My partner had an old Apple account created with her Gmail address about 15 years ago and rarely used it. A few days ago, she received an alert saying that a foreign phone number had been added or changed. I removed it, changed the password, and enabled two-factor authentication. Two days later, another alert said the payment information had been changed. When I tried to secure the account again, Apple asked for old security-question answers, and we could not access some settings normally. With Apple Support's help, I used an old MacBook associated with the account to regain access and enable two-factor authentication again. I also noticed that the account's country had changed, and the credit-card name field contained what appeared to be a foreign man's name or the name of a grocery chain. There were also roughly 30 unfamiliar photos, apparently uploaded between 2022 and 2026. How could someone access the account after two-factor authentication was enabled? Could old security questions or a temporary cancellation window have allowed them to bypass it? Are the security questions disabled permanently now, and is there anything else I should do to prevent another takeover? Could the account have been used with stolen payment information?
4 Answers
Apple has historically had a short period after enabling two-factor authentication during which the change could be canceled or account-recovery details could still matter. That may explain how an attacker who already had access continued making changes shortly afterward. It is also possible they had an existing trusted session or device. Contact Apple Support again and ask them to verify the account’s security state, remove old trusted devices and recovery methods, and confirm whether the old security questions are still active.
Secure the Gmail account first, because control of the email account could let someone reset or interfere with the Apple account. Change its password, enable two-factor authentication there as well, review recent sign-ins and recovery methods, and remove any unfamiliar devices or app sessions. Also contact the card issuer about the changed payment details and watch for unauthorized charges.
Check the Apple account’s device list and sign out every device you do not recognize, then change the Apple password again from a trusted device. Review trusted phone numbers, recovery contacts, payment methods, subscriptions, purchases, and account-country settings. The unfamiliar photos strongly suggest that someone had access well before the recent alerts, so treat the account as compromised rather than assuming the payment-name change was harmless.
Do not assume the security questions were a permanent bypass. They may have been part of the account’s older recovery setup, while two-factor authentication was still being established. After recovery, make sure the account uses a current password, trusted phone number, and trusted device, and remove all legacy information you no longer recognize. If Apple cannot fully verify that the account is clean, abandoning it and creating a new account may be safer, especially since it appears to have been used by someone else for years.
I was hoping to keep the account, but I will consider replacing it if Apple cannot confirm that all old access and recovery options have been removed.

The only device currently visible is the MacBook we used for recovery, but the unfamiliar photos indicate that someone had been using the account previously.