Apple Allegedly Provided User Data to Hackers That Forged Legal Requests - MacRumors
Skip to Content

Apple Allegedly Provided User Data to Hackers That Forged Legal Requests

Apple apparently provided some user data to a hacker group that forged legal requests for the information in a 2021 social engineering scam, reports Bloomberg, citing three sources with knowledge of what happened.

apple logo plain
The hackers masqueraded as law enforcement officials and were able to convince Apple's staff to provide them with data that included customer addresses, phone numbers, and IP addresses after sending forged "emergency data requests."

Typically, Apple provides this information with a search warrant or subpoena from a judge, but that does not apply with emergency requests because they are used in cases of imminent danger. Apple did not confirm that data had been shared, and directed Bloomberg to its law enforcement guidelines when asked for comment.

In response to a request for comment, an Apple representative referred Bloomberg News to a section of its law enforcement guidelines.

The guidelines referenced by Apple say that a supervisor for the government or law enforcement agent who submitted the request "may be contacted and asked to confirm to Apple that the emergency request was legitimate," the Apple guideline states.

Facebook parent company Meta also provided data to the same hacker group, and in a statement, ‌Meta‌ said that it is working with law enforcement on the suspected fraudulent requests. Information obtained from Apple, Facebook, and others has been used in harassment campaigns and could be used in financial fraud schemes.

The requests were sent from hacked email domains belonging to law enforcement officials from multiple countries, and were crafted to look legitimate with forged signatures of real or fictional law enforcement officers.

According to Bloomberg, a cybercrime group known as "Recursion Team" is linked to some of the forged legal requests that were sent to various companies in 2021. Some of the hackers are believed to be minors located in the United States and United Kingdom, and at least one of the minors involved has also participated in the Lapsus$ group that attacked Microsoft, Samsung, and Nvidia.

As The Verge pointed out earlier today, Lapsus$ shared a post on Telegram claiming to have stolen 70GB of data from international software developer Globant, and screenshots of the data captured show a folder called "apple-health-app." What's in that folder and whether it contains data obtained from Apple is unclear.

Tag: Hack

Popular Stories

Apple Skipping iPhone 18 This Year

Apple Skipping iPhone 18 Launch This Year

Wednesday August 12, 2026 6:59 am PDT by
Apple supplier Pegatron today indirectly confirmed that the standard iPhone 18 model will not be released until next year, according to a new report. Pegatron held an earnings call for the second quarter of 2026 today. On the call, Taiwan's Economic Daily News said Pegatron indicated that one of its customers will be changing its usual smartphone shipment schedule. As widely expected, the...
Apple Event Logo

Apple Working on All-New Operating System

Tuesday August 11, 2026 1:11 pm PDT by
Apple is developing an all-new operating system that is essentially a mix of tvOS, watchOS, and iOS, according to Bloomberg's Mark Gurman. In a recent report, he said the operating system will feature a grid of icons, widgets, and apps, along with customizable clock faces. The new software platform is intended for Apple's long-rumored smart home hub. With built-in facial recognition, the...
iPhone 18 Pro Dark Cherry Feature

iPhone 18 Pro Max's Larger Battery Capacity Allegedly Revealed

Monday August 10, 2026 9:37 am PDT by
The upcoming iPhone 18 Pro Max will be equipped with a nearly 12% larger battery compared to the iPhone 17 Pro Max, according to an apparent leak. An alleged photo of a battery pack for a Chinese model of the iPhone 18 Pro Max with a SIM card tray lists a capacity of 5,391 mAh, up from 4,823 mAh for the equivalent iPhone 17 Pro Max battery. The photo was shared on the Korean platform Naver...

Top Rated Comments

blazerunner Avatar
57 months ago
No! Not Apple! Not this fine upstanding company with a squeaky clean record!
Score: 24 Votes (Like | Disagree)
Pro_the_legend Avatar
57 months ago
And they want people to trust them with things like CSAM… lol
Score: 22 Votes (Like | Disagree)
gaximus Avatar
57 months ago

Unfortunate but human being aren't infallible.
Which is exactly why a backdoor will always fail. The only way to have true privacy, is if Apple encrypted the data from themselves too, meaning that they can't give the information, if they don't know who they have information on.
Score: 17 Votes (Like | Disagree)
IllinoisCorn Avatar
57 months ago
I am SUPER excited for the sweaty video Rene Ritchie will make defending Apple. Grade A propaganda. He's probably on the phone with Apple PR people as I type this....
Score: 16 Votes (Like | Disagree)
boast Avatar
57 months ago
Can't wait for the law enforcement backdoors on the iPhones so hackers can take even better advantage instead of just iCloud data for now.
Score: 13 Votes (Like | Disagree)
57 months ago
Hopefully the final nail in the coffin for Apple thinking anyone will trust their competence and execution for the proposed CSAM child pornography reporting tool.
Score: 10 Votes (Like | Disagree)