Skip to main content

Apple acknowledges iCloud hacking in China, but says its servers are safe

apple icloud hack china header f
Image used with permission by copyright holder
Apple responded to concerns that its iCloud service was compromised following a widespread, man-in-the-middle (MITM) attack that is believed to have been sanctioned by the Chinese government.

First brought to light by GreatFire.org, the Chinese government is reportedly using the national firewall system (or the “Great Firewall of China,” as it’s colloquially known) to redirect iCloud users to spoofed pages. By fooling older browsers with phony certificates and hijacked addresses, the apparent intention is to compromise the credentials of unsuspecting visitors.

Related: Apple CEO promises new security measures after iCloud celebrity photo hack

The source of the attack is reportedly China Telecom, a company with ties to Chinese leadership. In August, Apple agreed to store local China iCloud data in China Telecom’s servers.

On Tuesday, Apple told CNBC that it was aware of “intermittent organized network attacks,” but that iCloud servers hadn’t been compromised. The company also said that iCloud sign-in on mobile and Macs running the latest version of OS X are not at risk.

Related: Hackers trick Apple into providing access to an iCloud account, chaos ensues

The same can’t be said for iCloud account holders who log in using outdated Internet browsers, which will not automatically warn of interception (newer distributions of Firefox and Chrome can alert of fake certificates). Users of those and other browsers can still get around the attack by using an unaffected IP address.

GreatFire.org speculates the attack is an attempt to circumvent security measures introduced with the iPhone 6 and 6 Plus, which went on sale in China last week.  It’s hardly the first instance of a hack orchestrated by the Chinese government, though. Yahoo was targeted earlier this month, and a MITM attack continues to affect Microsoft’s Outlook mail service.

The news comes after a slew of female celebrities saw their private photographs — often nude ones — made public after iCloud’s weak security was breached. Called “The Fappening,” the stolen photographs contains naked and semi-naked pictures and videos of more than 100 A-list celebrities, among them Oscar-winning actress Jennifer Lawrence, singer Rihanna, swimsuit model Kate Upton, and TV star Kim Kardashian. While some of the celebrities argue that the pictures are frauds, others  confirmed that the posted photos of themselves were indeed authentic.

To boost security, Apple CEO Tim Cook told the Wall Street Journal that customers would receive alerts via email and push notifications if another person attempts to perform actions such as change an account password, restore iCloud data to another device, or when a device logs in for the first time.

Editors' Recommendations

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
How to remove someone else’s Apple ID from your iPhone
iPhone 11 Pro Settings

While it's always a good idea to wipe your iPhone before selling it or passing it on to someone else, it's not uncommon for some folks to forget this important step, especially if they're just handing an old iPhone down to a friend or family member. Hence, if you've acquired a used iPhone from somewhere, you may find that it's still signed into the Apple ID of the previous owner, which can be a pretty frustrating situation as it makes it difficult for you to make your new iPhone truly your own.

Depending on whose Apple ID you're using, this may be more than just an inconvenience. Using an iPhone that's fully signed in to someone else's Apple ID means that you'll be syncing data like your photos and messages with their iCloud account instead of yours, and it's likely they can even track its location via Apple's Find My iPhone. Even if they're a close friend or immediate family member, you may not want them to have that level of access to your personal life.

Read more
Remember Apple’s MagSafe Duo wireless charger? Well, it’s 38% off
Product image of the Apple MagSafe Duo charger.

If you're browsing through Apple deals for accessories that you can buy for your iPhone or Apple Watch, you should check out this offer from Amazon's Woot for the Apple MagSafe Duo Charger. Originally priced at $130, it's on sale with a 38% discount that reduces its price to just $80. There's a lot of other things that you can purchase using the $50 in savings, but if you want it, you're going to have to hurry. While there's still some time before the bargain expires, it won't be wise to wait until the last minute because stocks may get sold out before then. If you're interested, you should proceed with the transaction right now.

Why you should buy the Apple MagSafe Duo Charger
Apple's MagSafe wireless charging technology uses magnets to charge compatible devices, so you won't have to fumble for cables each time. With the Apple MagSafe Duo Charger, the only cord that you need is the included USB-C to Lightning cable that connects it to the power outlet. Once it's plugged in, you can simply place your iPhone, Apple Watch, or AirPods' wireless charging case on the accessory to start charging them. Once you're done using it, the Apple MagSafe Duo Charger folds away neatly, which makes it a nice travel companion.

Read more
I love Apple, but it’s totally wrong about iMessage and RCS
An iPhone 15 Pro showing the main iMessage screen.

I’ve been using an iPhone ever since 2008, starting with the original and then every generation since. For several years, the iPhone was only capable of SMS texting, with MMS support arriving with iOS 3 in 2009.

But in 2011, Apple created something new: iMessage. It first arrived on iOS and then went to the Mac in 2012 to replace iChat. iMessage is basically an instant messaging service that is exclusive to all Apple products: iPhone, iPad, Apple Watch, and Mac. You can send text, images and video, documents, rich preview links, stickers, and more between one another. You can also see if a message is delivered, send read receipts (if you want), and everything is encrypted. With iOS 16, you can even edit and unsend messages within a certain time frame.

Read more