Security Researcher Allegedly Exploited Internal Apple Tool to Steal Millions

by

A security researcher who reported bugs to Apple was arrested in January for defrauding the company out of millions of dollars, according to a report from 404 Media.

bug security vulnerability issue fix larry
The researcher, Noah Roskin-Frazee, was accused alongside a co-conspirator obtaining over $3 million in products and services through more than two dozen fraudulent orders. That included around $2.5 million in gift cards and over $100,000 in “products and services.”

While Apple is not explicitly named in the court records, an unnamed “Company A” is located in Cupertino, California, and is clearly Apple. The court mentions that one of the perpetrators used gift cards to “purchase Final Cut Pro on Company A’s App Store,” and Apple is the only company that sells the software.

In 2019, Frazee and his accomplice used a password reset tool to gain access to an employee account that belonged to an unnamed “Company B,” which does customer support for Apple. That account led to access to additional employee credentials, and Frazee accessed Company B’s VPN servers. From there, Frazee was able to get into Apple’s systems, placing fraudulent orders for Apple products.

He used Apple’s “Toolbox” program that could be used to edit orders after they were placed, and he changed order values to zero, added products to orders, and extended AppleCare contracts. He abused Apple’s program from January to March 2019.

The defendants remoted into computers located in India and Costa Rica as part of the scheme, the indictment adds. The scam itself involved changing order monetary values to zero, adding products to existing orders without cost such as phones and laptops, and extending existing service contracts, the indictment adds. That included extending a customer service contract that was associated with one of the defendants and his family for an extra two years without paying.

Apple thanked Frazee for in a January support document for finding several bugs in macOS Sonoma, and the document was published less than two weeks after he was arrested. “We would like to acknowledge Noah Roskin-Frazee and Prof. J. (ZeroClicks.ai Lab) for their assistance,” reads Apple’s page in reference to a Wi-Fi vulnerability.

Frazee has been charged with wire fraud, mail fraud, conspiracy to commit wire fraud and mail fraud, conspiracy to commit computer fraud and abuse, and intentional damage to a protected computer. He will be required to forfeit all of the stolen goods, and he could be sentenced to more than 20 years in jail if convicted.

Popular Stories

Apple Releasing iOS 17.4 in March With These New Features and Changes

Apple last month confirmed that iOS 17.4 will be released in March, and the update includes several new features and changes for the iPhone. Key new features in iOS 17.4 include major App Store changes in the EU, Apple Podcasts transcripts, SharePlay for the HomePod, and new emoji. The update also includes preparations for the launch of next-generation CarPlay later this year. Apple’s pres…

Apple Preparing iOS 17.3.1 Update for iPhone

Apple appears to be internally testing an iOS 17.3.1 update for the iPhone, based on evidence of the software version in our website’s analytics logs this week. Our logs have revealed the existence of several iOS 17 versions before Apple released them, ranging from iOS 17.0.3 to iOS 17.2.1, so there is a good chance that Apple will follow through with releasing iOS 17.3.1. iOS 17.3.1…

OLED iPad Pro Price Hikes May Be Lower Than Early Reports Suggested

Tuesday February 6, 2024 3:52 am PST by

Apple’s price increases for its upcoming iPad Pro models with OLED displays could be up to $160, which is substantially lower than early reports have predicted, claims DigiTimes. Apple’s current 11-inch iPad Pro starts at $799, while the 12.9-inch model with a mini-LED display starts at $1,099. Previous reports have claimed that the pricing for the next-generation 11-inch ‌OLED ‌iPad‌ …

Videos: Apple Vision Pro Tested for Work, Gaming, Flying, and Sports

Apple Vision Pro launched in the U.S. on Friday, and there are already several YouTube videos that demonstrate using the headset for remote work, gaming, in-flight entertainment, watching sports, and more. We have rounded up these videos below. If you want to experience the Vision Pro for yourself, you can book an appointment for a free Vision Pro demo at any Apple Store in the U.S. on…

Apple Engineers Allegedly Able to Use Vision Pro With Two Mac Displays

Tuesday February 6, 2024 8:13 am PST by

Apple’s new Vision Pro headset can serve as an external display for a Mac, letting you view and control your computer’s screen in a visionOS window. The feature can currently be used with only a single Mac display, but analyst Ben Thompson today suggested that Apple has internally tested the ability to use multiple displays. “I have heard through the grapevine that Vision Pro users at Apple…

iPhone 16’s New ‘Capture Button’ Rumored to Emulate High-End Camera Functionality

The iPhone 16 lineup’s new Capture Button will be able to detect multiple levels of pressure to emulate a two-step shutter button from dedicated digital cameras, according to a Weibo leaker. MacRumors was first to reveal the presence of a new button on the iPhone 16 models called the “Capture Button” last year. Bloomberg’s Mark Gurman remarked that the Capture Button will be able to record…

Honda Offering Wireless Apple CarPlay Upgrade for 2018-2022 Accords

Honda recently announced that owners of 2018-2022 Accord models in the U.S. are now eligible for a wireless Apple CarPlay upgrade option for a fee. The update can be completed at any Honda dealership in the U.S. for a suggested price of $112, plus a labor fee, according to the announcement. Eligible customers can book a service appointment on their local Honda dealership’s website….

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech Blog

See More Posts

Contact us

Partner with Us for Comprehensive IT

We’re happy to answer any questions you may have and help you determine which of our services best fit your needs.

Your benefits:
What happens next?
1

We Schedule a call at your convenience 

2

We do a discovery and consulting meting 

3

We prepare a proposal 

Schedule a Free Consultation
top
Simplifying IT
for a complex world.
Platform partnerships