Alipay and Tencent say hackers used stolen Apple IDs to access some customer accounts and steal unknown sums of money; Alipay says Apple hasn't fixed the issue
Context & Ripple Effects
This lands a year after Chinese police arrested 22 people — 20 of them employees of Apple device resellers or Apple contractors themselves — for selling Apple customers' names and phone numbers, so the raw material for targeted ID attacks was already circulating. What changed this week is that Alipay and Tencent went public: stolen Apple IDs were being used to reach customer payment accounts and pull out money, and Alipay says Apple still hasn't fixed the access path.
The dispute is also a fight over where the breach lives. Days later, [[a:934531|Apple apologized and framed the thefts as phishing scams against users who hadn't enabled two-factor authentication]] — shifting responsibility from its own account infrastructure to individual security hygiene.
First-order effects
- Chinese customers whose Apple IDs were linked to Alipay or Tencent payment methods are losing funds directly from those accounts, with the sums so far unquantified.
- Alipay and Tencent absorb the immediate fraud losses and dispute volume while publicly pinning the unresolved vulnerability on Apple, forcing Apple to respond on their timeline rather than its own.
Second-order effects
- Apple's apology-and-blame-users response pressures both payment platforms to harden the linkage itself — requiring two-factor authentication or re-verification before an Apple ID can touch a wallet balance.
- The episode hands ammunition to the long-running critique that began when Apple Pay first let online-stolen cards be spent in stores: every new way Apple connects an account credential to money creates a fresh fraud surface that partners must underwrite.
Third-order effects
- If one vendor's ID remains the key to third-party balances, account-takeover shifts from an Apple support problem to a systemic question of who is liable when a shared credential drains someone's wallet — a question that resurfaced in the 2025 findings on phished card data being minted into Apple and Google wallets.
- Payment platforms operating in China may treat foreign identity providers as attack vectors by default, pushing toward stricter separation between login identities and stored value regardless of how Apple resolves this specific flaw.
The trend: As single-vendor account credentials become rails for third-party money, identity breaches convert directly into financial theft, and liability fights between platform and payment partner become the norm.