Hackers reveal details of thousands of iPad 'VIPs'
Friday 11 June 2010
Latest in Americas
On Facebook
From the blogs
Roy Hodgson for England: A club of one
To argue against Harry Redknapp for England is akin to arguing in favour of bankers bonuses. While s...
Time for a reality check on the Sri Lankan civil war
Sri Lanka, much like Britain, has side-lined accountability long enough.
Children Of Alcoholics week: One million children may just be the tip of the iceberg
Children Of Alcoholics week starts today. So, what are the aims for Nacoa during this important week...
Review of Being Human: ‘Being Human 1955’
Following on from an episode tinged with tragedy, this week lifted the mood with something lighter.
They thought they were among the lucky few: the "VIPs" who were the very first to get their hands on Apple's latest gadget. But those high-ranking military officials, media bosses and even White House staff might now be wishing they hadn't bothered, after an online security breach exposed the personal details of thousands of iPad users.
The email addresses of around 114,000 Apple iPad owners who subscribe via America’s second largest mobile phone provider AT&T were hacked by an internet security group.
Among those believed to have been affected are filmmaker Harvey Weinstein, Mayor of New York City Michael Bloomberg and White House Chief of Staff Rahm Emanuel. The New York Times Co. also told its staff to shut off iPad wireless access after learning of the breach, according to a memo confirmed by the company.
The attack, by a group of hackers named Goatse Security, exposed a weakness in a part of AT&T's website used to prompt users of their email addresses, making it easier for them to log-in via their iPad. It holds information on all iPad users subscribed through the telecoms company's 3G network.
Each of the accounts has an associated ICC code – an internal code used to link a subscriber with their SIM card. The hackers bombarded the AT&T website with fake ICC codes in the knowledge that, by chance, some would inevitably match genuine patterns. When they did, the website thought it was being contacted by a real iPad user and released the associated email addresses.
The breach is being interpreted as a major embarrassment for both Apple and AT&T and comes just weeks after a member of Apple staff lost a prototype of an iPhone in a bar, which was promptly taken apart, photographed and published online by a technology blog.
It also provoked fears that iPad users, subscribed via AT&T’s 3G network could be at risk from phishing scams. Armed with a valid email address and the knowledge that their target may be expecting emails from Apple or AT&T, criminals could send emails that plant malicious software on thier victims’ computers.
Internet security expert Graham Cluley wrote that targetting users would be possible. But he played down the significance of the attack. In a blog post, he pointed out that no further “information about the individuals appears to have been exposed – for instance, there are no passwords, real names, telephone numbers, dates of birth.” He added, however, that the breach would cause embarrassment.
A Goatse Security spokesman said the group contacted AT&T and waited until the vulnerability was fixed before going public with the information. It also released the information to media website Gawker Media.
AT&T admitted the breach and said that the problem had been fixed on Tuesday. But it claimed that it was alerted to it by a business customer. In a statement, an AT&T spokesman said: “The only information that can be derived from the ICC Ids is the e-mail address attached to that device.
“This issue was escalated to the highest levels of the company and was corrected by Tuesday; and we have essentially turned off the feature that provided the e-mail addresses.
“The person or group who discovered this gap did not contact AT&T. We are continuing to investigate and will inform all customers whose e-mail addresses and ICC IDS may have been obtained.
“We take customer privacy very seriously and while we have fixed this problem, we apologize to our customers who were impacted.”
Apple has sold more than two million iPads since they went on sale two months ago. Some models of the iPad tablet work with AT&T's third-generation wireless network, and other versions only work on Wi-Fi networks. Wi-Fi-only models are not affected by the breach. It is believed only users within the United States have been affected.
Apple did not respond to requests for a comment.
- 1 Murdoch hit by threat of new legal fight in US
- 2 Eight arrests as Murdoch 'throws staff to the wolves'
- 3 Lightning kills an entire football team
- 4 I was born to be a killer. Every night I see the Devil in my dreams
- 5 What really happened on the bridge when the Costa Concordia crashed
- 6 Letters raise fears for last Briton in Guantanamo
- 7 BBC to issue global apology for documentaries that broke rules
- 1 Eight arrests as Murdoch 'throws staff to the wolves'
- 2 I was born to be a killer. Every night I see the Devil in my dreams
- 3 Spotify: 1 million plays, £108 return
- 4 Lightning kills an entire football team
- 5 Modern lovers: The 'sexual body warriors' and pioneers transforming 21st-century relationships
- 6 BBC to issue global apology for documentaries that broke rules
- 7 Mona Lisa's 'twin sister' is discovered – 500 years late
- 8 Best served cold: BBC canteen has the last laugh on Twitter
- 9 Pucker up: The art of kissing
- 10 Did Banksy's latest work bring misery to a homeless man?
Free trial of new Independent iPad app
Get your daily dose of the best of British journalism, sponsored by American Airlines
Win a three-week coastal jaunt
Spend three weeks exploring every nook and cranny of gorgeous Atlantic Canada.
Amazing restaurant offers
Three glasses of free champagne and a special menu at 46 top London restaurants.
Latest Independent competitions
Win anything from gadgets to five-star holidays on our competitions and offers page.
Commercial thought leaders
Watch the best in the business world give their insights into the world of business.
Day In a Page
Procrastination: Not now – I'm busy
The diva who had – and lost – it all
How Picasso won over (some of) the British


Comments