Paul Sinclair 

1.5K posts

Paul Sinclair  banner
Paul Sinclair 

Paul Sinclair 

@ORIPIK1

🧑🏼‍💻 iOS / Android / Mobile Developer 📲 Mobile Development 🚀 Computer Science 🌟 Swift / SwiftUI

Katılım Mart 2013
387 Takip Edilen1.3K Takipçiler
Sabitlenmiş Tweet
Paul Sinclair 
Paul Sinclair @ORIPIK1·
My Apple Developer account was hacked today. Email changed. Phone numbers changed. Apps being transferred without my consent. 8 apps. My entire business at risk. Has anyone dealt with this? How did you recover? @Apple @AppleSupport #BuildInPublic Please RT 🙏
English
59
62
422
91.4K
Paul Sinclair 
Paul Sinclair @ORIPIK1·
@CihadTurhan @alpennec @ChrisKruegerDev @juanjovn They managed it in about 30 minutes, which was completely insane. I was surprised by how quickly it happened; I’ve never done an app transfer so I wasn’t familiar with the process. However, it’s absolutely true they did it in about 30 minutes…
English
1
0
1
95
Paul Sinclair 
Paul Sinclair @ORIPIK1·
@_appcartel @Apple @AppleSupport Still figuring it out, but session cookie hijacking is on the table. Steal a valid auth cookie, replay the session and 2FA becomes completely irrelevant. No password needed. 😕
English
0
0
1
228
Paul Sinclair 
Paul Sinclair @ORIPIK1·
My Apple Developer account was hacked today. Email changed. Phone numbers changed. Apps being transferred without my consent. 8 apps. My entire business at risk. Has anyone dealt with this? How did you recover? @Apple @AppleSupport #BuildInPublic Please RT 🙏
English
59
62
422
91.4K
Paul Sinclair 
Paul Sinclair @ORIPIK1·
@alpennec @juanjovn Thank you so much Axel! It really means a lot to me. You have no idea how much I appreciate it. Tomorrow starts my first day, report + apple developer support💪
English
0
0
1
79
Paul Sinclair 
Paul Sinclair @ORIPIK1·
@_artcc_ @juanjovn btw no descarto que haya sido openclaw. si pulsa un enlace malicioso sin darte cuenta, te roba la cookie y game over
Español
0
0
0
72
Paul Sinclair 
Paul Sinclair @ORIPIK1·
mi apuesta es session cookie hijacking. alguien robó una auth cookie válida, replicó la sesión y el 2FA quedó completamente irrelevante. ni contraseña necesitó también pinta que clonaron mi password vault, así que no es solo una cuenta llevamos 48h en modo supervivencia, como la cuarentena pero en digital. revisando sesiones, rotando credenciales, cerrando accesos uno a uno mañana lunes denuncia + soporte developer de apple. los fines de semana no hay línea telefónica así que aquí seguimos 💀 ni en las películas de miedo, terrible...
Español
2
0
0
72
Paul Sinclair 
Paul Sinclair @ORIPIK1·
nope. used apple's official site only but here's the thing: i got the SMS *before* changing my password. attacker already had access at that point my bet? session cookie hijacking. steal a valid auth cookie, replay the session, 2FA is completely irrelevant. no credentials needed maybe also cloned my password vault. still tracing the initial vector, possibly a malicious link clicked somewhere without realizing it 💀
English
0
0
1
339
Bilal Bakr
Bilal Bakr@bil0090·
Prob the root cause was a suspicious link you opened on your work laptop that stole all your cookies Happened to me once with this X account Thankfully X support helped immediately I know the feeling you have, its terrifying Just calm down everything is hopefully gonna be solved GL 🫡
English
2
0
2
1.8K
Ben
Ben@BenToFound·
@ORIPIK1 @Apple @AppleSupport This is genuinely terrifying. 8 apps is your whole livelihood. Have you tried escalating through Apple business support rather than consumer? Sometimes getting through to the developer relations team directly moves faster. Hope you get it sorted quickly.
English
1
0
7
5K
Paul Sinclair 
Paul Sinclair @ORIPIK1·
Already called. 50 minutes on the phone, they remoted into my PC, and they guide me to literally try Forgot Password, I couldn't reset because the recovery number was changed by the attacker. Literally told me "we can't help you, contact Developer Support." Developer phone support doesn't work on weekends. Trust me the first thing was calling them.
English
2
0
2
783
Hulya
Hulya@hey_hulya·
@ORIPIK1 @Apple @AppleSupport Two days ago, I got a notification that someone tried to login to my account. I changed the password asap, but i don't know what happened exactly.
English
2
0
4
4.9K
Kevin
Kevin@nc_coffee_guy·
@ORIPIK1 @Apple @AppleSupport This is the literal definition of a nightmare. Sorry you are dealing with this. Please share the outcome.
English
1
0
1
2.2K