Apple has locked my Apple ID, and I have no recourse. A plea for help
hey.paris
hey.paris
But reading horror stories like this is is why I only use the very bare minimum of any of these cloud services. Keep local copies of everything. For developer accounts, I always create them under a separate email so they're not tied to my personal. At least it can minimize the damage somewhat.
It sucks that I have to take all these extra precautions though. It's definitely made me develop a do not trust any big corp mindset.
It's also the buying of gift cards that can get Apple accounts locked: https://old.reddit.com/r/apple/comments/r8b1lu/apple_will_pe...
If enough of these horror stories are publicized, people will learn to never buy/redeem Apple gift cards because of the real possibility of account bans.
- Don't give Apple gift cards to family and friends: You're potentially ruining the recipient's digital life if they redeem it.
- Don't buy Apple gift cards: You risk ruining your own digital life.
If you've been given an Apple gc for Christmas -- and you have paranoia of the risks -- don't buy anything online that's tied to your Apple ID. Instead, go to the physical Apple store to redeem it. And don't buy an iPhone with it because that will eventually get assigned to an Apple ID. Instead, get a non-AppleID item such as the $249 ISSEY MIYAKE knit sock.
I have thousands of credit-card reward points that could be traded in for Apple gift cards but I don't do it because Apple's over-aggressive fraud tracking means Apple's store currency is too dangerous to use.
I proved them who I am, that the new payment method (virtual card from a well-known organization) is mine, everything.
After lots of back-forth I've been informed their decision is final.
I HAVE NOT BREACHED TOS. I wish I has a major law company behind me to force them to admit that.
Very happy it was my almost unused account, heavily went down with my purchases in mt main account (in my usual country of residence) as well.
And yes, I use login-with-companyName as sparingly as possible. We are not the users, we're beggars.
In addition, I always suggest people to:
- Not use big tech's cloud services - ever
- But if you must, do not use many cloud services from just one provider (i.e no Google everything, no iCloud everything) i.e stop using "one account gateways".
- Needless to say, it's time you had a domain and start paying for mail hosting (at least for critical stuff - you can actually buy a very cheap plan; and use that gmail/live-hotmail/yahoo/iCloud/whatever everywhere else) [0]
- Keep an offline (but safe) copy of your "most" important data [1] and ways to remember (i.e cryptic hints) for your "most" important passwords
- Gain some experience in fighting in consumer courts/forums (depending upon your country) - start early, start with e-com companies. A lot many times we don't put up a fight because we have never done it before and we give up always because every time it's a first time. Apple and Google make a mockery of consumers everywhere because we have allowed them to. In fact sometimes when we talk of lack of accessible support at Google and Apple (yes, Apple) we speak in a disdainful appreciation or awe :)
[0] Some might disagree but disabling (or dev/nulling in a way) mail@, hi@, contact@, sales@ etc on your domain (esp. if you have catch-all enabled) goes a long way in terms of avoiding spam
[1] It's also very important to have a tiered approach to data storage and backup strategies. There should be a very, very, very small subset of your personal data, including some of your photos and videos, that is really, really small in storage footprint that you can back up/sync to multiple locations and actually pay the full price for it at storage costs via your own setup, preferably using FOSS tools (which are becoming too good these days) out there.
At the same time, AML solutions tend to be a closely guarded black box which simply tells you to block a customer, finding out why is pretty difficult.
To add more to the problem, some anti money Landry solutions are … AI powered.
I've been reading about Lovecraft's Old Ones. Apparently they have no ill will towards humans. They just sometimes cause harm without realizing it, while going about their business.
Most likely stolen cards. Stolen credit cards are used to purchase gift cards which are then resold to unsuspecting buyers. Think of it as stolen money laundering.
Of course Support should be able to resolve this if proves are given
Their mega high risk - high value gift cards are effective for laundering stolen/fraudulent credit cards. Buy a $500 gift card with a stolen CC and sell it on FB marketplace for $400 - you’re up $400, the buyer saves $100, Apple get paid by the retailer and the CC company are (likely) on the hook.
Of course the actual solution here is _don’t sell high value gift cards_, or require the Apple ID email at time of purchase/activation of the card
Gift cards are used by phishers. In our institution, we routinely get personalized spam mails (in the name of the corresponding group lead of the recipient, sent via GMail -- this is not low-effort) that ask whether they are available and, when (accidentally) responding, ask for Apple gift cards.
Note that this has nothing to do with the actual well meaning (mostly - see leadership emails leaks) people forming the egregore.
The purpose of the company structure is isolating it from liabilities, and as the regulation which would force it to recognize the damage it did is mostly missing, thus the outcome.
See also https://www.ribbonfarm.com/2010/07/26/a-big-little-idea-call...
This is literally a money laundering pattern
The question will be why isn't this person just adding the money to their account directly, where is this money coming from, why are they structuring it like this
Enough that I am very wary of buying or redeeming gift cards now, especially more than one in a row.
Apparently there's some sort of scam with gift cards, which must affect any platform which allows them, and legit uses often get flagged by automated systems.
If they are so much trouble for Amazon/Apple I wonder why not disallow gift cards, instead of randomly banning users?
If I need to guess, gift cards are sold online in money laundering schemes, also on some platforms they are used to let you buy apps from a lower priced country
And some of them don't even have that!
After nearly 30 years as a loyal customer
I've heard others say this (and was a "loyal advocate" of Windows for around 2 decades myself), but the reality is they simply do not care. You are merely a single user out of several billion.
Many of the reps I’ve spoken to have suggested strange things
That almost sounds like some sort of AI, not a human. But if I were in your situation I'd be inclined to print out that response as evidence, and then actually go there physically to see what happens.
I’ve had Clone Hero running badly on an ancient MacBook for my drums, so I decided to swap it out for an M1 Mini that was collecting dust on a shelf. I did a full erase, but I couldn’t get past its activation lock. At all.
