Skip to main content

Australian student hacks into Apple, steals 90GB of data because he’s a ‘fan’

outlook email
Image used with permission by copyright holder

A 16-year-old student attending a private school in Melbourne, Australia, broke into Apple’s network multiple times and downloaded 90GB of “secure” data for an entire year. He hacked into Apple’s network from his suburban home using tools and instructions stored on his PC in a folder named “hacky hack hack.”

According to a report by The Age newspaper stemming from Thursday’s court hearing, the student accessed Apple customer accounts as well. But Apple stated in an email to The Guardian that the student did not “compromise” personal data.

“We regard the data security of our users as one of our greatest responsibilities and want to assure our customers that at no point during this incident was their personal data compromised,” a company spokesperson said.

So how did this teen infiltrate Apple’s networks for an entire year without getting caught? The details are scarce for obvious reasons, but reports mention the student using virtual private networking (VPN) tools.

If you’re not familiar with VPNs, they essentially create a secure “tunnel” across the internet, mimicking the connection of a local private network. Corporations typically use VPNs to connect to a central network from remote locations, as VPNs encrypt all transferred data and are typically impenetrable by eavesdropping hackers.

VPNs can be used for personal use as well. They not only hide your true IP address but enable you to choose a specific country where your fake IP address originates. This allows you to access content not available in your region and bypass blocked websites. In this case, the student supposedly used VPN tools to hide his identity, IP address, and physical location.

Throughout the year, he accessed Apple’s internal systems and retrieved highly secure “authorized keys” for logging into customer accounts, relaying his successes through Whatsapp. His Apple-slicing feats supposedly made him well-known in the international hacking community to the point that the details of the case must be refrained. Apple even admitted it was “very sensitive about publicity.”

Once Apple eventually figured out what was going on, the company blocked his access and informed the FBI. Due to the student’s physical location, the FBI informed the Australian Federal Police (AFP), which executed a search warrant in 2017.

“At Apple, we vigilantly protect our networks and have dedicated teams of information security professionals that work to detect and respond to threats,” the company said in its email to The Guardian. “In this case, our teams discovered the unauthorized access, contained it, and reported the incident to law enforcement.”

According to the prosecutor, officials raided the home and seized two Apple laptops that contained the logged serial numbers used to access Apple’s internal systems and customer accounts. They also confiscated a hard drive and a mobile phone.

A possible scenario is that Apple paired the logged serial numbers to the ones listed on the student’s legitimate Apple account and then notified the FBI with its allegations. What’s strange about this case is that the student supposedly hacked into Apple because he was a huge “fan” of the company. He even admitted to the police that working for Apple was his “dream job.”

That said, sneaking into a company’s network, downloading sensitive data, and accessing customer accounts is not a good way to impress a potential boss. The Children’s Court listened to his case on Thursday, August 16, as the student pleaded guilty to the criminal charges. Due to the “complexity” of the case, sentencing won’t take place until next month.

Editors' Recommendations

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
AMD’s upcoming APUs might destroy your GPU
AMD CEO Lisa Su holding an APU chip.

The spec sheets for AMD's upcoming APU lineups, dubbed Strix Point and Strix Halo, have just been leaked, and it's safe to say that they're looking pretty impressive. Equipped with Zen 5 cores, the new APUs will find their way to laptops that are meant to be on the thinner side, but their performance might rival that of some of the best budget graphics cards -- and that's without having a discrete GPU.

While AMD hasn't unveiled Strix Point (STX) and Strix Halo (STX Halo) specs just yet, they were leaked by HKEPC and then shared by VideoCardz. The sheet goes over the maximum specs for each APU lineup, the first of which, Strix Point, is rumored to launch this year. Strix Halo, said to be significantly more powerful, is currently slated for a 2025 release.

Read more
Hyte made me fall in love with my gaming PC all over again
A PC built with the Hyte Nexus Link ecosystem.

I've never seen anything quite like Hyte's new Nexus Link ecosystem. Corsair has its iCue Link system, and Lian Li has its magnetic Uni system, and all three companies are now offering ways to tie together your PC cooling and lighting devoid of extraneous cables. But Hyte's marriage of hardware, software, and accessories is in a league of its own -- and it transformed my PC build completely.

I've been using some of the foundational components of the ecosystem for about a week, retailoring a build inside of Hyte's own Y40 PC case to see how the system works. It doesn't seem too exciting at first -- Hyte released an all-in-one (AIO) liquid cooler, some fans, and a few RGB strips, who cares? But as I engaged more with the Nexus Link ecosystem, I only became more impressed.
It all starts with the cooler

Read more
How to delete your Spotify account on desktop and mobile
An iPhone with the Stats for Spotify screen on it being held in a hand.

Spotify is home to a bountiful trove of music. With over 615 million users connected to the platform, it’s no wonder it’s one of the biggest music-streaming platforms in town. Still, sometimes we need to put aside a little extra pocket change every month. And one of the first things to go are monthly subscriptions. We know it stinks, but this doesn’t mean your Spotify account needs to disappear forever.

Read more