Alipay and Tencent say hackers used stolen Apple IDs to access some customer accounts and steal unknown sums of money; Alipay says Apple hasn't fixed the issue
- China's top digital wallet didn't say how much was stolen — Ant Financial and Tencent are working with Apple on the case
Context & Ripple Effects
This breach lands on top of an already uncomfortable record for Apple in China: a year earlier, police arrested 22 people for selling Apple customers' names and phone numbers, and said 20 of them worked for Apple device resellers or as Apple contractors. The stolen-data pipeline that fed those arrests is exactly the raw material phishing crews need to take over Apple IDs.
What changed this week is where the losses surface: not in Apple's own services but in China's two dominant wallets, which let customers link Apple IDs to payments. Alipay's public statement that Apple hasn't fixed the issue put the blame on the identity provider before Apple responded days later with an apology that framed the scam around victims who hadn't enabled two-factor authentication.
First-order effects
- Customers who linked Apple IDs to Alipay or Tenpay face direct, unquantified theft from their wallet balances right now, with neither company saying how much was taken.
- Alipay and Ant Financial are absorbing fraud complaints and support costs for an account system they don't control, while publicly pressuring Apple to close the hole.
Second-order effects
- Apple was forced into damage control within days — apologizing and attributing the scams to missing two-factor authentication — a framing that shifts responsibility back onto users and away from its own ID infrastructure.
- Wallet operators now have a concrete reason to tighten or re-examine how loosely they treat a third-party login as sufficient authentication for moving money, raising friction for every user of the Apple ID linkage.
Third-order effects
- The pattern runs from Apple Pay letting online-stolen cards work in stores in 2015, through this ID-takeover drain, to investigators finding Chinese cybercrime groups still converting phished card data into fresh mobile wallets in 2025 (the same wallet-loading playbook) — the identity and token layers above the card network keep proving to be the softest target.
- If wallets keep bearing losses caused by another company's login system, expect a structural fight over fraud liability between platform gatekeepers and payment apps — and regulators in China watching who is held accountable for consumer losses.
The trend: Payment apps that authenticate through a single platform's identity system inherit that platform's security failures, and each incident pushes the industry toward renegotiating who owns fraud liability at the gatekeeper boundary.