A very old Apple account I barely use has been taken over repeatedly. The attacker changed the password, personal information, two-factor authentication settings, and security questions. I contacted Apple several times, recovered the account, and was told the attacker could not regain access, but the takeover happened again the next day and then again after the account was supposedly locked. The attacker also accessed my Instagram, even though it uses a different email address and password. I have checked my Gmail and do not see any unfamiliar logins or devices. This time, the security questions were changed to Chinese, and Apple says they cannot delete the account because the attacker added about AUD 70 rather than withdrawing money. Has anyone dealt with this before, and why would someone add money to a compromised account?
3 Answers
The money may be part of an attempt to use the account for purchases, gift cards, or other transactions later. It could also be a payment or account-abuse tactic rather than a direct theft from you. Do not spend or transfer the balance, and ask Apple to document the unauthorized deposit and place a fraud hold on the account. Keep copies of every email, case number, timestamp, and account-change notification, and contact your bank or card provider if any payment method was involved.
If the attacker keeps changing the details after Apple resets everything, treat the email account, phone number, computer, and any previously trusted Apple device as possible parts of the compromise. Sign out of all sessions, update the operating systems, remove unknown profiles or apps, and consider using a separate clean device for account recovery. Also report the repeated takeover to local law enforcement or your national cybercrime reporting service, even if the current loss is only the added balance.
Changing the password repeatedly will not help if the attacker still has access to a trusted device, recovery method, email session, or saved credentials. From a clean device, change the passwords for your email and other important accounts, enable strong two-factor authentication, review recovery addresses and phone numbers, remove unfamiliar devices and app sessions, and check for forwarding rules or malware. A password manager can help ensure every account has a different password. Ask Apple specifically to review trusted devices, recovery contacts, payment methods, and account activity rather than only resetting the password.
I have checked the visible Gmail sessions, but I will also review forwarding rules, recovery settings, and every trusted device. I had mainly been relying on Apple to secure the account after each reset.

That makes sense. I was assuming the account itself was the only problem because I could not find an unfamiliar Gmail login, but I will check the other recovery paths and devices as well.