Cybercriminals Exploit Apple Store Online’s Pickup Policy

This year’s annual hacking conference Black Hat Asia has shown a new modern crime: a well-prepared and intricate ‘Someone else will pick it up’ caper targeting stolen credit cards and Apple Store Online’s inherent feature to bundle purchases.

The implemented exploit for over 2 years resulted in almost 500.000$ in losses. South Korean Financial Security Institute researchers Gyuyeon Kim and Hyunho Cho discovered was targeting a legitimate website. They quickly realized a massive data breach had occurred, with over 50 websites being affected.

Apple

More About Apple Store Exploitation

However, the malefactors had more than simple data thievery in mind. Cybercriminals did not steal credit and personal information but also made their servers receive the data directly through legitimate payments made with the phishing page using multiple anti-protection methods. However, stealing credit card details was just one aspect of their strategy.

image 15 358 jpg Cybercriminals Exploit Apple Store Online's Pickup Policy

The “Pickup Contact” policy of the Apple Store Online was the most important method of monetizing the activities. Financial gain was the main motivation of the operation and Kim explained the process in detail. First, the new Apple products were then listed in the second-hand online store on multiple sites with a discount in South Korea.

Once an agreement was made with a buyer, the stolen credit card numbers were used to purchase a product in the Apple Store. Following the order, the item was set to the “Someone else will pick it up” system on Apple’s website, and the cybercriminals would designate an individual who could pick up the product with a QR code and a government ID in the Apple retail store. The final stage of the process was made by the buyer from the second-hand store who was unaware of the fraudulent purchase.

image 15 359 jpg Cybercriminals Exploit Apple Store Online's Pickup Policy

Dubbed “PoisonedApple” by Kim and Cho, the scheme is estimated to have generated $400,000 in illicit gains over two years, primarily in South Korea and Japan. The researchers suspect the culprits are based in China, indicated by the registration of phishing web pages through a Chinese ISP and mentions in simplified Chinese on dark web forums.

FAQs

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.

More like this

iOS 18.4: The Must-Know Apple Intelligence Features Arriving in April

iOS 18.4: The Must-Know Apple Intelligence Features Arriving in...

Apple's latest iOS 18.4 update may not bring the much-anticipated Siri enhancements just yet, but it still...

M4 iPad Air Set for Launch With Upgrades, But...

Apple is preparing to launch its new iPad Air models featuring the upgraded M4 chip, which is...

Apple’s AI Push in 2025 Hits a Critical Turning...

Apple's ambition in artificial intelligence (AI) has finally hit its stride, with the company accelerating to challenge...
iOS 18.4 Beta 1

iOS 18.4 Beta 1: New Features, Updates, & Changes...

iOS 18.4 Beta 1 : Apple has officially rolled out iOS 18.4 Beta 1 to developers, bringing...
India Begins Exporting Apple Components 

India Begins Exporting Apple Components: Rise in Apple’s Global...

India Begins Exporting Apple Components: In a landmark development, India has started exporting electronic components for Apple...

LATEST NEWS

Exclusive: The Top 10 PC Games Available on MacOS as of 2025

PC Games Available on macOS: While macOS has never been as synonymous with gaming as Windows, there are a growing number of excellent titles...

ASUS Brings AMD Radeon RX 9070 Series GPUs: The Future of Gaming Graphics

Picture this: You’re immersed in the latest open-world game, marveling at the lifelike reflections in a rain-soaked city street, when suddenly you realize -...

[18+] Top 15 Best Adult Actress in the World Right Now in 2025

The adult film industry shapes technological breakthroughs that revolutionize digital entertainment consumption today. Many people know the top performers' names. The surprising fact is...

EA FC25: Newcastle vs Man United – Get An Exclusive Ultimate Virtual Showdown

In the digital realm of EA FC25, football isn’t just a game—it’s a strategic battlefield where team composition, player attributes, and tactical nuance determine...

Featured