“Massachusetts Attorney General Martha Coakley said on Tuesday that her office would be inquiring into long-standing complaints about fraudulent purchases that leverage Apple’s popular online music store,” Paul Roberts reports for threatpost.
“In a lunchtime address to business and technology leaders in Massachusetts, Coakley said she was a victim of identity theft in recent months, and that her stolen credit card information was used to make fraudulent iTunes purchases,” Roberts reports. “When asked (by Threatpost) about whether such fraud constitutes a reportable event under the Bay State’s strict data breach notification law, Coakley said that her office would be looking into that question and demanding answers from Cupertino, California based Apple.”
Roberts reports, “Coakley was speaking before an audience of technology and business leaders at an inaugural lunch for Massachusetts’ Advanced Cyber Security Center (ACSC). Coakley said that her investment in protecting consumers from identity theft was personal, acknowledging that her bank account was emptied after cyber criminals stole her debit card information during a ski trip to New Hampshire… Informed of the well documented pattern of fraud through iTunes, in which stolen credit cards or bogus iTunes gift cards are matched with compromised iTunes accounts and used to purchase merchandise, Coakley said she wasn’t aware of the larger pattern, but that it could be a reportable offense under the State’s data privacy law. She promised her office would be contacting Apple for more information that very afternoon – a statement that received hearty applause from the audience.”
Much more in the full article here.
MacDailyNews Take: A fool and her money are soon parted.
if she lost a credit card and some moron used it to purchase something then how do you really think that the merchant has to pay the bill? there’s her, the thief and the merchant, the only party that is making no mistake is the merchant, because she did not secure the credit card well enough, the thief is of course making the biggest mistake. But the merchant? what the merchant did wrong?
OK so someone steals her card and uses at Walgreens, is she going to demand Walgreens answer to “Walgreens Fraud”?
This is just crass PR. How about going after the Banksters who ripped off most homeowners in the nation?
What does her experience have to do with Apple? She is the one that needs to be more careful with ID etc ., should have reported the theft asap to any places she has accounts with, including place like Amazon and iTunes that have one click purchasing etc.
Color me confused… her debit card information was stolen “while on a ski trip” and her bank account was emptied and she’s demanding answers from Apple?
Her card information wasn’t stolen from Apple servers- So?
Personally, I’d be looking for answers as to how a thief in New Hampshire compromised her cards.
Perhaps she’s not well suited to law enforcement.
Bah, she’s just an idiot.
It’s not the REAL iTunes fraud problem… Macworld wrote an article on it a few weeks back. Been going on since nov last year. That one apple does sweep under the rug.
methinks that cyber criminals don’t steal your credit card details on skiing trips – this is old fashioned criminals – and that New Hampshire sucks for skiing. She should have gone to Vermont or Maine. My credit cards have been stolen twice by cyber criminals and the accounts were shut down immediately by the bank that recognized fraudulent purchases and I lost no money.
You’re lucky. Not everyone is as fortunate. I worked with someone who had their bank account emptied and the credit cards run up. Neither the bank or credit card company caught it. It was a nightmare for them to go through. My son has had his bank account tapped twice through the ATM. He thinks it was stolen credit card info at the bank(Wells Fargo) but they won’t admit it. They did put the money back both times : $400 each time which must be a figure that is safe to withdraw for crooks. And before you think Apple is safe…………….I was checking my iTunes account several years ago only to find a Vietnamese name on my account. I’m not Vietnamese! Apple fixed it but tried to blow me off as though it was a simple mistake. I contacted my state attorney general’s office : hmmmmmmmmmm Apple was very helpful and apologetic then. But make no mistake Apple is no better or worse than any other online business, they are all vulnerable. Apple was simply arrogant for no reason. Funny how they changed their tune though. They don’t like to hear from the “law”.
I am thinking that her debit card info was skimmed… so the thief had the debit card info…. but no name…. so you go to iTunes, add a need account, add the stolen credit card info…. and iTunes will come back with the fact that the card is already associated with account abc…… so now they have a name….
I am guessing here… but it sounds like a possibility.
Here is the link to the MacWorld story: http://www.macworld.com/article/153611/2010/08/fake_itunes_charges.html
How is this Apple’s fault? the scam is based on phishing attempts. I receive phishing scams spoofing a variety of banks. I don’t fall for them. First I know that banks never send emails to ask you to log in. Second, many of them are for banks of which i’m not even a customer. Stupid to fall for that!
That’s the article that refers to what the attorney got his with.
http://www.macworld.com/article/161794/2011/09/the_towson_hack_the_mystery_of_disappearing_itunes_credit.html
This is the link I mentioned above, this has been going on for a year… And no word from apple.
Most people hit by this, entered the gift card they got from buying a new Mac… Next day it’s gone. No phishing, nothing.
The reason they go for store credit loaded from a gift card is that they steal the gift card information while it’s still on the shelf or in transit and wait for someone to buy it and get it activated. Then if they can beat the purchaser to the account they can spend the money on dummy apps that they have set up on the itunes store. I believe there’s a way to find the account from the gift card number that was associated to the account.