This is a piece of hardware I purchased on my credit card, for my company, (luckily) linked to a phone number I control and an email address on a domain I can control, but Apple in their infinite wisdom are still locking me out of my own hardware because I don’t know the password the last employee used on the computer! I don’t want any data off it, thats gone, I just want the computer I spent money on to actually be usable!
I initiated a “recovery” process to unlock it (at Apples discretion?) and they’ve sent me an automated email saying the initial checks are passed and they will contact me again in 7 calendar days. Kafka-esque doesnt even begin to describe it. So for the next week I have to whistle Dixie!
I’ve been a massive Apple fanboy since I swore off Windows a couple of decades ago, giving them a decent high 6 figure spend over that time and influencing countless others to buy Apple devices. Well that very much ended this week & going forwards without Apple will be painful, but the message they sent me couldn’t have been any louder & clearer. The writing has been slowly creeping on to the wall for the last few years, between buckling to UK government pressure, the CSAM photo scanning nonsense, the absolute UI abomination of this new glass crap, this was my final straw.
I’m also going to be relaying their “message” very clearly and loudly now to any friend or family member considering another Apple device.
It’s almost certainly not, it’s just humans being human and going off script. I worked in a place where we dealt with an enormous number of customer service requests, and one of our measured support metrics was “how often do the agents deviate from what they’re allowed to offer”.
What changed your outlook? Did you get burned by Microsoft?
I once had to help a relative sue a bank who had closed his account after he refused to answer their very intrusive questions (they wanted to know details about distant relatives living in another country). They also refused to return his money (tens of thousands) and refused to explain why. No amount of complaining or escalating made any difference, although we did manage to get a nice recording of an employee saying that he thought the bank was in the wrong.
It took me issuing court proceedings, plus several more months of negotiating with their lawyer, before they finally settled out of court. Even then they tried to not pay the court fee, and they tried to get us to sign an NDA (I refused to budge on both). Altogether, it took 6 months to get the money.
Similar to how people in this thread are talking about mitigating reliance on cloud providers (e.g. with offline backups), I now do not trust any bank. I avoid being in a position where any one bank can ruin my life. That means having multiple accounts and spreading my money around.
Luckily for me I have a legal background so when a corp (big or small) does this sort of thing to me I don't hesitate to sue them. In almost all cases this causes them to "wake up" and start taking your issue seriously, in a way that the front line customer support reps never do. I recommend this to the author of the original post.
iCloud literally encourages users to opt for storing originals only in the cloud. It's marketed as such, it nags you about this every now and then, and iCloud is the preinstalled default cloud storage on every iPhone. Consider non-techies dealing with this too.
Convenience is a hell of a drug.
To me this is the biggest problem. Just like a bank can decide to close your account at any time, it's reasonable that Apple (or any business) could do the same. But they can't keep your stuff.
You can say "don't be naive and assume your cloud data is safe", but in today's world that's like saying "don't keep your money in a bank". The reason I pay for iCloud storage is because it's supposed to be safe (safer than my local HDD going bust or getting lost).
We really need laws for this sort of thing. They should have included it in the DMA for gatekeepers.
Even if in the T&Cs say Apple can do this, which it probably does, now they would have to prove it in front of a judge.
I thought about filing a claim for enough to cover my time in small claims court, but decided not to. I didn't track my time super well because initially I though it was my fault, but, by far, the huge deterrent is the "what if".
What happens if I take Google to small claims court for damages to a domain I've been using for 20 years? I have that domain tied to a legacy Google Workspace account which was a huge mistake. It's been tied to my email for at least 15 years and, even worse, I've never owned an Android phone that hasn't been tied to that Workspace account.
I don't depend on cloud services for much, but if I want to prepare for retaliation I'd have to migrate my email somewhere else and be ready to deal with family members that have their phones connected to the Workspace account. Who's been duped into photo "backup"? Who's been duped into using Google Docs? How many Play purchases do they have? And, the big one, who's been duped into using sign-in with Google?
Google, Apple, Microsoft all make choosing what's best for the consumer very high friction compared to choices that trap users and give all the power to big tech. Even though I constantly help my family members try to understand why the don't want to get locked into those services they always get deceived into using them. The number of family members unwittingly duped into uploading all their data to OneDrive is in the range of 100%.
Apple, Google, and Microsoft need to be broken into 10 or 20 companies each. Excel should be it's own company. Phone OSes and app stores should be different companies. OneDrive should be it's own company and to compete with Dropbox with zero Windows integration. The web browsers should be separate companies. The AI divisions should be separate companies. Split them up with a wood chipper IMO.
The safe browsing scam is the biggest fraud ever because providers can't opt out of it when it "accidentally" detriments independent or self-hosted solutions.
I am surprised that with such a pedigree, the author doesn't already have contacts at Apple they could reach out to for that personal touch.
I mean that. Exec level. This story and that this specific person cannot get it fixed indicates absolute failure.
I have a feeling that this guy also doesn't get why this happened to him and that he himself contributed towards it with the work of his life.
There was a time when I accidentally deleted some photos of which I had only one copy. I blamed myself for being stupid not having a copy but also money was tight for additional drives.
Then there is this: depending on a service provider and then blaming them for something like this. The problem is that now you are losing trust in service providers (of which there should be little to begin with) and on top of that you are also blaming yourself for depending on them. However you have to create a trust model where your fault allows you to have a service helping you with it while a fault at the service provider will allow you to restore data from your end too, getting the best of both worlds.
MacOS and Windows / Google with always logged in systems that lock you out completely at their will is an example of how your devices are not owned by you to begin with and then trusting them with your data as well means your digital life is basically owned by them completely.
Now imagine that there are no humans to solve this but endless LLM bots that respond with generic responses because the LLM has never seen a problem like this. I want to point out that owning your data and hardware is really important if you depend on it and your business especially does.
In a complex modern society, we can’t all be expected to have backup plans to the Nth degree.
