bounce.gmx.net

4:36 PM (9 hours ago)
User uploaded file


User uploaded file

User uploaded file

to me

User uploaded file

Hello!

We've blocked your device. To activate the device you need:
Pay 50$(USD) for a Bitcoin Address: 12yFuEpgnUKN1DCLNbhRPNEBBExJgEixTz
Buy bitcoins online: https://localbitcoins.net
How to buy bitcoins? https://localbitcoins.net/guides/how-to-buy-bitcoins
Inform us about the payment and we will send the passcode.
All your devices will be blocked within 24 hours if not receive payment.

1 PART APPLE SUPPORT CHAT

explained everything, operator sad that they never heard before about this problem, we tried to restart imac several times nothing, since i was able to get to my icloud account and see my devices including imac we tried to erase it, to lock it again and to play sound... everything was on pending... after 40 minutes operator suggested a call from someone else since she was not able to help.

2. PART APPLE SUPPORT CALL

I already had my apple case number another person went trough the whole chat conversation, said that this is impossible, never heard of before etc ...was surprised that i can see access my apple account ( find my phone , i cloud, basically everything) since it looks like someone got into my account and put my imac in lost mode.

After more then 40 minutes trying to reset, get into safe mode etc she said tha she needs to speak with her senior advisor ( something like that) and that she is not able to help me and I should continue the conversation with him

3.PART APPLE SUPPORT SENIOR ADVANCED MANAGER

I explained everything from the beginning, he suggested to try the same things, reset, get to safe mode,...etc

It never worked, so we tried to plug the internet cable to IMac hoping that it will as least show in online mode, but that didnt work out, in the end he suggested to erase my Imac from my icloud, from my devices hoping that it will free my device from everything ( like when you sell your device) but NOTHING changed the screen and that lock code with that email address. He was so surprised (senior manager) that he asked if we have some small kids or anyone else that could do/ type something by accident, since he could not believe that someone hacked my apple id and that they did not changed my password. And then I said that we dont have kids, and that even if i (or anyone from our family ) was sleepwalking, crazy or whatever how and why would anyone leave that email asking for 50$ worth bitcoins ????

He didnt have answers, checked official apple stores close to me and realized that since I am living in serbia , closest apple store is in Croatia ( also Serbia is not listed on apple forums, and we can not use 2 authentication security ). So I should try to contact official reseller /dealer in Serbia tomorrow and see what happens next.

I think this is serious problem with apple, all of them said that they never heard about it before but i can see other similar posts for different devices on this forum... and that is also confusing... I have no idea what to do next

I ll call the official reseller tomorrow and will update this tread...

