I recently found out that my old Apple ID was compromised while I was away on a business trip. I received a recovery email for an Apple ID I haven't used in years. The email detailed that a recovery request was made from Scottsboro, AL, with a phone number I don't recognize. By the time I saw the email, the scammer had already changed the phone number linked to my account. Now, I'm facing a lengthy recovery process that takes two weeks, during which I'm receiving notifications that purchases are being made on my old account. It's really concerning because I don't have any credit cards associated with that Apple ID anymore. How are they buying things? Apple won't expedite the recovery, so I'm left feeling helpless. Has anyone else faced a similar situation, and what advice do you have?
4 Answers
Do they need to add a payment method to make purchases? It seems odd that they could buy things without any linked accounts unless they already had something like a gift card balance.
It sounds like your email was hacked and they added a new phone number without you knowing. Apple’s infrastructure, especially for older accounts, isn't necessarily secure. Blaming Apple is a bit off because they can't control what's happening on the hacker's side, but it does raise concerns about their recovery policies.
That's really strange! If you didn't have any payment methods linked to your account, it's possible they might be using gift cards or someone else's credit card info to make those purchases. Under "BILLED TO" in the receipts, did it just show up as Account Balance? That’s a bit suspicious.
Exactly! Having your account like that without any visible payment methods just raises more questions about how they got access to funds. It's nuts that this can happen.
You really need to watch out if you didn’t have two-factor authentication on your account! This situation highlights how hackers can exploit old accounts with leaked data from various sites. They might even attach stolen credit cards to your account to buy stuff without anyone tracing it back to them. Unfortunately, once Apple gets reports about the fraudulent activity, that's when they might act, but till then, you just have to wait it out.
I had no idea about 2FA when I last used that account! It’s frustrating that Apple makes it so easy for people to hijack accounts.

But my email wasn’t hacked, just my Apple ID through that phone number recovery method. Apple should've had better checks to prevent that kind of access!