Cybercriminals Exploit Apple Store Online’s Pickup Policy

This year’s annual hacking conference Black Hat Asia has shown a new modern crime: a well-prepared and intricate ‘Someone else will pick it up’ caper targeting stolen credit cards and Apple Store Online’s inherent feature to bundle purchases.

The implemented exploit for over 2 years resulted in almost 500.000$ in losses. South Korean Financial Security Institute researchers Gyuyeon Kim and Hyunho Cho discovered was targeting a legitimate website. They quickly realized a massive data breach had occurred, with over 50 websites being affected.

Apple

More About Apple Store Exploitation

However, the malefactors had more than simple data thievery in mind. Cybercriminals did not steal credit and personal information but also made their servers receive the data directly through legitimate payments made with the phishing page using multiple anti-protection methods. However, stealing credit card details was just one aspect of their strategy.

image 15 358 jpg Cybercriminals Exploit Apple Store Online's Pickup Policy

The “Pickup Contact” policy of the Apple Store Online was the most important method of monetizing the activities. Financial gain was the main motivation of the operation and Kim explained the process in detail. First, the new Apple products were then listed in the second-hand online store on multiple sites with a discount in South Korea.

Once an agreement was made with a buyer, the stolen credit card numbers were used to purchase a product in the Apple Store. Following the order, the item was set to the “Someone else will pick it up” system on Apple’s website, and the cybercriminals would designate an individual who could pick up the product with a QR code and a government ID in the Apple retail store. The final stage of the process was made by the buyer from the second-hand store who was unaware of the fraudulent purchase.

image 15 359 jpg Cybercriminals Exploit Apple Store Online's Pickup Policy

Dubbed “PoisonedApple” by Kim and Cho, the scheme is estimated to have generated $400,000 in illicit gains over two years, primarily in South Korea and Japan. The researchers suspect the culprits are based in China, indicated by the registration of phishing web pages through a Chinese ISP and mentions in simplified Chinese on dark web forums.

FAQs

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.

More like this

Apple Hits 2.35 Billion Active Users, Reports Best Quarter...

Apple has reached a significant milestone, with 2.35 billion active users, as announced by CEO Tim Cook...

Apple in Talks with Bharat Forge for India Component...

Apple has opened discussions with Bharat Forge, part of the Kalyani Group, to potentially bring the company...

iPhone SE 4 to Feature Notch, Not Dynamic Island:...

According to Ross Young, a well-known display analyst, the iPhone SE 4 will have no Dynamic Island,...
iOS 18.3 Launching This Week: Features, Upgrades, and What to Expect

iOS 18.3 Launching This Week: Features, Upgrades, and What...

Apple is set to release iOS 18.3 this week, following nearly six weeks of beta testing. While...
iPad 11 Will Not Support Apple Intelligence: A Shift in Apple’s AI Strategy

iPad 11 Will Not Support Apple Intelligence: A Shift...

Apple’s upcoming iPad 11 has sparked significant buzz in the tech world, but recent reports reveal an...

LATEST NEWS

Arthur Melo to Girona: Juventus Midfielder Set for Loan Move with Salary Share Agreement

In a move that has garnered attention across European football, Arthur Melo, the Brazilian midfielder, is set to leave Juventus for Girona FC in...

Alvaro Morata Set to Leave Milan for Galatasaray in Shocking January Transfer

In an unexpected twist in the winter transfer window, Alvaro Morata is on the verge of leaving Milan for Galatasaray in a move that...

Sergio Ramos Nears Monterrey Move Amid Contract Negotiations as Spanish Icon in Talks for Liga MX Switch

Real Madrid legend Sergio Ramos is reportedly in advanced discussions with Mexican club Monterrey over a free transfer. The 38-year-old centre-back recently played for...

Asus Zenfone 12 Ultra Teaser Reveals Front Design, Features

The Zenfone 12 Ultra will make its global debut on February 6, after being teased by Asus as the successor to the Zenfone 11...

Featured