26.1 C
Delhi

Cybercriminals Exploit Apple Store Online’s Pickup Policy

This year’s annual hacking conference Black Hat Asia has shown a new modern crime: a well-prepared and intricate ‘Someone else will pick it up’ caper targeting stolen credit cards and Apple Store Online’s inherent feature to bundle purchases.

The implemented exploit for over 2 years resulted in almost 500.000$ in losses. South Korean Financial Security Institute researchers Gyuyeon Kim and Hyunho Cho discovered was targeting a legitimate website. They quickly realized a massive data breach had occurred, with over 50 websites being affected.

Apple

More About Apple Store Exploitation

However, the malefactors had more than simple data thievery in mind. Cybercriminals did not steal credit and personal information but also made their servers receive the data directly through legitimate payments made with the phishing page using multiple anti-protection methods. However, stealing credit card details was just one aspect of their strategy.

- Advertisement -TechnoSports-Ad
image 15 358 jpg Cybercriminals Exploit Apple Store Online's Pickup Policy

The “Pickup Contact” policy of the Apple Store Online was the most important method of monetizing the activities. Financial gain was the main motivation of the operation and Kim explained the process in detail. First, the new Apple products were then listed in the second-hand online store on multiple sites with a discount in South Korea.

Once an agreement was made with a buyer, the stolen credit card numbers were used to purchase a product in the Apple Store. Following the order, the item was set to the “Someone else will pick it up” system on Apple’s website, and the cybercriminals would designate an individual who could pick up the product with a QR code and a government ID in the Apple retail store. The final stage of the process was made by the buyer from the second-hand store who was unaware of the fraudulent purchase.

image 15 359 jpg Cybercriminals Exploit Apple Store Online's Pickup Policy

Dubbed “PoisonedApple” by Kim and Cho, the scheme is estimated to have generated $400,000 in illicit gains over two years, primarily in South Korea and Japan. The researchers suspect the culprits are based in China, indicated by the registration of phishing web pages through a Chinese ISP and mentions in simplified Chinese on dark web forums.

- Advertisement -TechnoSports-Ad

FAQs

  1. How can users stay safe from similar cybercrime tactics?

    Users should be cautious when purchasing from discounted second-hand stores online and verify the legitimacy of sellers to avoid falling victim to scams.

  2. What measures can businesses take to prevent such attacks?

    Businesses should prioritize cybersecurity measures like software updates, multi-factor authentication, and employee and customer education to mitigate the risk of phishing attacks and protect sensitive data.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.

TechnoSports-Ad

Popular

TechnoSports-Ad

Related Stories

More from author

Reliance Jio Boosts Data: Extra Benefits Unveiled for Two Prepaid Plans

Reliance Jio has introduced mobile data benefits for two of its existing prepaid plans. Although most Jio prepaid plans offer 5G data some users...

Vi Introduces New Prepaid Plans and Long-term Validity Options to Attract Customers as of 4th May

Vodafone Ide­a (Vi) has been losing customers ste­adily due to the absence­ of 5G connectivity and subpar 4G speeds in many are­as. One perk...

Jio Republic Day 2024 Offer Revealed: Price, Benefits, and Validity Unveiled

Reliance Jio has recently launched a prepaid package exclusively for Indian users to celebrate Republic Day 2024. Priced at ₹2,999 this recharge plan offers...

Best Prepaid Recharge for Vodafone Idea (May 4, 2024)

Vodafone Idea, known as Vi, is currently a leading telecommunications provider in India. It emerged as a result of the collaboration between Vodafone India...