The Towson Hack: The mystery of vanishing iTunes credit
macworld.com
macworld.com
I can't imagine they are selling accounts to people who are actually using them and no one outside has noticed. If you want to steal apps there are easier ways than trying to purchase a compromised iTunes account. Stealing an account or purchasing a stolen account is a good way to get in a lot of trouble (it also shouldn't be hard for Apple to figure out who's doing the in-app buying--you have their device ID). This is for in-game credits, so simply jail breaking and installing from Hackulous won't do the trick, but I have doubts that a bunch of people want to risk going to jail just to play KingdomConquest on iOS.
They're converting in-app purchases to cash somehow.
In the past I have bought in-game money with real-world money. A character would turn up in the game to meet your character at a pre-determined locations, and complete the deal. (Usually ;-) )
I'm guessing something like this is happening. If that was the case, I'd like to think between Apple and Sega they could work out privately between themselves who may be involved in this.
"Their store credit is being drained before PayPal because that's how iTunes works, uses your credit first. You don't have to choose credit vs. PayPal.
They aren't hacking those that use Credit Cards (VISA, MasterCard etc) because any purchase from a new device has to confirm the security number on the back of the credit card.
Thus the attack is only going after open (non credit card) accounts, possibly phishing, possibly dictionary attacks, or any other form of hacking."
That is, valid purchases were being made, but the wrong account was being charged/edited.
Of course, I have no proof of this. It simply struck me as strange that a hacker would reset the town to the same thing in the accounts. What purpose, unless it was the hacker's signature.
I would guess that this an inside job that exploits a flaw in an account address change procedure. That would explain why Apple couldn't resolve the problem by patching up iTunes protocol, which would be the reasonable thing to expect if the flaw was exploited from the outside.
I would say that Apple's actions around refunds are just a simple way to make sure they don't take too much bad press while they try to find a way to prevent this from happening.
10 songs from this guy who I've never heard of - http://stantonlanier.com/ and N.O.V.A. - Near Orbit Vanguard Alliance, v1.2.1, Seller: Gameloft (12+)
Both were from my store credit in the span of a day. I changed my password and have been good since then, didn't think about complaining to apple as it was only like $15.
Three devices (2 iPhones & an iPad).
For what it is worth, I was using the same password as my "normal" internet pass. Promptly changed to unique one and that saved it, so not sure if it could have been a phising thing or a stolen pw (although I'm typically very diligent about it)
Disclaimer: I am a satisfied 1password customer (iPhone and OS X) who is not affiliated with the agile.ws team in any way.
If the hack is genuine, it reflects one of the biggest problems Apple has, in that while they may be able to handle individual complaints quite well, they fail completely at handling overarching issues that affect a large number of people, which just permeates the impression that you sometimes get that Apple is a completely closed culture, not subject to outside scrutiny. This is not a good thing.
At any rate, I am certainly intrigued, and I hope very much that if Apple does nail the issue, they release details. Which may be optimistic...
If the criminal/s (or the original instigator/s at least) are using the Store Credit to buy their own Apps, they wouldn't want the payment to be stopped. Seems like Apply is giving them that payment (less Applue's 30% of course) and refunding the victim - Apple is out of pocket, but the criminal is still paid.
If so it's not so risky as the sucker will end up being the player who bought the items and I doubt anyone ever pursues their claims as they've invariably violated the TOS of the game.
Edit: The more I think about this, the more genius a way to monetize this hack it is.
The address change is probably the 'verification' step to be sure they have the correct password.