Post

Replies

Boosts

Views

Activity

Urgent: Apple Developer Organization Account Takeover – No Resolution After One Week
Case Number: 102905844463 I'm posting here in the hope that someone from Apple or the developer community can advise on the appropriate escalation path. Our Apple Developer Organization account appears to have been compromised approximately one week ago. The primary Apple ID associated with the account was info at tadarab.com. Prior to losing access, we received multiple unsolicited Apple verification code SMS messages. Shortly thereafter, Apple sent a security notification confirming that a new trusted phone number ending in **9794 had been added to the account. The original trusted phone number ending in **4346 was no longer being used for verification. Since then: We have completely lost access to the primary Apple ID. The original Apple ID is no longer recognized through Apple's account recovery process. Team members associated with the organization appear to have been removed. Developer certificates appear to have been removed. We can no longer access App Store Connect or the Apple Developer account. A support case was opened immediately after the incident. Unfortunately, after a week of communication, support has not yet addressed the reported account compromise and instead responded that they could not verify our association with the Developer Program membership—which is itself one of the consequences of the apparent takeover. My main concern is understanding how a trusted verification phone number could be changed and an entire Developer Organization account effectively taken over without the legitimate owner being able to prevent or recover from the change. Has anyone experienced a similar situation, and is there a recommended escalation path within Apple for Developer Organization account compromises? Any guidance would be greatly appreciated.
1
0
66
6d
Urgent: Apple Developer Organization Account Takeover – No Resolution After One Week
Case Number: 102905844463 I'm posting here in the hope that someone from Apple or the developer community can advise on the appropriate escalation path. Our Apple Developer Organization account appears to have been compromised approximately one week ago. The primary Apple ID associated with the account was info at tadarab.com. Prior to losing access, we received multiple unsolicited Apple verification code SMS messages. Shortly thereafter, Apple sent a security notification confirming that a new trusted phone number ending in **9794 had been added to the account. The original trusted phone number ending in **4346 was no longer being used for verification. Since then: We have completely lost access to the primary Apple ID. The original Apple ID is no longer recognized through Apple's account recovery process. Team members associated with the organization appear to have been removed. Developer certificates appear to have been removed. We can no longer access App Store Connect or the Apple Developer account. A support case was opened immediately after the incident. Unfortunately, after a week of communication, support has not yet addressed the reported account compromise and instead responded that they could not verify our association with the Developer Program membership—which is itself one of the consequences of the apparent takeover. My main concern is understanding how a trusted verification phone number could be changed and an entire Developer Organization account effectively taken over without the legitimate owner being able to prevent or recover from the change. Has anyone experienced a similar situation, and is there a recommended escalation path within Apple for Developer Organization account compromises? Any guidance would be greatly appreciated.
Replies
1
Boosts
0
Views
66
Activity
6d