4 ms·
I had very similar questions for Apple, but they refused to answer most of them. I’m confident my Apple account wasn’t compromised directly: - Apple confirmed
by zenexer 4y ago
I had very similar questions for Apple, but they refused to answer most of them.
I’m confident my Apple account wasn’t compromised directly:
- Apple confirmed there were no login attempts around the relevant time period
- I have 2FA enabled, but I didn’t receive any approval alerts and couldn’t have leaked the number even if I had—I was asleep at the time. This doesn’t rule out malware, though.
- All authorized devices on my account were in my home. My home was locked.
- I use a randomly-generated password. That doesn’t rule out phishing, though.
Session stealing is still a possibility, but Apple seemed reasonably confident that hadn’t happened.
Initially, I was promised a call back from Apple’s fraud team. However, after closing they investigation, they refused to talk to me directly. They wouldn’t even tell me the IP address used to check out.
I do know that the order was placed on the website, rather than in a store.
As to why they would use my shipping info: I still don’t know. If they entered the info manually, it’s awfully convenient that it exactly matched the info on my Apple account, considering most companies don’t get that info.
I do know that T-Mobile and Citizens Bank both have that info, since I have T-Mobile as a carrier and am enrolled in the iPhone Upgrade Program. My T-Mobile billing info didn’t match exactly, but it was very similar. Citizens Bank matched exactly. I’ve now given both Citizens Bank and T-Mobile unique email addresses that differ from my Apple ID.