A very old Apple account I barely use has been repeatedly compromised. I first received notifications that the password, personal information, and two-factor authentication settings had been changed. Apple helped me regain access and reset everything, but the same thing happened again the next day. The attacker then accessed my Instagram, even though it uses a different email address and password. I secured Instagram as well, but my Apple account was compromised again that evening.
Apple eventually locked the account, saying that nobody—including me—would be able to access it. However, I received another notification today saying the account details had changed. I was able to reset the password, but changing the account information now requires security-question answers. The attacker appears to have changed those questions and set them in Chinese, so I cannot reset them.
Apple says they cannot delete the account because the attacker added 70 AUD to it instead of making a purchase. Has anyone dealt with something similar and managed to recover the account? Why would someone put money into a compromised account? I have also checked my Gmail and other accounts for unfamiliar logins and have not found anything suspicious.
3 Answers
Since another account was accessed too, I would treat this as a wider security incident even if the email accounts show no unfamiliar sessions. Scan your devices for malware, update their operating systems, review password-manager and browser access, revoke unknown app permissions, and check whether your phone number has been transferred or duplicated. Keep screenshots and case numbers, and report the repeated takeover to local police or the relevant cybercrime reporting service even if no money was stolen.
The added money could be an attempt to test a payment method, use the account for fraudulent purchases or refunds, or make the account look financially active. Do not spend, transfer, or add any more money. Ask Apple to document the deposit, investigate where it came from, remove any unknown payment methods, and place a fraud hold on the account. Also contact your bank or card provider if any of your payment details may have been exposed.
If the attacker keeps regaining access after password changes, something beyond the Apple password may be compromised. Check the email account and recovery addresses, trusted phone numbers, devices, browser sessions, saved passwords, and any computer or phone you used to make the changes. Change passwords from a known-clean device, enable stronger two-factor authentication where possible, and avoid reusing passwords. Apple Support should escalate this as an account-takeover and payment/fraud case rather than treating it as a routine password reset.
I was worried that simply resetting the password was not fixing the actual way they were getting back in. I’ll ask Apple to treat it as a takeover and check the recovery details and trusted devices more carefully.

I was concerned that authorities might not take it seriously because there has not been an obvious theft, but I’ll keep the Apple records and report the repeated unauthorized access anyway.