Ok guys, yes you can get your cc info stolen when using it at any store where a crook works. Yes it as happened to me pumping gas at a gas station, few hours later there were thousands of dollars charges.
The iTunes issue is different. She probably fell for one of the fake iTunes emails.
Debit cards DO NOT provide the protection to consumers that more regulated credit cards do. Plus, while a credit card has a limit, the only limit on debit cards is your bank account balance. It took me a couple of months, but I forced Etrade to issue me a plain old fashioned ATM card after someone in Japan (where I have never been) used my debit card (which was in my wallet) to buy a couple of thousand worth of bullet train tickets. I watch my account every couple of days or I might have lost all the money, as it was it took THREE months to get it back into my account. DO NOT LET THEM GIVE YOU A DEBIT CARD FOR ANY REASON!!!!
By the way, too bad for Martha, but it’s people like her who let the banks get away with screwing their customers with lax regulation.
Not true.
Many banks have protections built into their accounts, and guarantee credit card sized limits on losses IF you report the theft within 24 hours.
My debit card also has a per transaction limit and a daily limit, and my daughter actually had her debit card frozen when she forgot to tell the company that she’d taken a trip to Florida!
If your bank allows unlimited transactions or fails to account for your common transaction patterns, find another bank.
When I bought a new iMac recently, I called my bank and let them know that the transaction was going to occur – it went over at the Apple store without a hitch.
caveat emptor!
If you check your accounts every 24 hours, good for you. However, most of us would see that for what it is: a huge loophole that makes the bank not responsible for your losses.
You’re wrong. Debit cards have per day and per transaction limits. In addition, they are protected against fraud just like credit cards, so the maximum under federal law you would be liable for is $50. Virtually all banks will not ask you to pay that and will simply put the money back and then pursue the criminal.
You know Apple has arrived when politicians “go after” after Apple for the flimsiest reasons.
The larger question is how can someone in her position allow herself to be put in the position to allow her identity be stolen, without having safeguards in place?
Typical nanny state democrat response.
No personal accountability.
It’s much easier to have your identity stolen than you think. No safeguards can prevent it, and the financial and legal systems are set up to assume you are who you say you are, although this is changing slowly. It’s very difficult to prove you did not buy something, particularly online, when the paper trail says you did.
Yeah, it’s Apple’s fault that someone got her password and used it.
And it’s not possible to steal a password and download from another music store.
Stupid is as stupid does, I suppose.
“12345? That’s amazing! I’ve got the same password on my iTunes account!”
(…with apologies to Mel Brooks and Spaceballs)
The headline is misleading. It’s not “iTunes fraud” but credit card theft. An attorney should know that.
Microsoft makes banks and people lose billions, and what is she doing?
Now, if it results that her credit card info was stole because she didn’t took care of it, can Apple contact her to ask for an explanation?
I’m surprised people clapped, I would have laughed.
She’s probably a democrat.. that explains it all.
She is
“MacDailyNews Take: A fool and her money are soon parted.”
…uh, a fool and YOUR money are soon parted, Ms. Coakley subsists on da’ gubbamint tit.
I did have an issue on my iTunes account. Had $50 gift card balance. Then it was gone. Someone in Asia bought some games on it. Contacted Apple and they replaced it. Not sure what really happened as I am pretty careful about what I open, etc. But Apple was great. Replaced the stolen amount. No hoops to jump through.
MDN take is pretty lame. This has nothing to do about whether she is a fool or not. She probably just used her debit card just like millions of other people do, and happened to get her identity stolen.
My in-laws had their card stolen at a restaurant. Fortunately my mother-in-law is a fanatic about checking her account online, and saw charges appear that she didn’t make (gas, etc.). She cancelled the card and the thief was caught, but it can happen to even the most vigilant person.
Your mother in-law was smart to not call the merchants about the fraudulent charges and instead cancel the card.
I believe the take should be “A fool and his/her credit card information are soon parted”.
What she experienced is actually pretty low-level identity theft. the real big business is in obtaining social security numbers, etc., and then applying for credit cards in your name and having them sent to a different address, or selling your social security number and name to illegal immigrants, particularly if you have a hispanic surname.
The criminals who stole her debit card info were pretty criminals, probably just looking for some quick cash (obviously, because they just emptied her bank account and bothered to download $0.99 songs from iTunes instead of buying a TV or something bigger).
Total bullshit, first of all because credit card companies will reverse unauthorized charges and have done so for many years.
You’re correct and the word of the day is “dispute”.
The real question is whether Massachusetts Attorney
General Martha Coakley is qualified to hold her job.
She doesn’t seem to be too bright.
Was her CC number used be the thieves to setup an iTunes account, or did the thieves hack an existing account in her name, or…
was she a coincidental victim of two totally separate incidents?
There may be a conflating of two separate issues; her CC number getting stolen and fraud on iTunes. Nearly everyone commenting seems to be jumping on the notion the two incidents are connected.
The article doesn’t provide enough details.
Nothing like using your taxpayer-funded position to stump for an issue you have in your private life.
Tell you what, Martha: why don’t you query the people of the state of Massachusetts and ask them what issues deserve the resources of the state?