How 2 support calls wiped a journalist's iPhone, iPad and MacBook
In 2012, attackers erased a technology journalist's iPhone, iPad and MacBook in about an hour without writing any malicious code. They made support calls to Amazon and Apple and let each company's help desk hand over what the other one used to prove identity.[1][2][3] This case file covers how 2 helpful support calls added up to a full account takeover, what the victim lost, how both companies changed their rules within days, and the control that was missing.
What happened
On Friday, August 3, 2012, a well-known technology writer watched his digital life come apart. His iPhone shut down and asked for setup, and his laptop asked for a PIN he had never set. Within about an hour, attackers had taken over his Apple iCloud account, his Google account and his Twitter account.[1][3]
The prize they wanted was his short, 3-letter Twitter handle. To reach it, they took control of his iCloud account and used Apple's remote-wipe feature, built to protect a lost phone, to erase his iPhone, iPad and MacBook. They deleted his Google account, which held 8 years of email, and posted racist and homophobic messages from his Twitter account and from a publication's account linked to it.[1][3]
He had no backup of the laptop. Among the losses were about a year and a half of photos of his young daughter.[3] He later got in touch with one of the attackers, who explained how it was done in exchange for the journalist not pressing charges, and he published the full account a few days later.[3][1]
How they got in
The weakness was not in any password. It was in how 2 companies decided whether a caller was really the account owner, and in the fact that each one treated as secret what the other showed freely.[1][4]
The attackers started with public information. His email address was visible from his online profiles, and his billing address could be found in public website registration records.[1][4] They then called Amazon customer service posing as him. Amazon's phone process at the time let a caller make changes to an account with only a name, address and email, and those changes led to a view of the last 4 digits of the cards on file.[4][2]
Amazon showed those 4 digits openly, because it considered them harmless. Apple, however, accepted a billing address plus the last 4 digits of a card on file as proof of identity. With both in hand, the attackers called Apple support and were issued a temporary iCloud password without being asked the security questions on the account.[1][5] From there, the linked accounts fell: the iCloud email was the backup for his Google account, and the Google account controlled Twitter.[1]
What it cost
No money was stolen and no one was charged. The cost was personal and permanent: family photos, years of email and documents that existed only on the wiped devices.[3] He recovered his Google account through Google's own recovery process, but the laptop data was gone at the time.[3]
The companies moved quickly once the story spread. Amazon said it closed the gap on August 6, and support staff stopped changing account settings such as credit cards and email addresses over the phone.[2][4] On August 7, Apple temporarily suspended Apple ID password resets by phone, told customers to use its online reset system, and said that when phone resets returned, callers would need stronger proof of identity.[5][2]
The missing control
The missing control: consistent identity checks across support. A help desk that can reset a password or change account details should verify the caller with something only the real owner has, not with facts that are public or shown freely by other companies.
Apple's rule treated the last 4 digits of a card as a secret, while Amazon displayed them to anyone who got into the account. Each company's process looked reasonable alone; together they formed a chain. If Apple's support desk had required the account's security questions, or a code sent to a device the owner already had, the Amazon information would have been worthless. A backup would not have stopped the break-in, but it would have saved the photos.[1][3]
What to do in your business
- Write down how you verify callers. Decide what a customer or employee must prove before anyone changes a password, email, bank detail or delivery address, and make everyone use the same checklist.
- Stop using public facts as proof. Addresses, birthdays and the last 4 digits of a card can all be found elsewhere. Use a callback to the number on file, a code to a known device, or a security question that is not public.
- Add a wait on risky changes. For password resets and payment or email changes requested by phone, add a short delay and a notice to the old contact details so the real owner can object.
- Turn on multi-factor sign-in for your own accounts. Especially email, which is usually the key to resetting everything else.
- Back up what cannot be replaced. Keep an automatic backup of company files and photos that a remote wipe or a locked account cannot touch.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Engadget: Details of the Amazon and Apple security flaws that let hackers wipe a journalist's MacBook
- CNN Money: Hack forces Apple and Amazon to change security policies
- NPR: Interview transcript, hackers wreak havoc on writer's digital life
- eWeek: Apple, Amazon change security policies after hack of journalist's accounts
- Macworld: Apple temporarily suspends phone password resets