How the 2014 celebrity iCloud hack happened: fake emails, real passwords
The 2014 celebrity photo break-ins were not a hack of Apple's cloud. Federal prosecutors say they started with emails pretending to be from Apple and Google, asking people to confirm their usernames and passwords.[1][3] This case file covers how those fake emails opened more than 100 accounts, how the cases ended in prison sentences, and the control that makes a stolen password worthless.
What happened
From November 2012 to early September 2014, a man in Lancaster, Pennsylvania, named Ryan Collins sent emails dressed up to look like security messages from Apple or Google. They asked the recipients to supply their usernames and passwords.[1][2] Many people did.
With those credentials, Collins got into at least 50 iCloud accounts and 72 Gmail accounts. In some cases he used a software program to download the entire contents of a person's iCloud backup, which can include every photo, message and contact synced from a phone.[1][2] Investigators later identified more than 600 victims, many of them women in the entertainment industry in Los Angeles.[1][2]
At the end of August 2014, private photos of dozens of well-known women appeared online, and the story went around the world. On September 2 and 3, after more than 40 hours of investigation, Apple said certain celebrity accounts had been taken over by a very targeted attack on usernames, passwords and security questions, and that none of the cases came from a breach of iCloud or Find My iPhone themselves.[3][4]
How they got in
This was phishing: a fake message that gets a person to hand over their own login. The emails looked like account security notices from the companies people trusted, and they asked for exactly what the attacker needed.[1][2] A second man in Chicago ran a similar scheme from November 2013 to August 2014, sending emails that appeared to come from the security teams of internet providers and pointing people to fake sites that collected their credentials. He got into more than 300 iCloud and Gmail accounts, at least 30 of them belonging to celebrities.[5]
Once the attacker had a username and password, nothing else stood in the way. A cloud backup is designed to be restored easily by its owner, which also makes it easy to copy in full for anyone who logs in as that owner.[2] Apple's own advice in its statement was to use a strong password and turn on two-step verification, which requires a second proof beyond the password.[3]
How it was caught
The FBI's Los Angeles field office investigated.[1] In January 2017 prosecutors announced the Chicago man, Edward Majerczyk, had pleaded guilty in September 2016 to one felony count of unauthorized computer access; he was sentenced to 9 months in federal prison and ordered to pay $5,700 to one victim.[5]
Collins pleaded guilty in May 2016 to one felony count of unauthorized access to a protected computer to obtain information. On October 26, 2016, a federal judge in Harrisburg, Pennsylvania, sentenced him to 18 months in federal prison.[1][2]
One detail surprises people. In both cases, prosecutors said investigators found no evidence linking the men to the actual public leak of the photos.[1][5] The break-ins and the posting online were treated as separate questions. The FBI described the damage as lasting distress for hundreds of victims.[1]
The missing control
The missing control: phishing-resistant multi-factor authentication, so a stolen password alone opens nothing.
Every account in this case fell to the same thing: a correct username and password typed in by someone who was not the owner. A second factor tied to the owner's device would have stopped that login even after the password was given away. The strongest versions, hardware security keys and passkeys, go further: they check the real web address before answering, so a lookalike page cannot collect anything reusable in the first place.
Security questions were also part of the problem Apple described.[3] Answers like a pet's name or a first school are often findable online, so they add little protection. A real second factor does not depend on facts a stranger can look up.
What to do in your business
- Turn on multi-factor for every cloud account. Start with email, file storage and phone backups, since those hold everything else. Use security keys or passkeys where the service offers them.
- Never log in from a link in an email. Teach staff to open the app or type the address themselves when a message says their account needs attention.
- Retire security questions. Where a service still asks them, use random answers stored in a password manager, not true facts.
- Know what your backups contain. Check which company phones sync photos, messages and files to the cloud, and whether that account is protected as well as your main email.
- Watch for new-sign-in alerts. Make sure login alerts go to someone who reads them, and that staff know to report one they do not recognize right away.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Attorney's Office, Central District of California: Pennsylvania man sentenced today to 18 months in federal prison for hacking Apple and Google e-mail accounts
- U.S. Attorney's Office, Middle District of Pennsylvania: Lancaster County man sentenced to 18 months in federal prison for hacking Apple and Google e-mail accounts
- Nextgov: Apple blames 'targeted attack,' not iCloud, for celebrity photo hack
- Engadget: Apple says celebrity photo breach not due to iCloud or Find my iPhone issues
- U.S. Attorney's Office, Central District of California: Illinois man who illegally accessed e-mail belonging to more than 300 people, including many celebrities, sentenced to 9 months