Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

App Firm Says it May be Source of Apple Breach

A digital publisher said Monday it was likely the source of a data breach which resulted in the leak of personal data from as many as 12 million Apple iPhone and iPad users.

Hackers initially claimed the data containing Apple identification codes known as UDIDs was stolen from an FBI computer, but the US law enforcement agency claimed this was incorrect.

A digital publisher said Monday it was likely the source of a data breach which resulted in the leak of personal data from as many as 12 million Apple iPhone and iPad users.

Hackers initially claimed the data containing Apple identification codes known as UDIDs was stolen from an FBI computer, but the US law enforcement agency claimed this was incorrect.

BlueToad, a Florida-based firm which creates digital and mobile editions of publications, said that it was “the victim of a criminal cyber attack, which resulted in the theft of Apple UDIDs from our systems.”

Paul DeHart, the company’s chief executive and president, said in a blog posting that the firm immediately contacted law enforcement after learning of the attack.

“Although we successfully defend against thousands of cyber attacks each day, this determined criminal attack ultimately resulted in a breach to a portion of our systems,” he said.

“When we discovered that we were the likely source of the information in question, we immediately reached out to law enforcement to inform them and to cooperate with their ongoing criminal investigation of the parties responsible for the criminal attack and the posting of the stolen information.”

The company apologized for the breach and said it had fixed the vulnerability. It also said it does not collect sensitive personal information like credit cards, social security numbers or medical information.

“We understand and respect the privacy concerns surrounding the data that was stolen from our system,” DeHart said.

Advertisement. Scroll to continue reading.

“BlueToad believes the risk that the stolen data can be used to harm app users is very low. But that certainly doesn’t lessen our resolve to ensure that all data is protected and kept from those who seek to illegally obtain it.”

The group called AntiSec, linked to the hacking collective known as Anonymous, posted one million Apple user identifiers purported to be part of a larger group of 12 million obtained from an FBI laptop.

The FBI initially had no comment on the reports, but later issued a statement which said it never had the data in question.

One website set up a database to help users determine if their device was on the hacked list of Apple unique device IDs (UDIDs)

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Malware & Threats

Apple’s cat-and-mouse struggles with zero-day exploits on its flagship iOS platform is showing no signs of slowing down.

Mobile & Wireless

Samsung smartphone users warned about CVE-2023-21492, an ASLR bypass vulnerability exploited in the wild, likely by a spyware vendor.

Mobile & Wireless

Infonetics Research has shared excerpts from its Mobile Device Security Client Software market size and forecasts report, which tracks enterprise and consumer security client...

Fraud & Identity Theft

A team of researchers has demonstrated a new attack method that affects iPhone owners who use Apple Pay and Visa payment cards. The vulnerabilities...

Mobile & Wireless

Critical security flaws expose Samsung’s Exynos modems to “Internet-to-baseband remote code execution” attacks with no user interaction. Project Zero says an attacker only needs...

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.

Mobile & Wireless

Asus patched nine WiFi router security defects, including a highly critical 2018 vulnerability that exposes users to code execution attacks.