Is it possible to bore for my own water supply, install solar+inverter/battery backup for electricity, get a medical degree to treat my own wounds? Sure but most would say it’s not reasonable.
It’s why we have regulations and ombudsmans for healthcare, transport, finance, water provider, electricity providers, communications providers etc.
Oddly missing from that list is critical technical infrastructure providers like Microsoft, Apple and Google.
[Quote]
Yes they do still get activated at the checkout. But when you go to redeem, the code is missing the last digit or two so it doesn't work. People take the unactivated gift card, tamper with it to get inside carefully so it's not detectable, scratch and get the code, remove the last digit or two, replace the scratch off layer, put the unactivated gift card back on the shelf. Then after you activate the gift card at the checkout, they redeem it.
[/Quote]
From this discussion
We all depend heavily on cloud storage and sso . Everything works fine until you are locked out .
And using them isn’t fully voluntary. They are necessary for collaboration . You end up using what your team uses .
You can try to be that “own cloud” snob but it only works if you live in a basement
Every normal person has content in Google , iCloud , OneDrive , Dropbox and maybe more. That’s 4+ single points of failure
You’re just not imaginative enough if you think you’re safe .
OPs only recourse is an insider or a lawyer
It is totally normal in today’s world to depend on cloud services and reasonably difficult to do without it. In China: no WeChat you are practically dead. Here try to join meetings without account, try to send a message on WhatsApp without account, etc… a lot can go wrong very fast. What if you used your Apple account as SSO to other services ?
Yes, those companies should absolutely be forbidden to behave like this, and punished heavily when they do. But until it happens (which doesn't look like it will), your data is your responsibility.
Sure, it is not directly their fault, when they are treated badly by big tech. Though of course they could have been more careful, and rely less on big tech and cloud. We can all learn from this example, like many others before this one.
So, fallacy aside, the abnormals would be...
a) people that don't tech, and b) people that saw the writing on the wall years ago, and either didn't trust the system and didn'tget into it, or those that did for a while, and got tfo.
?
WTF is this about? So you think anyone proficient in hardware/software lives in a basement? This kind of derogatory statement does not belong on HN.
Well, i don't. I have my local file storage. Contacts and Calendar get synched, thats it. These get lcal backups, but aren't important so or so.
Not an average or "normal" computer user? Granted. Not a normal person? No.
It only means that the content is not valuable for them. I know people who created Google Account only because the phone required them to and they do not even remember the password or username, and do not use Gmail (why use email when there is Telegram). If they lose the phone, they would just probably make a new account.
If you were an investor or trader, managing millions of dollars, would you keep the only copy of critical information in a cloud? I don't think so if you are a reasonable person. Would you keep the only copy of a cryptowallet key in a cloud?
ACCC (Australian Competition and Consumer Commission): The primary enforcer of gift card laws, ensuring businesses comply with the three-year minimum expiry, clear terms, and fair practices.
An even more egregious case is the corporate credit card. The company dictates its use exclusively for business expenses, yet pushes all the liability onto the employee. The business gets a massive, interest-free credit line with absolutely no risk. The company gets the float, and the employee gets the bill and the potential credit damage if anything goes wrong.
</rant>
It's hard to believe EU governments are actually considering mandating iOS and Android as gateways to access government services. It's a level of ignorance that's unfathomable.
This story is also exactly why I invest precious time running a Linux machine in the basement that rclones my cloud drives locally, as well as having full local copies of my webmail contents.
While I agree in principle, it's not so bad. If you get hit with an account ban, you just get another device to work with the government.
There's a good reason behind this approach, even though I don't think the benefits outweigh the downsides. These apps are supposed to be the phone equivalent of the NFC chips inside of passports and ID cards, which have all kinds of encryption and verification inside of them. They have to be protected against malicious data extraction, manipulation, and other fakery.
Phones do have the ability to do that, even free ones, and even regular desktops and laptops. How they do it kind of depends on the implementation (whether you call it a "secure element", a "TPM", or a "trusted execution environment"), but they all come down to "hardware proof shows that this digital signature is not extractable or alterable". The data isn't supposed to be something you can access, like a password, but something you can only do signed reads from, like the physical ID chips.
In iOS, that part runs entirely on dedicated hardware which will refuse to run non-Apple code, which is probably the best approach. On Android, there are more options and many phones run a software version of that concept in a dedicated separate virtual machine to save cost on physical hardware. The security of that virtual mechanism relies squarely on the early boot process having been verified not to be altered by malware. That's what the Google verification library is for in this case.
This approach can work just as well on other hardware with dedicated TPMs (although a lot of free software enthusiasts will tell you those are evil contraptions designed by Microsoft to turn your unborn children into little versions of Clippy) or dedicated encryption modules. However, you'd need a common enough, accessible API for those to function. That's actually quite easy on Windows and macOS, but Linux TPM support is rather woeful at the moment, especially with how uncommon things like secure boot (even self-signed secure boot) are.
In practice, nobody is going to buy a special sort of yubikey to log into their government's tax portal. Dragging people into basic multi-factor security has been a challenge that lasted decades.
However, pretty much all citizens already have phones capable of top-of-the-line security verification. Developing a free app is a lot easier than implementing cross-platform HSM support for a novel authentication mechanism.
All of this comes at the cost of having to run vendor-approved software. That's a huge problem for a lot of HN visitors, but those people form a sliver of a fraction of the population. I'm willing to bet the EU's digital access is inhibited more by the amount of old people without cell phones than the number of people who care about free software.
I personally feel like outsourcing this kind of trust to closed source implementations of vendor blobs is a terrible idea, but it's hard to find an accessible alternative that provides even the lax security properties those blobs provide.
Something I do find lacking in discussions about these technologies is how much the EU is relying specifically on American vendors here. America has been shown to be an unreliable ally that will gladly force the EU's hand with whatever mechanism comes to mind for extremely arbitrary reasons. There is a distinct lack of European alternatives when it comes to accessible secure computing, and I'd rather see the EU invest in local alternatives than go all-in on the security promises from Apple and Google.
