logo

Cybercrime duo accused of picking $2.5M from Apple's orchard

ID: 9bc42849-2dfb-5e19-b094-d283031c4014

STIX ID: report--9bc42849-2dfb-5e19-b094-d283031c4014

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2024-02-08

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Two researchers are accused of compromising a third‑party customer support contractor (via a password‑reset tool and credential theft), using VPN/RDP access and Jamf‑driven remote machines with reverse SSH tunnels to reach a major tech company's backend (likely Apple). They allegedly used App Store Connect/Toolbox to modify orders and redeem or obtain over $2.6M in gift cards and hardware, shipping items through transshipment companies to conceal identities; one defendant has also been credited separately for legitimate vulnerability research (CVE reports).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.