The iPhone feature that lets families share apps is being used to scam people
Appleās Family Sharing feature on iOS was introduced in 2014, enabling iPhone and iPad users to share photos, iCloud storage and iTunes media content with up to five family members.
Unfortunately, it appears the family-friendly feature isn't as secure as one would expect, with reports of Chinese scammers hijacking Apple IDs via Family Sharing and using them to make purchases worth hundreds of dollars.
According to a reader email sent to Business Insider, one user was unable to download apps onto his device as his account was linked to Family Sharing, something he doesnāt remember setting up. The only way out was to remove himself from the sharing feature, which required the permission of a Chinese person whom he had no idea how to get in touch with.
While Apple support was able to get him out of the Family Sharing mess, it's since become apparent that the Business Insider reader wasnāt alone.
App Store shopping spree
A quick search online reveals that scamming unsuspecting iOS users has been going on for a while. Discussions on both Reddit and Apple Community date back to 2016, with people complaining of being added to a āfamilyā or having unfamiliar people added to their Family Sharing account.
According to one user, a scammer from Youku, China, was able to make app and iTunes purchases using a second account associated with his own ā something he never did himself. Again, Apple was able to help him sort this out, meaning that the Cupertino company is fully aware of the problem.
Whether thereāll be a proper fix for this is anyoneās guess, but there are ways you can protect yourself from similar scams.
Staying safe
Going through the forum threads, itās clear that most people either used the same password across multiple accounts or didnāt have two-factor authentication turned on, making it rather easy for their Apple IDs to be hacked.
Firstly, itās important to check if any of your online account details have been leaked. The Have I Been Pwned database has a complete list of known breaches; all you need do is enter your email address.
Ensuring you have unique passwords for all your accounts will also help keep you safe in case of a data breach ā if one username and password has been compromised, youāll know that everything else is fine as they donāt share the same details.
However, the best way to keep your Apple ID secure is to enable two-factor authentication on your iPhone or iPad. This will prevent anyone using your username and password from gaining access to your account without a six-digit verification code thatās sent directly to your device.