Apple Flooded with iCloud Password Reset Requests Amid Tightened Account Security Controls

icloud icon textIn a high-profile case last month, a hacker was able to gain access to Wired reporter Mat Honan's iCloud, Gmail, Twitter, and Amazon accounts, taking control of much of Honan's digital life and remote wiping his iPhone, iPad, and MacBook Air. Honan later detailed how the hack was accomplished through social engineering by entering the system through weaknesses in Amazon's account security and then using credit card information stored there to gain access to Honan's iCloud account.

Following the incident, Apple temporarily halted over-the-phone iCloud password resets, which had required only the user's billing address and the last four digits of the credit card on file with the account. Apple has since rolled out new authentication for password resets, including a requirement that users provide two correct responses to a small group of challenges that includes user-set security questions, more detailed credit card information, and device confirmations via either serial number or pushed Find My iPhone verification codes.

We've heard from several Apple support employees who have noted that their abilities to help customers have been severely restricted as part of the effort to tighten up security, with staff only able to send password resets to email addresses on file with the account. Employees are no longer permitted to send password resets to arbitrary email addresses and can no longer set temporary passwords on accounts to enter troubleshooting mode during support calls.

icloud backup and restore
One employee we spoke with has detailed a tremendous influx in support calls with the release of iPhone 5, as customers looking to restore iCloud backups of their old phones onto their new phones are in some cases having difficulty remembering their passwords. Support calls are said to be up on the order of tenfold over the past week or so surrounding the iOS 6 and iPhone 5 launches.

I know what you are thinking. The rightful person that owns the Apple ID should have no problem doing enough of that to be able to verify their ID and be able to then reset their password or security questions or unlock their account. And you would be wrong in thinking that.

This employee has emphasized that if users can not confirm their identities within the new framework of authentication challenges, there is nothing Apple support staff can do to help them and they will be frozen out of their iCloud accounts. For this reason, the employee notes that users are strongly encouraged to know the exact answers to their security questions, make sure a proper credit card is associated with the account, and set up Find My iPhone/iPad/iPod, maximizing their chances of being able to regain access to their accounts should their passwords be lost.

Finally, this employee has cautioned users about both changing their password and resetting their security questions at the same time, particularly if they do not have a credit card on file with the account. In that instance, if the user is unable to get into their account with the reset password, the deleted security questions and the lack of a credit card will essentially make it impossible for Apple support to verify their identity and regain access to the account.

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Rumored to Use Same Rear Chassis as iPhone 16

Friday July 19, 2024 7:16 am PDT by
Apple will adopt the same rear chassis manufacturing process for the iPhone SE 4 that it is using for the upcoming standard iPhone 16, claims a new rumor coming out of China. According to the Weibo-based leaker "Fixed Focus Digital," the backplate manufacturing process for the iPhone SE 4 is "exactly the same" as the standard model in Apple's upcoming iPhone 16 lineup, which is expected to...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Just Two Months Away: Everything We Know

Monday July 15, 2024 4:44 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
bsod

Crowdstrike Says Global IT Outage Impacting Windows PCs, But Mac and Linux Hosts Not Affected

Friday July 19, 2024 3:12 am PDT by
A widespread system failure is currently affecting numerous Windows devices globally, causing critical boot failures across various industries, including banks, rail networks, airlines, retailers, broadcasters, healthcare, and many more sectors. The issue, manifesting as a Blue Screen of Death (BSOD), is preventing computers from starting up properly and forcing them into continuous recovery...
iphone 14 lineup

Cellebrite Unable to Unlock iPhones on iOS 17.4 or Later, Leak Reveals

Thursday July 18, 2024 4:18 am PDT by
Israel-based mobile forensics company Cellebrite is unable to unlock iPhones running iOS 17.4 or later, according to leaked documents verified by 404 Media. The documents provide a rare glimpse into the capabilities of the company's mobile forensics tools and highlight the ongoing security improvements in Apple's latest devices. The leaked "Cellebrite iOS Support Matrix" obtained by 404 Media...
Apple Watch Series 9

2024 Apple Watch Lineup: Key Changes We're Expecting

Tuesday July 16, 2024 7:59 am PDT by
Apple is seemingly planning a rework of the Apple Watch lineup for 2024, according to a range of reports from over the past year. Here's everything we know so far. Apple is expected to continue to offer three different Apple Watch models in five casing sizes, but the various display sizes will allegedly grow by up to 12% and the casings will get taller. Based on all of the latest rumors,...
tinypod apple watch

TinyPod Turns Your Apple Watch Into an iPod

Wednesday July 17, 2024 3:18 pm PDT by
If you have an old Apple Watch and you're not sure what to do with it, a new product called TinyPod might be the answer. Priced at $79, the TinyPod is a silicone case with a built-in scroll wheel that houses the Apple Watch chassis. When an Apple Watch is placed inside the TinyPod, the click wheel on the case is able to be used to scroll through the Apple Watch interface. The feature works...

Top Rated Comments

DrFu79 Avatar
154 months ago
I have NO sympathy for people who lose their passwords, their security questions and their credit card id at the same time.
Sorry.
If you lose your passport, your birth certificate and your house keys at the same time, you are also in trouble - rightfully so. Identity theft is serious. :rolleyes:
Score: 11 Votes (Like | Disagree)
thefourthpope Avatar
154 months ago
1password keeps me sane
Score: 8 Votes (Like | Disagree)
smileyborg Avatar
154 months ago
I think we've moved into an era where the traditional username and password combination for authentication is insufficient, both from a security and feasibility standpoint.
Score: 6 Votes (Like | Disagree)
kas23 Avatar
154 months ago
I would hate to be an Apple employee working the phones right now. I just can't imagine how many stupid people must be calling. I know Mac users have been shown to have higher IQs, but I'm sure it's the opposite with iPhone users.
Score: 6 Votes (Like | Disagree)
ChazUK Avatar
154 months ago
Last pass has me sorted. I'm slowly learning many of the generated passwords by using them regularly too.

Such a shame to see people stuck like this but due to the constant media scrutiny towards Apple, they're damned if they do and damned if they don't.
Score: 5 Votes (Like | Disagree)
pubwvj Avatar
154 months ago
One more reason not to use iCloud.
Store Locally.
Score: 4 Votes (Like | Disagree)