You don't have to self-host everything in your basement, and you don't have to hand your entire digital life to Google or Apple either. Mail, CalDAV/CardDAV, Immich, Nextcloud, OpenCloud, OpenTalk, web hosting, Kubernetes, simple VMs.. whatever ... fully managed, run by local or independent providers or by the company behind projects, without Big Tech lock-in. If chosen wisely, you can migrate, take over, or bring it in-house when you want. Just spend a few bucks and do some company research. Same as you would when choosing craftsmen, lawyers or something else.
For example, that's actually how we operate as a company for some of our customers and even a few single persons: we provide SaaS AND setup documentation. Customers can transparently take over at any time. We even help separate domains, credentials, and administration from us. Convenience without captivity. I am sure there are hundreds of shops like ours, providing comparable services for people in their wider neighborhood.
As for Apple fans, they specifically seek the vertical integration.
In the past people have emailed Tim Cook directly - his email id is fairly easy to find.
Edit: "I have escalated this through my many friends in WWDR and SRE at Apple, with no success."
This doesn't bode well.
One day the engineers will try their best to fix things, but get stopped by management satisfied by high-nines logic. If anyone is falling through the cracks, it's bad customer support.
This bodes poorly indeed.
WWDR stands for World-Wide Developer Relations and SRE stands for Site Reliability Engineering.
How are people handling this these days? If i wanted to ensure a full backup of everything on my iCloud to a NAS, what's the best way these days? Seems like they make it difficult by design..
What I’m not sure about is how to backup things like iMessages, Notes, and my Contacts. Every time I’ve looked, it appears the only options are random GitHub scripts that have reverse engineered the iMessage database.
Google and MS don’t charge as much as Apple for storage, and you probably need you need to pay beyond the free limits, but it’s not a huge expense.
Once your installed Google Photos and One Drive on your iPhone, just tell the apps to sync all your photos all the time!
Now I appreciate that isn’t for everyone.
But it works, is reliable, and requires no technical knowledge of running your own service.
The other thing to do is setup a Mac that synchs all your iCloud data, One Drive documents and Google Drive.
Then back up that device with Backblaze.
This gets expensive as a Mac with decent levels of storage isn’t cheap!
I live in fear everyday or my primary Apple and Google accounts getting locked!
I’ve had accounts since day one of iTools and very shortly after Gmail launched….
I don't have a solution for iCloud Drive, as there wasn't a keep offline setting last time I checked. So use it only ephemerally.
It copy Photos, iCloud files and my mails once every days to S3 with incremental backups.
It requires to have a full copy locally.
Works great!
It is not hard to configure once, with the proper folders and settings.
You could put Immich data on a LUKS volume I suppose, but then you have to fiddle with your server every time it reboots.
I did PhotoSync for a while, but now I just set up my Mac to download my whole photos library, and do Time Machine backups of my Mac. This gets two copies of the data not tied to my Apple ID (the one on my Mac's local disk, and the one on my NAS on the time machine volume).
Syncthing is wonderful, and does a great job of syncing between an Android phone's photos/videos and a laptop. And if you have regular automated backups of the laptop, you'll have backups of the photos/videos too.
For an iPhone, perhaps you could use iTunes to sync to a computer and back up that computer.
(One of these days I’ll setup my NAS to backup offsite fo a #3 backup).
I know that others with Macbooks sync their whole library to their Macbook and then Time Machine to a NAS as their copy #2. Is this vulnerable to the problem in TFA?
I will also never have an electronic ID. We (Switzerland) were dumb enough to vote yes for it but we are giving away our freedoms eventually.
We need regulations to ensure vendor cannot lock in users and cannot threaten them. Everything should work like if you have your own domain and use email. If your provider go nuts, move your hosting and change your MX and point your local copy to it.
This should not be reserved to some nerd like me, it should be an universal right.
It is already late, but it can be reversed. We need for more sotires like this one to errupt, so people understand.
I personally prefer this to sending a copy of your ID and a video with my face to someone verifying service provider that verifies my identity for a bank or some website.
What's the link with the rest though? Your government already knows you, whether your id has your information printed with ink or stored on a chip.
Belgium has had electronic id for decades now and I fail to see how it has taken away any freedom, but it has enabled people to get their official documents online without having to make appointments in person in most cases.
Exactly, for all the victim blaming in other comments, try to explain 3-2-1 backup to non-technical people and you'll be met with glazed eyes.
Sadly I think it's going to take more people losing their irreplaceable data and for the network effect of having it happen to someone close to actually see any change.
There's a surge of people losing their Google accounts with hackers abusing parental controls at the moment, although I suspect a lot of those people will just move to Microsoft or Apple thinking they're safer until they get burnt there too.
As more non-deterministic AI is built into abuse systems it's inevitable that there'll be more false positives, couple that with impossible to access human support to override the decisions, it's a risky time to trust your irreplaceable data with anyone but yourself.
You could do everything right and still get locked out.
Feel free to chat to me on Bluesky (https://bsky.app/profile/hey.paris) or Mastodon (https://cloudisland.nz/@parisba) or email if you have ideas. I've received nearly 500 emails!
I've had to do it before, also for a gift-card-related problem (different from yours), and I was contacted by a member of the Apple executive escalations team a couple days later.
I did read about part of the product development org having a standup about trending social media cases, and prioritizing followup on items that were under public scrutiny.
I imagine it could be helpful to other people in the same situation.
I can understand this happening if it was a freshly created account topped up with a sus gift card but it’s unacceptable that the first action is to completely block an account with history.
Even more concerning is the nonchalant support response to “go create a new one” with emojis. C’mon Apple — this is just a terrible way to respond to this situation.
2. Last time there was a post where this happened to someone, I looked into what you can do if you're locked out of your Apple ID or Google Account.