If anyone has any suggestions i would be happy to try anything ... tnx


iMac, macOS Sierra (10.12.6), null

Posted on Aug 13, 2017 5:37 PM

Reply
37 replies

Aug 14, 2017 6:23 PM in response to JelenaI

You have every right to be upset....ironically, this same exact thing happened to me last night as well. Someone in Kalunga, Russia signed in on a PC to my icloud account and locked my iPad, iPhone, and MacBook Pro. I was able to get back into my iPad and iPhone when I woke up and after researching this all day I believe it's because I had a PIN code set up for those devices. The firmware passcode needed to unlock my MacBook Pro is another matter. I have the same exact message telling me to email that address. I did so (without including any information in email body) and the recieve an identical message to the one you received down to the Bitcoin address. Obviously it's the same person who did this to us, and on the same day. It happened during the night for me too (but I'm in the US so different time zones) and the message on my iPhone this morning when I woke up said my account was accessed at 3am. I do have the 2 factor authorization feature set up and it still happened to me! I called Apple support and they had never heard of it either....it blows my mind. I made an appointment at my local Apple Store to have them help me access my MacBook again....luckily I bought my MacBook online and the receipt was emailed to me, or I'd be screwed like a lot of the people I've seen online who threw out their 3 or 4 year old paper receipt and don't have proof of ownership. It's insane though that it's their own "Find My" feature that's causing this problem and they won't acknowledge it. I found articles online discussing how Apple received word earlier this year that some criminals had somehow accessed millions of iCloud usernames and passwords. Apple was asked by these criminals to pay a ransom and Apple didn't. Which they shouldn't have, obvioutlying, but they should have sent an email or some type of notification out to every iCloud account holder telling them of this possible breach and to change their passwords ASAP. I don't regularly check Apple or Mac websites (most people dont) so even if they had put a message on some remote web page of theirs about this issue, I never would have seen it. Maybe, it's not Apple's fault that iCloud accounts were compromised (which is debatable) but they should have done steps to prevent this Ransom hijacking from occurring....and they did NOTHING! I wish I had more of a voice and could tell people about this, but I don't really think there's much I can do about it. I never reply to or comment on this kind of stuff but considering how mad I am and the fact that the exact same thing happened to both of us within the same 24 hour time frame, I felt compelled to respond. Maybe this thread will help protect other people. But don't listen to some other posters; you have every right to be upset. Tomorrow, after my appointment at the Apple Store, I'll post on this thread again if they fix it and it's a fix that I can convey to you easily. Otherwise, good luck!

Aug 16, 2017 11:21 AM in response to JelenaI

J, Any luck on this. I go hit Tuesday early am. Apple was no help since it is on a Late 2009 Imac. I have two Iphone7s, an Ipad and Apple TV, yet no help cause my imac is a bit older. Not an issue that stemmed from my imac, yet a hack into Apple IDs that I think Apple should honor regardless.


Any info would be appreciated.


Thanks

Aug 16, 2017 12:55 PM in response to Jstuie

My phone was locked two days ago but was able to locate and change password so no issues there. My MacBook was blocked though, and I ended up calling Apple. As others have said, the Rep said this was his first call for this issue. We confirmed that since it had a firmware password set, it has to be brought into an Apple Store or Apple authorized service provider, with proof of ownership. And these stores want a $70 diagnostic fee to fix it. They claim there are no other options, and that without a receipt we could be sitting on a $1K+ brick. Of course, I refuse to accept this and will be doing an Internet deep dive tonight to find another solution. We know our usernames/passwords were compromised, we just can't prove they were compromised on Apple servers so they won't help in that regard. So from their perspective, the anti-theft features are doing what they're supposed to be doing...fair enough. Had we set our own firmware passwords AND had two-factor authentication enabled, we would have an easier workaround.

Aug 16, 2017 2:04 PM in response to Jstuie

No, so far nothing, I am still trying to find / get that receipt. But since in my country there is no official apple store (only authorized resellers and dealers) Im not sure that even with a receipt I will solve this.

I already contacted some local repair shops and they said that no one but official apple would be able to do anything since it is Mac (i guess they would be able to do something with iphone or ipad)...

Aug 16, 2017 2:17 PM in response to Shadama

And where are you? Why would they charge you 70$? Did you find anything online? So far it looks like there is no solution... We tried to remove one memory stick (someone suggested that any physical change in configuration will automatically erase firmware lock) but it looks like you can do it only on older devices (before 2011). You can check it

here . If you can find your receipt , or your device is still under warranty you should go directly to an apple store.

Aug 16, 2017 3:03 PM in response to JelenaI

JelenaI wrote:


No, so far nothing, I am still trying to find / get that receipt. But since in my country there is no official apple store (only authorized resellers and dealers) Im not sure that even with a receipt I will solve this.

If you have a receipt, or even the original iMac packaging should help an Apple Reseller/Dealer to help you.

Aug 16, 2017 3:30 PM in response to JelenaI

This is exactly what happened to me Friday night/Saturday morning. I did have 2 factor authentication on iPhone and iPad and was able to reset my password. However, my used 2010 MacBook went through the same process yours did. The reset originated in Kulunga, however I never saw an email to respond to....my MacBook just rebooted and locked after connection to wifi. I purchased this from Amazon and was very happy after upgrades I performed myself. When I booked a Genius Bar appointment I was assured on the phone that my receipt from Amazon should suffice but I was turned away at the Apple store. Had I known, that there were so many others I would have been much more angry.

