Spammers hack iCloud accounts to message victims in China

iCloud device setup
(Image credit: Shutterstock)

Spammers have stolen US citizens' iCloud logins to spam wealthy Chinese consumers with messages about counterfeit luxury goods, according to an IT security firm.

Adaptive Mobile discovered the trend in recent months, spotting iMessage and SMS spam sent from North American phone numbers to recipients in China, pointing them to inexpensive Prada and Coach Handbags as well as other goods.

Security analyst Cary Anderson said that the vast majority of these spam messages have been sent using various models of iPhone, and in particular, by hackers using stolen iCloud account credentials to exploit the ability to send iMessages and SMS between different countries.

“This spam campaign has been ongoing for several months, but in many cases does not match the standard method of sending SMS abuse in that it is persistent, widely distributed, and the senders are, as far as we could determine, predominately iPhone users that did not exhibit prior spamming behaviour,” Adaptive Mobile said in a blog post.

Hackers carry out the attack by obtaining compromised iCloud account credentials from various sources, the firm said. The hackers then use the stolen credentials to sign onto an Apple device of their own.

The person whose iCloud account it is will receive a notification on their iPhone that a new device has been paired, but the notification itself does not have an option to stop access. The hacker then sends spam messages to recipients in China using iMessage.

iMessages that don't reach their destination are downgraded to SMS and sent again to the target in China.

Anderson said the sender is likely to be hit with sizable bills for any large scale number of SMS messages that are being sent to China.

Anderson said the solution to this problem is via customer education and improvement on iCloud security.

“In the end, defeating these scammers will take a community effort – not just from Apple, but also from telecom operators and consumers,” said Anderson.

“Operators can protect their customers from unusual spikes in international traffic, Apple can and do[es] recommend using strong passwords and Two-Factor-Authentication on [its] accounts, and consumers should learn about and own their own personal security, paying particular attention to login alerts from new devices.”

The firm recommended that Apple should look at ways to further secure iCloud accounts, saying that one potential way would be to ensure that new paired devices are vetted.

Rene Millman

Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.

Latest in Cloud Security
AI chatbot text dialogue boxes in difference colours above a digital circuit board with lines of light emanating from it
Enterprise AI is surging, but is security keeping up?
Cloud storage concept image showing digitized cloud symbol with data flows.
AI is putting your cloud workloads at risk
Logo of Google Cloud, which recently announced the Wiz acquisition, pictured at Mobile World Congress 2025 in Barcelona, Spain.
The Wiz acquisition stakes Google's claim as the go-to hyperscaler for cloud security – now it’s up to AWS and industry vendors to react
Wiz logo pictured on a laptop screen.
Google confirms Wiz acquisition in record-breaking $32 billion deal
A multicolored, CGI padlock set against blue and yellow glowing slabs representing SWG and next-gen SWG in a cloud environment.
What is a secure web gateway (SWG) and next-gen SWG?
Cloud computing concept image showing a cloud symbol with electricity flowing to it, signifying cloud uptime capabilities.
Surging CNAPP investment is a big opportunity for the channel
Latest in News
Ransomware concept image showing a warning symbol in red with binary code in background.
Healthcare systems are rife with exploits — and ransomware gangs have noticed
Application security concept image showing a digitized padlock placed upon a digital platform.
ESET looks to ‘empower’ partners with cybersecurity portfolio updates
Male software engineer working on a laptop at a home office desk with two PC monitors sitting on top of desk.
‘This shift highlights not just a continuation but a broad acceptance of remote work as the norm’: Software engineers are sticking with remote work and refusing to budge on RTO mandates – and 21% would quit if forced back to the office
Databricks logo and branding pictured on a MacBook Pro screen.
Databricks and Anthropic are teaming up on agentic AI development – here’s what it means for customers
Dell Technologies logo and branding pictured at the company's stall at Mobile World Congress (MWC) in Barcelona, Spain.
Scale of Dell job cuts laid bare as firm sheds 10% of staff in a year
Male employee sitting at a desk working on a laptop with earphones in and books scattered on desk.
Employees want purpose, and they’re willing to quit to find it – upskilling, career growth, and work-life balance have shifted priorities for workers