I know people will say "just self host", but all of the self-hosting solutions are not friendly to families or non-tech people. Telling my extended family to tailscale into my server to look at family photos from vacation is a total non-starter. All of the self-hosted solutions are also just way less smooth to use than the built-in integration iCloud or Google Drive gives with devices.
That said, there are straightforward options to deal with this (at least the data part), if you plan ahead. The high level strategy is to setup backups that let you get _a copy_ of your data not tied to any login you don't control. It's a bummer to have to go through these hoops, but again pragmatically, I'm stuck using these services to participate in modern life.
For Google Drive, you can rclone your data to a computer of your choice to get a copy of your data not tied to Google Account. It will even convert G-Suite files to Microsoft Office format, so you have a copy of the data offline.
For Google Photos, I'm not aware of a great way to get the data - rclone only gets low quality copies of photos. I'm an Apple user, so I didn't dive too deep here, perhaps the HN hivemind knows.
For iCloud and Apple Photos, you have a lot of options. You can use Parachute backup or the PhotoSync App to get a copy of your data not tied to your Apple ID. If you have a mac, you can also setup your mac to download everything offline, and do time machine backups - they are not tied to your Apple ID.
I will also add Synology NASes have a super, super easy to setup way to do all of this stuff (HyperBackup plus Synology Photos app) that's borderline worth the cost of admission on it's own, even with Synology's recent turn to the dark side. If you have non-technical family, you should strongly consider pointing them in this direction, if you can use a smartphone you can probably get this working.
The built-in integrations (iCloud, Google Drive) are smooth right up until you’re locked out or forced into changes you can't control. Obviously.
There is a middle ground though: managed service providers (per-service). You don't have to self-host everything in your basement, and you don't have to hand your entire digital life to Google or Apple either.
It's not really about winning the claim. It's about getting them to acknowledge you and hopefully resolve it before the court case comes up. That is, you want them to "settle" by restoring your account.
IANAL and YMMV.
(With the exception of some services like their credit card, but you can opt out of that more easily than any other arbitration clause I've seen.)
If the only way to get your digital property back is a public plea to your Lord, that's called feudalism. Everyone should be treated fairly, not only those who can get their public pleas heard.
You should approach a lawyer to petition Apple and the Tasmanian police on your behalf.
Mine was the same, and that's all it took. Nothing was lost, as the account itself remained the same.
That‘s always the most kafkaesque part of these problems and should be illegal
Of course, this is absolutely silly and beyond absurd, for bad actors share information of forums, can deduce fairly easily, and even have help from people on staff.
Such actors typically know about detection and flagging methods within days of implementation. There's literally zero benefit to secrecy. None. Security through obscurity can be a beneficial additional layer, but it simply never helps here.
We really should pass a law requiring full disclosure of the precise method of banning. I can even see a 'trial' period, where accounts activated (and used!) for 3 months receive this benefit, but new accounts, or new + dormant accounts do not.
This should likely be coupled with mandated full refunds of phones or computers, as an example.
Note that this isn't a 'free' account we're talking about here. An Apple account, or a Google account is required to use an iphone or pixel in its default config, and all the features it entails. These accounts aren't free, they're part of purchase cost, and core-required.
(Even if it's a, for example, Samsung phone? It comes pre-installed, with uninstallable Google Play cruft, as part of an agreement with Samsung. Same conditions need apply here)
it is very likely illegal to tell him. it was triggered by the use of a gift card, and therefore very likely to be AML, and in many places (I am not sure about Australia specifically) it is illegal to provide information in the circumstances.
Given how invested you are in the Apple ecosystem I can’t fathom why you would go get an Apple Gift Card from a store to do this kind of transaction, though. It wouldn’t even cross my mind to do it that way.
You can even use this to get an effective discount on hardware, as you can use your Apple account balance to buy from Apple.
Obviously I'm not claiming it was OP's mistake, that wouldn't make me any better than the guy who was telling people "you're holding it wrong™".
We are obviously not going to get a fuller idea about this situation from a blog post, and while I won't assume that the author has done anything wrong, there have been similar stories in the past where the affected individual was deliberately withholding the whole, much more illegal, story.
Presuming his innocence: What could have happened here is that the gift card he's purchased has been marked as part of a scam operation. Apple gift cards are frequently used for "tax bill" and "police fine" scams in Australia (where they are sold there is often signage informing people of that.) So potentially this person is accidentally roped into that.
Also it's not entirely unheard of to purchase gift cards for long-time users (who would normally just use their linked credit card), as the cards are often sold in the retail space with a 10% discount, or can be redeemed as rewards through points/loyalty schemes.
With all that said, at this point if he's not getting anywhere, he should approach a lawyer, as they'd be able to petition on his behalf (whether that is to Apple or to the state of Tasmania.)
Perhaps between the scammer redeeming it and the poster then trying to redeem by entering the same code, the scammer’s account was flagged and then the OP’s account terminated along with the scammer for using the same code (even though the OP had done nothing wrong).
It makes me so mad, that's insane!
"I understand, relieved face"
Literal psychopath reply.
At the Apple Store, the employees suggestion (a more senior one, who was consulted) was to buy a gift card for the computer’s cost (~$1500) and pay at the online store with that. I didn’t do it because buying “virtual stuff” for that amount seemed crazy (this was a huge amount of money for me, at the time).
One day he was bricked from his accounts because he ran afoul of Apple’s ToS. The problem then was I couldn’t feel sure that he hadn’t actually done something which a reasonable person would say should result in account closure.
Paris’s case is much more strange, because it feels more likely to be a false-positive.
There is no legal right to have an account with Apple or Google, and I’m not sure I want there to be. But so much of our lives are built on these services and these stories erode our trust that the services themselves can handle the responsibility of adjudicating acceptable use. We need our digital accounts to be robust in the very long-term, even when there are bad actors who want to do all manner of bad things. And we need to feel confident that a properly empowered human reviewed the case and can articulate the reasons for a ban. When we charge a person with a crime, we tell them what the crime was and give them due process to fight it. I’m not sure I want the courts to decide these questions but we need some more due process when it comes to account termination.
