Feeds

Hacker claims whaling expedition harpooned Steve Jobs

Alleged Amazon account access

5 things you didn’t know about cloud backup

A hacker has claimed he hijacked the Amazon.com account of Steve Jobs by sending the Apple CEO a phony email that tricked him into logging in to a fake website, according to the Cult of Mac blog.

Reporter Leander Kahney was ultimately unable to confirm if screenshots and other information provided by the hacker, who identified himself as "orin0co," were authentic. Apple didn't comment for the story and Amazon said it was unaware of any such breach.

But if true, the account includes some tantalizing details. According to orin0co, Jobs has purchased 20,000 items from Amazon in the past 10 years, a binge that could rival the legendary shopping sprees of Michael Jackson and Paris Hilton. Among Jobs's more recent buys was a Blu-Ray DVD, an HBO miniseries on DVD, and a copy of The Nuclear Express, a history of the nuclear bomb.

More intriguing still, the claim, if true, would suggest that even someone as sophisticated as Jobs can fall for a simple phishing email.

"2 years ago, I set a amazon.com fake page, and sent emails to different IT people around the globe," orin0co wrote in an email. "Among some other unknown person, Steve Jobs got my mail, he didn't notice the scam I set so he 'updated' his amazon account with data( name, address, credit card number, phone, amazon user and password) which I received, sent to my mail."

The miscreant goes on to portray the breach as some sort of public service.

"Imagine how safe Mac is if you can trick the mighty Steve Jobs," he added, as if the personal failing of one CEO - assuming it happened at all - could be equated with the overall security posture of the Mac platform. He then went on to demand Cult of Mac pay a fee to get access to the detailed data, something the blog refused to do.

Of course, we already knew that CEOs and similarly powerful executives were gullible. Highly targeted "whaling" emails that singled out corporate fat cats managed to trick more than 15,000 recipients in 15 months into believing they were legitimate, according to a study by security firm iDefense. The low-volume scams are attractive to fraudsters because they go after high-worth individuals who have much more to lose than the rest of us. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
JLaw, Kate Upton exposed in celeb nude pics hack
100 women victimised as Apple iCloud accounts reportedly popped
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.