iCloud not compromised in Apple ID attack: Apple
Summary: Apple has produced a minuscule response to the Apple ID attack that began affecting Australian and New Zealand iCloud users yesterday. — Chris Duckett — Almost a half and a day after a number of Australian users reported finding …
Context & Ripple Effects
The remote-locking of Apple devices across Queensland, NSW and Western Australia put iCloud in an awkward spotlight, and Apple answered within about half a day with a statement insisting its service was untouched. It is a familiar position for the company: back in August 2012, Apple's own support staff let a hacker talk his way into a reporter's iCloud account, so the question of whether the fault sits with Apple's systems or with how individual accounts get accessed is a recurring one.
The story travelled unusually wide for a regional incident — pickups at 9to5Mac, Computerworld, BGR, Business Insider, Cult of Mac and others, plus scrutiny from security blogger Troy Hunt — and much of that attention fixed on the same point Apple's denial raises: if iCloud itself did not fall, the attackers' working Apple ID passwords had to come from somewhere else.
First-order effects
- Device owners in Queensland, NSW and Western Australia whose iPhones and iPads were locked via Find My iPhone face live ransom demands, with their only outs being Apple support or paying the attackers.
- Apple's denial moves the fault line from iCloud infrastructure to individual account credentials, placing the burden on affected users to explain how their Apple IDs were compromised.
Second-order effects
- Security researchers, Troy Hunt among them, will press on the provenance of the working passwords — if they trace to earlier third-party breaches, every other site those users reused credentials on inherits part of the blame.
- Find My iPhone's remote lock, designed as anti-theft protection, is now functioning as the extortion mechanism, forcing Apple to weigh added verification friction against the feature's core convenience.
Third-order effects
- If remote-management features keep doubling as extortion tools, consumer cloud platforms face structural pressure toward default two-factor authentication and auditable account-access records.
- The 'our servers were never breached' defence, even when accurate, does less each time to protect trust in cloud-tethered devices — repeated account-level attacks erode confidence in the model regardless of which layer failed.
The trend: Consumer cloud services are increasingly attacked through their own legitimate remote-management features rather than server-side breaches, shifting the battleground for platform trust from infrastructure security to account-level authentication.