It sounds like something from a Science Fiction movie.
Mat Honan was playing with his daughter on Friday August 3, when his iPhone died and then rebooted to the setup screen. This was irritating, Mat wasn’t concerned, assuming it was simply a software glitch. As the phone automatically backs up every night. he just assumed it would be a "pain in the ass" [sic], and nothing more. Mat entered his iCloud login to restore, and it wasn’t accepted. Again, he was irritated, but not alarmed.
Mat decided to restore the phone from his computer's backup. When he opened the laptop, an iCal message popped up telling Mat that his Gmail account information was wrong. Then the laptop's screen turned grey, and asked for a four digit pin number to access the laptop. Mat didn’t have a four digit pin.
Now Mat, knew "something was very, very wrong". He walked to the hallway to grab his iPad. It had been reset too. Mat could not turn on computer, iPad or iPhone.
Using his wife’s iPhone Mat called Apple tech support. While on hold, he grabbed her laptop and tried to log into his gmail account whereupon he discovered his password had changed. He couldn’t reset it either because the backup went to iCloud. Of course, the ICloud had already not let him in.
Mat tried to log into Gmail again, but was told that his Google account had now been deleted. The way to restore it was to send a text message to my phone which Mat didn’t have access to.
Apple tech support weren’t able to stop the wipe on the Macbook. Or provide the four number pin to log into it. Or give immediate access to my phone.
What was going on?
At 4:50 PM on August 3rd, someone got into Mat's iCloud account, reset the password and sent the confirmation message about the reset to the trash. The backup email address for his Gmail account is that same .mac email address. At 4:52 PM, that person tried to log into Gmail by requesting a password recovery email. An email changing the Gmail password arrived two minutes later to the mac email account.
At 5:00 PM Using ICloud, the hacker remote wiped my iPhone. They then remote wiped the iPad at 5:01pm and followed that up with his MacBook Air at 5:05pm. A few minutes later, they had access to his Twitter account. Because Mat had linked his Twitter account to his ex employer's Twitter account years before, the hacker had access to that Twitter account too. A series of nasty tweets started being sent from the ex-employer (Gizmodo).
Mat lost at least a year’s worth of photos, emails, documents, and more.
Someone claiming to be the hacker got in touch to says “didnt guess ur password or use bruteforce. i have my own guide on how to secure emails.” Apple then confirmed that Apple tech support provided the hacker with access to the iCloud password. Before yelling too loudly at Apple, the hacker was able to use "
some clever social engineering that let them bypass security questions"
My learnings:
- Have a company policy around passwords eg when changed, length. We need to emphasise how careful we must be with passwords
- do not write down passwords in public places
- do not use the same password on every account
- Have an email account that is only for backup password requests and the like. Give it out for no one and nothing
- Be aware of who has password access to your organisation's server, email, Facebook and Twitter accounts. Change common codes when an employee or volunteer leaves
- Do not use your Mother's real maiden name when asked that security question. This is the most common question asked. It does not take a genius to find out what most people's mother's maiden name is
- Think about the other common security questions asked by companies. Eg where born (Facebook tells me that). My First car? If your facebook timeline says: Got my first Volvo in 1996 or if you sent a tweet that said " said good bye to my first car today. will miss my Toyota" then anyone can get that information
- Do a password audit. What are all of the passwords in your organisation? In your personal life? Who knows what?




