{"id":403824,"date":"2017-09-21T03:23:38","date_gmt":"2017-09-20T19:23:38","guid":{"rendered":"https:\/\/www.macrumors.com\/2017\/09\/20\/hackers-find-my-iphone-remote-mac-lock\/"},"modified":"2017-09-21T03:23:38","modified_gmt":"2017-09-20T19:23:38","slug":"hackers-using-iclouds-find-my-iphone-feature-to-remotely-lock-macs-and-demand-ransom-payments","status":"publish","type":"post","link":"https:\/\/people.utm.my\/asmawisham\/hackers-using-iclouds-find-my-iphone-feature-to-remotely-lock-macs-and-demand-ransom-payments\/","title":{"rendered":"Hackers Using iCloud&#8217;s Find My iPhone Feature to Remotely Lock Macs and Demand Ransom Payments"},"content":{"rendered":"<p>Over the last day or two, several Mac users appear to have been locked out of their machines after hackers signed into their iCloud accounts and initiated a remote lock using Find My iPhone.<\/p>\n<p>With access to an iCloud user&#8217;s username and password, Find My iPhone on iCloud.com can be used to &#8220;lock&#8221; a Mac with a passcode even with two-factor authentication turned on, and that&#8217;s what&#8217;s going on here.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.macrumors.com\/article-new\/2017\/09\/maclockedfindmyiphone-800x600.jpg\" alt=\"\" width=\"800\" height=\"600\" class=\"aligncenter size-large wp-image-590840\"\/><br \/>Apple allows users to access Find My iPhone without requiring two-factor authentication in case a person&#8217;s only trusted device has gone missing.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.macrumors.com\/article-new\/2017\/09\/2faicloud-800x557.jpg\" alt=\"\" width=\"800\" height=\"557\" class=\"aligncenter size-large wp-image-590841\"\/><\/p>\n<p><center><em>2-factor authentication not required to access Find My iPhone and a user&#8217;s list of devices.<\/em><\/center><br \/>Affected users who have had their iCloud accounts hacked are receiving messages demanding money for the passcode to unlock a locked Mac device.<center readability=\"0.87828947368421\"><\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\" readability=\"3.5131578947368\">\n<p lang=\"en\" dir=\"ltr\">Y&#8217;all my MacBook been locked and hacked. Someone help me <a href=\"https:\/\/twitter.com\/Apple\">@apple<\/a> <a href=\"https:\/\/twitter.com\/AppleSupport\">@AppleSupport<\/a> <a href=\"https:\/\/t.co\/BE110TMgSv\">pic.twitter.com\/BE110TMgSv<\/a><\/p>\n<p>\u2014 Jovan (@bunandsomesauce) <a href=\"https:\/\/twitter.com\/bunandsomesauce\/status\/909181846591860736\">September 16, 2017<\/a><\/p><\/blockquote>\n<p><\/center><br \/>\n<br \/>The usernames and passwords of the iCloud accounts affected by this &#8220;hack&#8221; were likely found through various site data breaches and have not been acquired through a breach of Apple&#8217;s servers.<\/p>\n<p>Impacted users likely used the same email addresses, account names, and passwords for multiple accounts, allowing people with malicious intent to figure out their iCloud details.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.macrumors.com\/article-new\/2017\/09\/lockmacfindmyiphone.jpg\" alt=\"\" width=\"600\" height=\"618\" class=\"aligncenter size-full wp-image-590843\"\/><\/p>\n<p><center><em>It&#8217;s easy to lock a Mac with a passcode in Find My iPhone if you have someone&#8217;s Apple ID and password.<\/em><\/center><br \/>\n<br \/>To prevent an issue like this, Apple users should <strong>change their Apple ID passwords<\/strong>, enable two-factor authentication, and never use the same password twice. Products like 1Password, LastPass, and even Apple&#8217;s own iCloud Keychain are ideal ways to generate and store new passwords for each and every website.<center readability=\"1.332298136646\"><\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\" readability=\"5.3291925465839\">\n<p lang=\"en\" dir=\"ltr\">So a hacker gained access to my iCloud account (despite two-factor authorization) while I was asleep this morning.<\/p>\n<p>\u2014 Jason Caffoe (@jcaffoe) <a href=\"https:\/\/twitter.com\/jcaffoe\/status\/910543213148102656\">September 20, 2017<\/a><\/p><\/blockquote>\n<p><\/center><br \/>\n<br \/>Users who have had their Macs locked will need to get in contact with Apple Support for assistance with removing the Find My iPhone lock.<\/p>\n<p><em>(Thanks, Eli!)<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over the last day or two, several Mac users appear to have been locked out of their machines after hackers signed into their iCloud accounts and initiated a remote lock using Find My iPhone. With access to an iCloud user&#8217;s username and password, Find My iPhone on iCloud.com can be used to &#8220;lock&#8221; a Mac [&hellip;]<\/p>\n","protected":false},"author":5817,"featured_media":403825,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[25],"tags":[68,69,59,26],"class_list":["post-403824","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-apple","tag-macrumors","tag-media","tag-technology"],"_links":{"self":[{"href":"https:\/\/people.utm.my\/asmawisham\/wp-json\/wp\/v2\/posts\/403824","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/people.utm.my\/asmawisham\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/people.utm.my\/asmawisham\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/people.utm.my\/asmawisham\/wp-json\/wp\/v2\/users\/5817"}],"replies":[{"embeddable":true,"href":"https:\/\/people.utm.my\/asmawisham\/wp-json\/wp\/v2\/comments?post=403824"}],"version-history":[{"count":0,"href":"https:\/\/people.utm.my\/asmawisham\/wp-json\/wp\/v2\/posts\/403824\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/people.utm.my\/asmawisham\/wp-json\/wp\/v2\/media\/403825"}],"wp:attachment":[{"href":"https:\/\/people.utm.my\/asmawisham\/wp-json\/wp\/v2\/media?parent=403824"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/people.utm.my\/asmawisham\/wp-json\/wp\/v2\/categories?post=403824"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/people.utm.my\/asmawisham\/wp-json\/wp\/v2\/tags?post=403824"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}