There shouldn’t be a legal right to an account, but there absolutely should be a legal right to sit down with someone from the company to plead your case, understand why the account was locked, and at least be given the opportunity to gather your things if they decide not give you a second chance.
If you get evicted from an apartment they don’t just change the locks and keep all your stuff…
You could make it so costs for arbitration could be paid up front by the person appealing and then if the account deletion was deemed wrong the company refunds said user. Could probably apply to monetisation on YouTube that I see withdrawn for very dubious reasons too.
People running scams that will shamelessly and relentlessly pull any string at their disposal to keep their account running.
Update 14 December 2025: Someone from Executive Relations at Apple says they’re looking into it. I hope this is true. They say they’ll call me back tomorrow, on 15 December 2025. In the mean time, it’s been covered by Daring Fireball, Apple Insider, Michael Tsai, and others, thanks folks! I’ve received 100s of emails of support, and will reply to you all in time, thank you. Finger’s crossed Apple calls back.
Second Update 14 December 2025: No luck so far, and not looking good. Anyone got a good lawyer to send them a letter and/or help me sue them? paris AT paris.id.au
Update 16 December 2025: The Register covered it. No luck yet.
I know this might sound cynical... But the author should really understand that Apple gives less than zero fcks about them. Apple is known (and, weirdly, loved) for being tyrannical in this sense. Apple is known for their "my way or the highway" approach to anything, without much explanation and with self-attributed "we're always right" attitude.
> The Damage: I effectively have over $30,000 worth of previously-active “bricked" hardware. My iPhone, iPad, Watch, and Macs cannot sync, update, or function properly. I have lost access to thousands of dollars in purchased software and media.
And that's why people complain about Apple's walled garden. Given the size of the damage I'd look into getting a lawyer involved, and possibly try and get Apple to court (in coerce them into being reasonable).
Frankly, I'm taking note of the archived page (https://archive.is/jrsLV) that I will reference to anybody that will ask why not to trust Apple in the future. Note that Google is also known for having a similar approach (there is no way to get support if something like this happens UNLESS you happen to know somebody inside google). Amazon on the other hand has made customer support one of its defining traits.
Btw if you are doing any decent amount of tech stuff, you should REALLY get off walled gardens and at the very least have an on-premise backup solution (an off-the-shelf nas with spinning disks could be a good starter solution).
Why in the world do we let tech companies adjudicate our service relations?
Update 18 December 2025: We’re back! A lovely man from Singapore, working for Apple Executive Relations, who has been calling me every so often for a couple of days, has let me know it’s all fixed.
It looks like the gift card I tried to redeem, which did not work for me, and did not credit my account, was already redeemed in some way (sounds like classic gift card tampering), and my account was caught by that.
Obviously it’s unacceptable that this can happen, and I’m still trying to get more information out of him, but at least things are now mostly working.
Strangely, he did tell me to only ever buy gift cards from Apple themselves; I asked if that means Apple’s supply chain of Blackhawk Network, InComm, and other gift card vendors is insecure, and he was unwilling to comment.Maybe now we will start seeing a reversion to the people in it for the passion.
Hackaday is a content aggregator site that usually has more content on these topics - https://hackaday.com
Or there are still some good old blogs out there with RSS feeds http://www.righto.com/ http://oldvcr.blogspot.com/ https://blog.ret2.io/
You assumed wrong. Honestly that was never case, but maybe it was better 15 years ago
I'm curious about the apple's passwords app. Where you able to use it? What about passkeys?
Don´t check in to Hotel Cupertino or soon you'll be singing along:
Mirrors on the ceiling
The pink champagne on ice, and she said
"We are all just prisoners here
Of our own device"
And in the master's chambers
They gathered for the feast
They stab it with their steely knives
But they just can't kill the beast
Last thing I remember, I was
Running for the door
I had to find the passage back
To the place I was before
"Relax," said the night man
"We are programmed to receive
You can check out any time you like
But you can never leave"How many account lockouts must occur before we accept that digital life built on permission rather than ownership is inherently fragile?
https://skogsbrus.xyz/dont-put-all-your-apples-in-one-basket...
The Stockholm syndrome is real.
If this situation somehow escalates until they have to take action, they will already have made so much money that is not a blip.
They don’t care. You as an individual customer means absolutely nothing.
This does not seem strange to me and could be a course of action. When I moved my domains off Google because of this type of "banned without recourse" possibility, I found a registrar that had a physical address, small office, and people listed on the company website (porkbun) so in the worse case I could fly to the office and straighten things out.
No mention of even going to an Apple store. Maybe the nearest one is very far away from him?
She told me to email Tim Cook directly (his email is entirely guessable).
I did this and within a day or two my access was restored.
Absolutely horrible black mark on Apple.
I'll be buying an external HDD to download all my photos / iCloud docs to. I've been too trusting.
Since then I have been removing myself from the ecosystem - my email is from hey, file sync on Dropbox, obsidian for notes, whatsapp for messages. Sometimes it doesn’t feel as joined up, mostly it is way better.
Moved to framework computers + omarchy last month and am not looking back.
Slightly different issue involving the Apple credit card, but it’s just as insane that there’s no separation between the different parts of Apple.
For that reason I will never have an Apple Card, and I guess I won’t be redeeming Apple gift cards with my Apple ID.
Any company or entity ought not to be allowed to wield power over our lives, like locking someone out arbitrarily, let alone via some asinine, half-baked algorithm.
Musk/Jobs archetypes, though unpalatable at a personal level, are valuable in their willingness to burn themselves up to fight the "system" vs bureaucratic types who just fall in line and elevate what is a political issue into a Sacred Value
Time to say bye to Apple and Google for good...
