My partner had an old Apple account created about 15 years ago with her Gmail address, but she had barely used it. A few days ago, she received an email saying that a phone number from another country had been added or changed. I removed it, changed the password, and enabled two-factor authentication.
Two days later, she received another notification saying the payment information had changed. When I tried to sign in and change the password again, the account required answers to old security questions instead. We had no idea those questions still existed, and we were confused about how someone could make changes after 2FA had supposedly been enabled.
Apple Support helped us regain access using an old MacBook associated with the account. I enabled 2FA again and noticed that the account country had been changed. The payment information appeared to contain only a different name, possibly belonging to a grocery chain or a person. I also found roughly 30 unfamiliar photos, including pictures of a Chinese man, dating from 2022 through 2026.
We have changed the password and enabled 2FA again, but we are still trying to understand what happened. Could an attacker have used the old security questions or an existing trusted session to bypass 2FA? Is there a recovery period during which 2FA can be canceled? Can the old security questions be removed permanently, and what other steps should we take to secure the account, the associated Gmail account, and any payment information?
5 Answers
An attacker may already have had a trusted device, an active login session, or account-recovery access before you enabled 2FA. Turning on 2FA does not necessarily invalidate every existing session immediately, and account recovery can involve additional safeguards or delays. Review the Apple account's device list, remove anything unfamiliar, sign out of other sessions if available, and ask Apple Support to check the account's security and recovery status.
The old security questions may have been part of the account's legacy recovery setup, but they are not necessarily a simple way to bypass modern 2FA. Apple can sometimes require older verification methods during account recovery, especially when the account was created under older security rules. Ask Apple Support specifically whether the questions are still active and whether they can fully reset the account's trusted numbers, devices, recovery contacts, and recovery methods.
Keep working with Apple Support rather than abandoning the account immediately. Have them verify the account's country or region, trusted phone numbers, trusted devices, purchase history, recovery settings, and any pending security changes. Save the notification emails and dates, because the timeline may help them determine whether the intruder used an existing session, account recovery, or a compromised email account.
Secure the Gmail account immediately as well. If someone accessed the email, they may have been able to approve account changes, reset passwords, or intercept security notifications. Change its password from a trusted device, enable 2FA there, review recent sign-ins and recovery details, remove unknown app access, and check for forwarding rules or filters that hide Apple messages.
Check for financial abuse separately. Contact the card issuer, explain that the Apple account was compromised, and ask whether the card or payment token was used anywhere. Remove all payment methods from the Apple account if possible, review purchases and subscriptions, and dispute anything unauthorized. Also change passwords anywhere the old Apple or Gmail password was reused, and avoid relying only on the account's notification emails as proof that every change was blocked.

The unfamiliar photos strongly suggest that someone had access for a while, rather than this being only a mistaken payment notification. Treat every device and account connected to the Apple ID as potentially exposed.