China attacks lead Apple to alert users on iCloud threats

China has allegedly staged the attack, according to an anti-censorship group.

Apple has warned users about attacks on its iCloud website, after monitoring groups alleged that China had tried to intercept customer information from the service.

Although China was not named, Apple said Tuesday it was "aware of intermittent organized network attacks" on its iCloud service that were designed to obtain user information, according to a company support page.

Apple said the iCloud servers are still secure but advised customers accessing the service to always verify that they've connected to an authentic iCloud website via a trusted browser.

Starting over the weekend, visits to Apple's iCloud site in China began returning an invalid digital certificate, a sign that the connections had been tampered with using a technique known as "man-in-the-middle attack", according to anti-censorship group GreatFire.org.

Such attacks involve the hacker trying to eavesdrop on the communication by tricking victims into believing they've visited a secure website. Once duped, the victim's activities can be monitored.

GreatFire.org alleged that the Chinese government was behind the attack, as a way to steal username and password information from Apple's iCloud users. But on Tuesday a spokeswoman with the Chinese Foreign Ministry said the country opposed any form of hacking.

The man-in-the-middle attack on the iCloud service was just one of several in China that have targeted U.S. websites. Starting late last month, visits to Yahoo's site from the country were also mysteriously returning invalid digital certificates.

Both Apple and Yahoo have declined comment.

Security vendor Netresec analyzed the attack on the iCloud service, and said it appeared to be conducted over networks belonging to China Telecom, and China Unicom, two state-controlled broadband providers. Both companies did not immediately respond to a request for comment.

The attack on the iCloud service came just after Apple began officially selling its iPhone 6 in mainland China. Before it launched, Apple had increased the security on its iOS software, following a request from a Chinese regulator.

The sophistication of the attack probably means the hackers had access to an Internet service provider, allowing them to create the insecure connections to the Apple site, said Su Gim Goh, a security adviser with F-Secure. "It's not something that a script kiddie could have done," he said, adding that an organized group or government could have been behind it.

"iCloud is a big service abroad. This is one good way to look at user content," he said.

Mainland China, Hong Kong and Taiwan represents Apple's second biggest market behind the U.S. On Tuesday, GreatFire.org said Apple had changed its domain name system in China to avoid the attack.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags privacyApple

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Michael Kan

IDG News Service
Show Comments

Father’s Day Gift Guide

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?