If you are buying large amounts of gift cards and then redeeming them, it is critical that your purchasing patterns do not look suspicious, such as buying more things that a normal user might need: multiple iphone wallets, multiple iPhones, or similar items.
I've started on my de-appleification plan in earnest this year:
Break that discipline and you are exposing yourself to this danger.
Nevertheless, the irony of this is overwhelming: a guy who spent his life promoting a company whose model is "we deeply control the products you use" gets burned by the fact they deeply control the products he's been using.
The thing is, that account was just used for dev. things for the US company, which builds/sells software for the US federal government (among the other US entities).
It would not be very wise to do fraud.
No appeal, no reasons given, no possible way to create another account.
Just. Banned.
The companies need to be big enough to provide the amazing services they do, but once they are large enough they will never care about individuals.
My internal model of large companies is that they are intelligent, psychopathic aliens. The people in them are like cells in our body, important for the function, but with no agency, and they are not who you are dealing with.
You're dealing with the company, and it's an inhuman, psychopathic alien.
"I have contacts in Apple, I'm better than all those losers". Well you were, until you were not.
Also because I know big tech has no real customer support.
It’s no comfort to OP though and I feel very sorry for them.
And there are also separate bodies for each state.
On a meta note, Fuck Apple, I'm so glad I didn't pursue an iOS developer career 10 years ago.
I've managed to reset the password, but I must answer a security question to log in. I mean, I answered those security questions probably a decade ago and I do not know what they are anymore. You can reset your security questions, but to do that you need to use an iPhone (last one I owned was a 4) that is still logged in, or, answer a security question. Which is as we established, the problem.
So every couple of months I log in, try a few other possible answers, get them wrong, and get locked out for a bit.
Anyway, I need to get this fixed my march, due to apple being the formula one streamer in my country now, so I have to actually solve the problem of logging in to my apple account. Or, I guess, making another random email just so I can watch f1. Sigh.
But if anyone knows how to reset security questions, I'd love to know. I would way rather pay apple actual money than go back to torrenting the races.
Not too keen on passkeys without an easy way to backup.
Same goes with sign in with Google and Apple.
Am I missing something? My current perspective is that not only am I free of all the hassle that comes with building for a closed ecosystem, such as managing a developer account and using proprietary tools, it also comes with much harder distribution. I can put up a website with no wait time and everybody on planet earth can use it right away. So much nicer than having to go through all the hoops and limitations of an app store.
Honest question: Am I missing something? What would I get in return if I invested all the work to build for iOS or Mac?
My own experience with big tech account bans was much milder, so I learned my lesson without much pain. I got a "free Azure credit to learn cloud computing" email from MS, redeemed the credit, created a VM, started clicking around the settings and got locked out. Raised a support ticket, asked what I did wrong, told my account was flagged for suspicious activity. I asked what I did wrong again and got a reply that my case had been reviewed by a human and that my Azure account wouldn't be reactivated. Thankfully, my primary MS account didn't get banned for that.
Conclusion #1: it's frankly insane that a big tech company can fully terminate your account with no means of recourse. People like to mock the EU and its lawfare, but I think it is the best candidate to force the tech firms to implement some sort of firewall between their various services, so they can't terminate your access without prior notice or without compensation.
Conclusion #2: those who are reading this, don't put all your eggs into one basket and teach your friends and relatives to do so as well. That is, if you have to use the services of various big tech companies, spread them around. Have a boring account with one company that you use for free stuff, a boring account with another company that you use for paid services (if you can purchase services X and Y from two different companies, do so), a boring account with a third company that you use for getting paid, a fourth account that you use for shitposting and getting into arguments with internet strangers.
- that Apple *can* always *just* disable their account
- that Apple regularly *does* do that
- that Apple does not care about them at all
and they chose to bet their entire digital life on Apple's benevolence anyway. They lost that bet.We need more stories like this hitting the mainstream news until even a non-technical person's reaction to this is "well, what did you expect?"
Centralization of power in unaccountable organizations has always been a recipe for disaster.
I could suggest some slogans:
"Apple. Not even once."
"Friends don't let friends use Apple."
But I think this is a problem that merits more than slogans.
I have fresh experience of setting up Azure/M365 and AppleDev for my startup. Those things are scary as f*uck, in many perspectives:
(1) Dark patterns everywhere (click this checkbox and we'll buy you a license, oops +xxxxx €/$ per year just came; get one-month trial for O365 to get bizaccount, select 1 license, see that there is 25 licenses (~ 4k €/$) to be renewed if I don't cancel).
(2) Microtransactions everywhere (e.g. Azure VM SSD I/O: every read/write operations costs), DDOS and 10/100 k€ bill coming. Everything "scales", especially bills. And no billing caps, of course.
(3) Codesign with Microsoft: I have option to wait weeks for freight ship to ship USB cert token (if it ever survives past toll/postal service after that), or use AzureKeyVault, but that is officially only for companies that has taxes/accounting for 3 years of operation. So no startup can use that by this requirement to codesign?!
(4) AppleDev (and kind of Azure/MS too) requires DUNS number, which takes 6 weeks to get in normal case. Apple's 5 bizday route doesn't exist anymore (at least not for non-US-based companies). Or just use D&B magic link from Grok and get it immediately in 5 mins.
(5) If you base your business on Azure/M365 and AppleDev and be obidient and compliant (as I am doing/being, because I'm building real legit and long-term company, not some hussle project), it still doesn't matter, because they can just can decide by human/ML to shut your business operations and means of living. And getting answers like in the title's article's screenshots with those emojis are just the most non-human interaction that there can be done for affecting so devastatingly to someone's life/business.
These are the most disgusting things that I know of.
Seriously can we fucking have any products that work, in the 21st century
Or is the answer just "lol automation is cheaper"
Why do people still do this, why??!? This is not an ignorant user! The author (and victim) has written several books about Apple tech, how do they not know that these "platforms" cannot be trusted with anything -- especially data that isn't backed up somewhere else!
