Chinese authorities allegedly are using a man-in-the-middle attack to harvest Apple ID information from Chinese users visiting Apple's iCloud service, reports web censorship blog Great Fire (via The Verge). A similar attack reportedly targets Microsoft's login.live.com website.

icloudbeta
According to Great Fire, Chinese users trying to access iCloud.com are redirected to a fake site that resembles Apple's iCloud website. While some browsers will issue a warning, popular Chinese browser Qihoo gives no indication users are entering their Apple credentials into a dummy site. Users fooled by the site may be putting their personal information at risk as attackers can then use these login details to access contacts, messages and more stored in iCloud.

This is clearly a malicious attack on Apple in an effort to gain access to usernames and passwords and consequently all data stored on iCloud such as iMessages, photos, contacts, etc. Unlike the recent attack on Google, this attack is nationwide and coincides with the launch today in China of the newest iPhone. While the attacks on Google and Yahoo enabled the authorities to snoop on what information Chinese were accessing on those two platforms, the Apple attack is different. If users ignored the security warning and clicked through to the Apple site and entered their username and password, this information has now been compromised by the Chinese authorities.

This attack follows the Chinese launch of the new iPhone 6 and 6 Plus and may be related to the encryption options and increased security of Apple's iOS 8. It is possible Chinese authorities are using this hack to penalize Apple for taking extra measures that would prevent the government from snooping on phones.

Great Fire advises Chinese users to switch to a trusted browser such as Firefox and Chrome, which will warn users when they access an illegitimate site. Apple owners also can use a VPN to bypass this redirection and connect directly to iCloud.com. Two-factor authentication may also prevent attackers from accessing an iCloud account using a compromised username and password.

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Tag: iCloud

Top Rated Comments

whooleytoo Avatar
144 months ago
Even the NSA wouldn't do this. Would they?

Too lazy. They just go straight to Apple and ask them to hand the data over.
Score: 21 Votes (Like | Disagree)
JoEw Avatar
144 months ago
Trying to stop the revolution that surely is coming.
Score: 17 Votes (Like | Disagree)
nerdAFK Avatar
144 months ago
DIE Communist Party DIE DIE DIE!
Score: 15 Votes (Like | Disagree)
brendu Avatar
144 months ago
But Tim Cook just gave these governments a big middle finger - "even we're required to provide the data we cannot decrypt it"...

(if Tim is not lying)

He claims they (Apple) can't decrypt it. To the best of his knowledge this is likely true. I still wouldn't bet against the possibility that the NSA has full access to Apple's (and everyone else's) servers and no one at Apple even knows about it.
Score: 12 Votes (Like | Disagree)
dannyyankou Avatar
144 months ago
Wow! Doubling down? Looking fwd to Tim's response!

This is a classic example of phishing, so it's not Apple's fault. They should use a better browser next time.
Score: 8 Votes (Like | Disagree)
haruhiko Avatar
144 months ago
Too lazy. They just go straight to Apple and ask them to hand the data over.

But Tim Cook just gave these governments a big middle finger - "even we're required to provide the data we cannot decrypt it"...

(if Tim is not lying)
Score: 7 Votes (Like | Disagree)

Popular Stories

2024 iPhone Boxes Feature

Apple Adjusts Trade-In Values for iPhones, iPads, Macs, and More

Thursday November 6, 2025 11:12 am PST by
Apple today updated its trade-in values for select iPhone, iPad, Mac, and Apple Watch models. Trade-ins can be completed on Apple's website, or at an Apple Store. The charts below provide an overview of Apple's current and previous trade-in values in the U.S., according to its website. Maximum values for most devices either decreased or saw no change, but the iPad Air received a slight bump. ...
Finder Siri Feature

Apple's New Siri Will Be Powered By Google Gemini

Wednesday November 5, 2025 11:57 am PST by
The smarter, more capable version of Siri that Apple is developing will be powered by Google Gemini, reports Bloomberg. Apple will pay Google approximately $1 billion per year for a 1.2 trillion parameter artificial intelligence model that was developed by Google. For context, parameters are a measure of how a model understands and responds to queries. More parameters generally means more...
iOS 26

iOS 26.1 Available Now With These 8 New Features

Monday November 3, 2025 5:54 am PST by
Following more than a month of beta testing, Apple released iOS 26.1 on Monday, November 3. The update includes a handful of new features and changes, including the ability to adjust the look of Liquid Glass and more. Below, we outline iOS 26.1's key new features. Liquid Glass Toggle iOS 26.1 lets you choose your preferred look for Liquid Glass. In the Settings app, under Display...
Liquid Glass General Feature

Apple Shares Liquid Glass Design Gallery

Thursday November 6, 2025 2:45 pm PST by
Apple is promoting the new Liquid Glass design in iOS 26, showing off the ways that third-party developers are embracing the aesthetic in their apps. On its developer website, Apple is featuring a visual gallery that demonstrates how "teams of all sizes" are creating Liquid Glass experiences. The gallery features examples of Liquid Glass in apps for iPhone, iPad, Apple Watch, and Mac. Apple...
apple watch se 3 always on

Apple to Remove iPhone-Apple Watch Wi-Fi Sync in EU With iOS 26.2

Thursday November 6, 2025 4:37 am PST by
Apple in iOS 26.2 will disable automatic Wi-Fi network syncing between iPhone and Apple Watch in the European Union to comply with the bloc's regulations, suggests a new report. Normally, when an iPhone connects to a new Wi-Fi network, it automatically shares the network credentials with the paired Apple Watch. This allows the watch to connect to the same network independently – for...
airtag purple

Apple's Website Lists AirTag 4-Pack at Shockingly Low Price [Updated]

Friday November 7, 2025 6:40 am PST by
Apple's online store in the U.S. is suddenly offering a pack of four AirTags for just $29, which is the same price as a single AirTag. This is likely a pricing error, and it is unclear if orders will be fulfilled. Apple has not discounted the AirTag four-pack in any other countries that we checked. Delivery estimates are already pushing into late November to early December, suggesting...
ikea smart home devices

IKEA Debuts 21 HomeKit-Compatible Smart Bulbs, Sensors, and Controls

Thursday November 6, 2025 4:08 pm PST by
IKEA today announced the upcoming launch of 21 new Matter-compatible smart home products that will be able to interface with HomeKit and the Apple Home app. There are sensors, lights, and control options, all of which will be reasonably priced. Some of the products are new, while some are updates to existing lines that IKEA previously offered. There are a series of new smart bulbs that are...
Home Hub Command Center with Dome Base Feature

Apple's 2026 Smart Home Revamp: All the Rumors

Wednesday November 5, 2025 3:54 pm PST by
It's been over a decade since Apple's HomeKit smart home platform launched, and it is overdue for an update. HomeKit and the Home app can no longer keep up with AI-powered solutions from other companies like Google and Amazon, but that's set to change with a smart home revamp that Apple has planned for 2026. Home Hub Apple is working on a home hub or "command center" that will serve as a...