HACKER Q&A
📣 ta-wtfsecurity

Weird Google and Apple account access?


Mid of December I received three Google auth codes via SMS in a row. I did not receive any security e-mails to my original account nor my recovery e-mail addresses related to any login attempts. To make sure it's not my mailserver which is compromised, I logged in into all known Google accounts I have (on a different device) and checked the security log which (as of my knowledge) can't be changed/wiped. All seemed fine and I received security related e-mails as expected when I logged in myself. I ignored the incident even though I am pretty sure that auth codes will only be sent after a valid password has been entered.

Today I received an e-mail stating that my Apple accounts surname has been changed: Two characters have been added to my original surname. What I thought was a fake e-mail turns out to be valid: my surname was actually changed as I verified on my device in the iOS settings. Again, no login attempt was being reported to me and I was not asked for a 2FA code on my phone (the only Apple device I own). I could change my surname back without problems.

All accounts have 2FA via TOTP. All accounts have their own unique-randomly generated passwords. I specifically don't have SMS 2FA enabled because I know that SIM-swapping is a thing. I checked Have I Been Pwned without any results. I store all my passwords in a self-hosted Vaultwarden which is in itself 2FA protected. I use the browser extensions in Firefox and Edge as well as the Windows and iOS Bitwarden App from the respective official stores. My mails are hosted on a smaller-but-known mail provider from Switzerland (not Protonmail). The amount of e-mails I received for my domain matches the amount of e-mails that are being reported in the admin interface of the e-mail provider for that domain on that day, so I think it's unlikely that someone quickly deleted e-mails. The MX-DNS records for my domain are fine and are also protected behind 2FA.

I know the usual advice is to rotate my passwords which I will do, but I do not know which of my devices I can trust currently. The question begging me more though is: why would someone append two characters to my surname and why is nothing "happening" with my data? No financial transactions that I don't know about (I checked), no ransomware encrypted anything on my devices, I didn't lose access to any account.


  👤 xilinx_guy Accepted Answer ✓
Hackers that are seeking banking passwords will sometimes monitor hacked devices for months, until they can convert stolen credentials to cash by buying crypto. The real question is whether any of your devices have been compromised, since Google/Apple account manipulation would appear to come directly from you. Changing passwords will be futile if your devices have been pwned.