Companies don't care about people, and the bigger they are the more evil they behave. They need to be treated like hostile business partners because that's what they are. They're only after money and absolutely nothing else.
This is not some radical leftist manifesto, it's the plain reality. And it's not new either. It's always been like this.
you can in the meantime, and for the future, try compartmentalizing services you use. the old saying of "all eggs in one basket" applies here as well.
VPS, hard drives, etc. are cheap and keep you more in control of your own data than you're with big tech.
...and then nothing. No sorry, no "here's what went wrong", no blog post to address the angry masses, no recognition, reconciliation, or reformation. Just things working again and silence.
Apple Support told me these “decisions are taken in a higher department” and escalated me to tier 2, who insisted: “we’ve determined your account doesn’t meet the conditions to enable it.” Their suggestion was for me to create a new Apple account.
Then, three days later, my account was suddenly re-enabled; and it has worked perfectly ever since, as if nothing happened.
I hadn’t used gift cards in nearly a decade, so my guess (and this is pure speculation) is there must be other flags affecting older accounts.
The whole episode was utterly kafkaesque, and it’s made me much more cautious about relying too heavily on the whims of our private megacorp gatekeepers.
Google and Apple can and will delete your content at any time for any reason and there is no appeals court.
I don't know what the solution is, but I think part of it is deliberately divorcing yourself from the big players as much as you can, which isn't much for some people, and encouraging government efforts to break them up and pull down garden walls whenever the opportunity arises.
This is what government is for even if we've forgotten it in some places.
Well, it can always be you.
Incidentally, the guy's .paris domain name may be next unless you are a resident or have a business related to the region of of Ile-de-France
The stories of online-only service failures are legion. And yet if you can get face to face support, even one person can do so much. The gap is infuriating.
I didn’t notice, do you have a Brick and Mortar Apple Store you can visit? I can’t help thinking this as I read the post.
Of course this is not a physical hardware issue. Where a store employee could just hand you, say, a new phone. This is on the level of getting a slot on Tim Cook’s day planner, though I imagine the person with the ability to fix this is an underling many levels down Cook on the org chart.
This is the kind of thing they need to be sued on a massive scale for to solve but it's too rare and too expensive for anything to ever happen to them for it.
They feel convenient, but they will keep changing their TOS to disadvantage you further and further as time goes on.
Everything you upload is scanned into their AI to create a profile about you that they can then exploit (once again, to your disadvantage). They do it despite regulations against it (Who's to say what they're complying with, deep in their complex data centers? Who's gonna even check? And how?) This is why online services that take control of your data are such gold mines (subscription fees, analytics, profiling, etc). They get you coming and going.
And of course, the account terminations: The earthquakes and "natural disasters" of the online world that destroy lives with no consequence or care.
When your data is not in your sole possession, you own nothing.
On the other hand, great learning case on putting eggs in one basket and on "own nothing and be happy".
I don't like that people just shrug and say this is how all big tech is.
Apple charges a premium and built their brand name on customer service.
But they have stopped caring about the customer.
I was also a loyal Apple customer for 2 decades and used to recommend them to everyone.
Now I recommend them to no one.
I've switched my phone back to android a few years ago to avoid apple lock-in. I still use an ipad pro and several macs and peripherals, sets of airpods and apple tv and what not - then I wanted to buy the watch - and was told it cannot work with any of their tablets or computer and cannot be activated without an apple phone. OK apple.
One day my debit card expired while on long overseas travel, suddenly I was unable to install apps I already paid for on my mac and other devices, update any apps, or install free apps, I could not pay with a different card because those were in a different region and would have required a region switch locking me out of a lot of content and apps. So for several months I could not install many of my apps I bought on my other sevice or update or install free apps. OK Apple.
I also remember how the base config of Apple laptops were 8gb ram and 256gb SSD when all other decent ones were on 16 and 2tb - and remember apple is supposed to be a premium brand and they're supposed to not burn you with a default config. OK apple. Then they charge you 3 times more for the upgrade from 256gb ssd to 2tb than what 2tb costs retail. OK Apple.
I still love their tablets and laptops and even the mac mini. But I've already started to mentally prepare for a switch to Linux and maybe x86 or other hardware.
Apple cannot be trusted. They are a fashion company and not a tech company any more. Jobs is dead.
Plan your exit, reduce your exposure, soon they will be so evil and dysfunctional that you will regret it.
Don't trust them with your most valuable data. Use other services. Use a diverse mix of providers, no apple exclusivity. If you tie your entire life to one cloud, especially Apple, you have set yourself up for future ruin.
Their software quality and reliability is also slowly slipping. Everything is being dumbed down. Their business processes are becoming a broken maze. Apple used to be a company that aimed to satisfy simultaneously the power user and the basic user, now they only care about optimising for the casual user mass market, power user is going to have an increasingly tough time with them. Remember it is now a fashion company, watch their keynotes and believe the vapid image they project.
Even though I:
- had my recovery password
- re-confirmed the email
- re-confirmed my phone
They just kept telling me "we'll contact you in two weeks", and kept not following.
Then after the 4th recovery they sent me my recovery link on email (in any case weeks later).
Worst of all? Their privacy and security they keep repeating like propaganda are beyond bogus. Sure, they de-logged me from all of my accounts, that I appreciate, but I had 0 issues accessing all of the contents on my hard drive if I was a thief with a simple script in recovery mode I could still access everything. Where's the security? Propaganda only non-technical normies believe and then repeat.
I'm never ever buying Apple products ever in my life, I've got MBPs that my clients send me, but that's it.
Speaking of which, the guy's .paris domain name may be next unless he is a resident of Ile-de-France etc.......
If this doesn’t get fixed, I’m going to have to rethink a lot of my digital life, including my company’s.
I mean, isn't writing what you said you do for a living?
Let's just hope more people read the story.
PS: My plan is to wait for Apple to release a folding iPhone to move back!