Skip to main content

Apple acknowledges iCloud hacking in China, but says its servers are safe

apple icloud hack china header f
Image used with permission by copyright holder
Apple responded to concerns that its iCloud service was compromised following a widespread, man-in-the-middle (MITM) attack that is believed to have been sanctioned by the Chinese government.

First brought to light by GreatFire.org, the Chinese government is reportedly using the national firewall system (or the “Great Firewall of China,” as it’s colloquially known) to redirect iCloud users to spoofed pages. By fooling older browsers with phony certificates and hijacked addresses, the apparent intention is to compromise the credentials of unsuspecting visitors.

Recommended Videos

Related: Apple CEO promises new security measures after iCloud celebrity photo hack

The source of the attack is reportedly China Telecom, a company with ties to Chinese leadership. In August, Apple agreed to store local China iCloud data in China Telecom’s servers.

On Tuesday, Apple told CNBC that it was aware of “intermittent organized network attacks,” but that iCloud servers hadn’t been compromised. The company also said that iCloud sign-in on mobile and Macs running the latest version of OS X are not at risk.

Related: Hackers trick Apple into providing access to an iCloud account, chaos ensues

The same can’t be said for iCloud account holders who log in using outdated Internet browsers, which will not automatically warn of interception (newer distributions of Firefox and Chrome can alert of fake certificates). Users of those and other browsers can still get around the attack by using an unaffected IP address.

GreatFire.org speculates the attack is an attempt to circumvent security measures introduced with the iPhone 6 and 6 Plus, which went on sale in China last week.  It’s hardly the first instance of a hack orchestrated by the Chinese government, though. Yahoo was targeted earlier this month, and a MITM attack continues to affect Microsoft’s Outlook mail service.

The news comes after a slew of female celebrities saw their private photographs — often nude ones — made public after iCloud’s weak security was breached. Called “The Fappening,” the stolen photographs contains naked and semi-naked pictures and videos of more than 100 A-list celebrities, among them Oscar-winning actress Jennifer Lawrence, singer Rihanna, swimsuit model Kate Upton, and TV star Kim Kardashian. While some of the celebrities argue that the pictures are frauds, others  confirmed that the posted photos of themselves were indeed authentic.

To boost security, Apple CEO Tim Cook told the Wall Street Journal that customers would receive alerts via email and push notifications if another person attempts to perform actions such as change an account password, restore iCloud data to another device, or when a device logs in for the first time.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Consumer group sues Apple for $3.8 billion over alleged iCloud monopoly
A person using the Apple iPhone 16 Plus.

Independent U.K. consumer rights association Which? has filed a massive legal claim of 3 billion British pounds (nearly $3.8 billion) against Apple, claiming it has breached competition law and locked its customers into its expensive iCloud cloud storage service. It says if the claim is successful, 40 million Apple device owners in the U.K could be entitled to money back.

If you haven’t heard of Which? before, it’s made up of two different companies. The Consumers Association, is a charity that campaigns for the protection of consumers and the understanding of consumer issues while also working to ensure businesses meet the law. The second company is Which? Limited, a website producing content and services around products to help people choose what’s best for them.

Read more
I don’t want to say goodbye to my Apple Watch Ultra
A person wearing the Apple Watch Ultra.

I probably shouldn’t have done it, but ahead of saying goodbye to my original Apple Watch Ultra, I put it back on to test out watchOS 11.

Why shouldn’t I have reacquainted myself with Apple’s chunkiest smartwatch? Despite initially not being that bothered about moving on, I’m now having second thoughts about it.
Why I'm getting rid of my Ultra

Read more
Apple just stopped its iPadOS 18 update, here’s why
M4 iPad Pro with Magic Keyboard.

Updated September 17 at 1:26 p.m. PT: Less than two hours after this story was published, it was confirmed that Apple has stopped the iPadOS 18 update and is no longer rolling it out to users.

Per Apple, "We have temporarily removed the iPadOS 18 update for M4 iPad Pro models as we work to resolve an issue that is impacting a small number of devices.”

Read more