Aug 16, 2017 5:44 PM in response to Loner T

If I tell you this would you believe me ?... My Imac is from late 2011, I was working at a design studio that bought my Imac (with several other apple products macs , macbooks etc ) from 2013-2014, when i decided to leave the company instead of my last paycheck, we made arrangement ...I ll get that Imac i was already working on instead of my last salary. They gave me the original box, even that little black microfiber cloth with apple logo. No receipt, i never asked for it and even if i did they would not give it to me, because they would usually buy several products at the same time and i knew that tImac was without warranty since it was already 2014. After I left my job I moved to another apartment, many stuff ended up in my sisters basement. Humidity and mold did the rest.. not only that stupid box was unrecognizable, my books and many things were only good for garbage.

Maybe i should take that black cloth as a proof of purchase XD???

Aug 16, 2017 6:08 PM in response to Loner T

Hahahah I mean this is insane why would i need a proof of the employment for apple? If i stole something from anyone I should have more problems with the police then with apple. There should be some other ,better, anti- theft system like every device has serial number, if it is stolen from you, you should just send that serial number to apple, with your id and other info, saying that it is stolen from you so that device is black-listed. Serial number on any apple device is not a short,easy ,visible and memorable and hacking someone s apple id looks like an easy job since this thing happened obviously to many people. And we all know that things like this, especially with older devices, will make problems to ordinary people. Thieves don ask on apple forums what to do, they sell stolen goods to repair shops for parts or people who will brake any password... Sorry I am heaving a mental break down, I cant use my Imac and my files, and I have to finish some projects... Of course i don't have backup..

Aug 16, 2017 6:41 PM in response to Loner T

That is the problem even if i find it It might not be enough, and I might have to pay for that etc...

What about common sense? Every time you login from another device, or sometimes from another country you get an email from apple.. (apple can check and they saw that that login was from windows ) Few seconds ago when i logged in to my icloud i had to type password,also answer two security questions before i actually got to my icloud...

How did they pass that? i never left any info anywhere, i dont use suspicious websites or software, how did they got my password and were able to put device in lost mode???...and since they left their email requesting bitcoins, how is that not enough for apple to help me? How many people in this world keep receipts after 5 years? or boxes?

Aug 16, 2017 7:11 PM in response to JelenaI

JelenaI wrote:


That is the problem even if i find it It might not be enough, and I might have to pay for that etc...

What about common sense? Every time you login from another device, or sometimes from another country you get an email from apple.. (apple can check and they saw that that login was from windows ) Few seconds ago when i logged in to my icloud i had to type password,also answer two security questions before i actually got to my icloud...

How did they pass that? i never left any info anywhere, i dont use suspicious websites or software, how did they got my password and were able to put device in lost mode???...and since they left their email requesting bitcoins, how is that not enough for apple to help me?

None of this will help you in your current situation. I understand you are frustrated. The mechanics of the Lost Mode are very well documented in the first link on page 1 of this discussion.


JelenaI wrote:


How many people in this world keep receipts after 5 years? or boxes?

I do. 😉. I have all the packaging, receipts, original box and the shipping carton for the original 2006 Mini I bought. But, again, this is not helping you.


I suggest talking to the Design Studio and establishing a chain of ownership, and then approaching Apple Reseller or an Apple Store to get your Mac back, otherwise your frustration level will just go up and your anger will cloud (pun intended) your judgement even further.

Aug 21, 2017 11:10 AM in response to Loner T

I'm pretty sure Apple doesn't care about my mid-2010 MacBook, only their culpability and rigid adherence to arbitrary constraints. In any case, I visited a 3rd party Mac repair shop and the technical expert had it sorted out in less than 5 minutes. I was gob-smacked. I don't know exactly how he did it but he was successful and I absconded with my laptop in absolute shock.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

apple id hacked, Imac locked, ransom

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.