Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

nwlondonlad

macrumors 65816
Original poster
Sep 20, 2007
1,015
729
UK London
Woke up this morning and seen a pop up on my iPhone asking me to verify my apple ID, entered password and it said incorrect, hmmm strange. Checked my email and have seen that someone from China has managed to hack into my itunes/app store account changed my password and spent all my app store credit £51

To make matters worse i can't even access my itunes account cos the person has changed it to their email. When i enter my username/email address it says this user does not exist. Contacted Apple support (UK) but they closed for New Years day.

Any advice would be most welcome
 

Gav2k

macrumors G3
Jul 24, 2009
9,216
1,608
Have you tried going to iforgot and answering your security questions?
 

nwlondonlad

macrumors 65816
Original poster
Sep 20, 2007
1,015
729
UK London
Yep but the problem is the person has already changed my apple ID so when i enter my name and apple id it says this apple ID does not exist. I then put in the apple ID that it was changed to but its 'their' security questions that come up in Chinese
 

Jsameds

Suspended
Apr 22, 2008
3,525
7,988
This happened to me, call Apple support and they can reset the account for you, as long as you can answer the security questions that you entered when you set up the account. That part is vital, if you can't answer them to the letter there is nothing they can do.
 
  • Like
Reactions: AJsAWiz

Gav2k

macrumors G3
Jul 24, 2009
9,216
1,608
Yep but the problem is the person has already changed my apple ID so when i enter my name and apple id it says this apple ID does not exist. I then put in the apple ID that it was changed to but its 'their' security questions that come up in Chinese
You'll need to call apple tomorrow. They can't disassociate the original email address from the account so you'll be able to get it back. This is why you should use 2step.
 

nwlondonlad

macrumors 65816
Original poster
Sep 20, 2007
1,015
729
UK London
This happened to me, call Apple support and they can reset the account for you, as long as you can answer the security questions that you entered when you set up the account. That part is vital, if you can't answer them to the letter there is nothing they can do.

Yep that part should be fine, i'm just shocked how someone can actually hack into my iTunes account and then change it to their own. Its almost like someone broke into your home and changed the locks so you can't even get in let alone see what damage has been done.

Did Apple refund you on any credit that was used?
 

nwlondonlad

macrumors 65816
Original poster
Sep 20, 2007
1,015
729
UK London
You'll need to call apple tomorrow. They can't disassociate the original email address from the account so you'll be able to get it back. This is why you should use 2step.

That was my first thought, how did they get past 2 step? Then i checked and see its something you manually opt in for.
 

Jsameds

Suspended
Apr 22, 2008
3,525
7,988
Yep that part should be fine, i'm just shocked how someone can actually hack into my iTunes account and then change it to their own. Its almost like someone broke into your home and changed the locks so you can't even get in let alone see what damage has been done.

Did Apple refund you on any credit that was used?

I know right! Exactly the same happened to me. It's like they changed the locks and the keys.

They changed it to some random email like beixanyxu@163.com

Just get on to Apple support and they'll sort it. Be prepared for an hour long call because you'll have to juggle the accounts round which takes a good while.

Piece of advice, bookmark appleid.apple.com before you call, you need to use that page a fair few times during the process.
 

Jsameds

Suspended
Apr 22, 2008
3,525
7,988
They didn't use any credit luckily, no idea why.

I picked up the emails just a few minutes after it happened (got one saying PW has changed and got another a couple minutes later saying the AppleID and email address had changed)

Time is vital so you should try and sort it ASAP. Good luck!
 

nwlondonlad

macrumors 65816
Original poster
Sep 20, 2007
1,015
729
UK London
It happened at 5am and didn't wake up till around 9am by which time the damage was done. I got two emails. 1st one saying username and password changed, 2nd one was 18 mins later in Chinese saying purchases had been made. My credit dropped from £51 to 17p

Nothing i can do till tomorrow as Apple support not open today
 

maka344

macrumors 68020
Nov 4, 2009
2,144
1,316
London, UK
Did you have 2step enabled?

I use this on everything now as its not store credit I'd be worried about, I'd be worried about someone syncing my data to their device - pictures, emails etc.
 

nwlondonlad

macrumors 65816
Original poster
Sep 20, 2007
1,015
729
UK London
Contacted Apple this morning, the security questions were compromised so they had to verify me by device serial numbers and sending codes directly to the devices. I've now gained access to my account and changed all passwords. The Credit of about £58 will be refunded within 24 hours

For security measures 2 step cant be enabled till the 5th Jan. Thanks to everyone on here for their support
 

Jsameds

Suspended
Apr 22, 2008
3,525
7,988
Contacted Apple this morning, the security questions were compromised so they had to verify me by device serial numbers and sending codes directly to the devices. I've now gained access to my account and changed all passwords. The Credit of about £58 will be refunded within 24 hours

For security measures 2 step cant be enabled till the 5th Jan. Thanks to everyone on here for their support

Glad you sorted it. Sadly it looks like they're getting better at hacking accounts - when they hacked mine they didn't change the questions.

Weirdly Apple never gave me the option of using the serial numbers, they out and out said there was absolutely no way at all to unlock the account if I couldn't answer the questions correctly, which was a pain because I really struggled to remember what I put as the answers because I set up the account nearly a decade ago.
 

Gav2k

macrumors G3
Jul 24, 2009
9,216
1,608
They do it to download music then the either sell it or upload it. Sad really
 

soniasim

macrumors regular
May 1, 2008
172
73
Yesterday, I got an sms from Apple with a 2-step verification code, (I have 2-step verification enabled). It seemed weird to me, because I hadn't put my Apple credentials in any field to get such an sms afterwards... Now that I read this thread, I guess that they attempted to hack into my account as well? Probably yes... Any idea how they find the emails?
 

b0fh666

macrumors 6502a
Oct 12, 2012
954
785
south
Yesterday, I got an sms from Apple with a 2-step verification code, (I have 2-step verification enabled). It seemed weird to me, because I hadn't put my Apple credentials in any field to get such an sms afterwards... Now that I read this thread, I guess that they attempted to hack into my account as well? Probably yes... Any idea how they find the emails?

more than that, how are they cracking the passwords... mine surely is not easy to guess maybe that's what got me safe. Wife's not so much so I will enable 2step for her as well.
 

soniasim

macrumors regular
May 1, 2008
172
73
more than that, how are they cracking the passwords... mine surely is not easy to guess maybe that's what got me safe. Wife's not so much so I will enable 2step for her as well.
I wouldn't say mine is easy either, it has uper letters and symbols as well, also it consists of many digits... Not a possibility to guess it without a hacking software.
It's also weird that I never got the usual email I always get from Apple, saying that my Apple ID was used to sign in to a new device... Very weird...
 
Last edited:

maka344

macrumors 68020
Nov 4, 2009
2,144
1,316
London, UK
Again, did the poster have 2step enabled before the hacking?

My Apple password is complex and not re-used anywhere else, also I have 2step enables. My data is more important than a credit or them downloading music.

Remember, they have access to backups, pictures, emails and iMessage - not a good situation to be in!
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.