FBI says a man phished thousands of iCloud accounts via an email scam where he impersonated customer support, stealing 620K photos and 9K videos until mid-2018
and he wasn't even using a VPN. And Apple didn't catch on. Matthew Green / @matthew_d_green : Imagine if instead of stealing photos he'd inserted CSAM images into these accounts. 306 lives would now be ruined. Christopher Burgess / @burgessct : 🔥🤬found were “479 videos and images of unconscious women in various states of undress on multiple devices and in his iCloud account dating back to at least 2006 until May 30, 2021” #natsec @ncsc @fbi @TheJusticeDept @StateDept @StateDeptDSS @SRE_mx #mexico @r_velascoa #vawa https://twitter.com/... George Brauchler / @georgebrauchler : “Chi, who goes by David, admitted that he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords,” https://www.latimes.com/... Elizabeth Wharton / @lawyerliz : Stealing private (intimate) photos from people's iCloud accounts as a service - both the ppl requesting stolen pics & the thief stealing the pics are horrible. https://twitter.com/... John Wu / @topjohnwu : Regardless whether iCloud is secure or not, please tell me what does this incident have anything to do with iCloud's security. I mean, come on man 🙄😕 https://twitter.com/... https://twitter.com/...
Context & Ripple Effects
The FBI had already linked nearly 600 iCloud breaches to the Celebgate investigation, while a separate case showed that phishing could compromise both iCloud and Gmail accounts. This case ties a far larger collection of private media to customer-support impersonation rather than a purely technical break-in.
Related coverage also documented an illicit market for socially engineered iCloud access and earlier phishing charges involving iCloud accounts. Together, they put Apple’s support and account-recovery interactions inside the security boundary.
First-order effects
- Victims whose Apple IDs and passwords were obtained through the impersonation lost control over private iCloud media, with David Chi reported to have taken roughly 620,000 photos and 9,000 videos.
- Apple faces a concrete gap in detecting account compromises driven by fraudulent support emails, since the reported exfiltration continued without detection through mid-2018.
Second-order effects
- Apple’s support and account-protection teams are pressured to treat requests and messages that resemble customer service as an account-takeover channel, not merely a fraud-awareness problem.
- The case reinforces the incentive for criminals in the iCloud-unlocking ecosystem to target identity and credential workflows, because access to an account can expose both cloud data and device-linked services.
Third-order effects
- Repeated iCloud phishing cases, from the Celebgate-related breaches to this investigation, point to support-mediated social engineering becoming a durable security perimeter for consumer cloud platforms.
- If providers harden those workflows, account security will increasingly depend on verifying support interactions and detecting anomalous data access alongside protecting passwords.
The trend: Consumer-cloud security is shifting from password protection alone toward defending the support and recovery channels attackers use to obtain legitimate account access.