Company says it, not FBI, was hacked for Apple device IDs leak

Advertisement
By Nicole Perlroth, The New York Times | Updated: 10 September 2012 23:14 IST
An Orlando, Fla., company said on Monday that it - not the F.B.I. - was the source of a file hackers posted online last week that contained a million identification numbers for Apple mobile devices.

The company, BlueToad, which works with thousands of publishers to translate printed content into digital and mobile formats, said hackers had breached its systems more than a week ago and stolen the file. A few days after the file appeared online, the company realized it matched the stolen information, said Paul DeHart, BlueToad's chief executive.

That version of events differs sharply from that put forth by the hackers last week. They claimed to have stolen the file from the laptop of an F.B.I. agent - and they said it was proof that the F.B.I. was tracking people through their iPhones, iPads and iPod Touches. They posted one million identification numbers but claimed to have 11 million more in their possession.

A spokesman for the F.B.I. denied last week that the file had been taken from one of its agent's computers, and an Apple spokeswoman said it had never given any such information to the F.B.I.

"We decided to come forward to apologize to our customers, partners and the public in general that this got out there," Mr. DeHart said in an interview. "We face thousands of attacks every day that we've been successful at defending. This one happened to get through."

Mr. DeHart said his company had contacted law enforcement, as well as Apple, to alert them to the breach and had hired an outside security firm to patch its systems. He said BlueToad had "nowhere near" the 12 million identification numbers that the hackers claimed to have stolen.

Apple's unique device identifiers - known as U.D.I.D.'s - are 40-character strings that are tied to a particular device. Apple started to discourage app makers from using U.D.I.D.'s last year after learning that developers and advertisers could use them to track users as they moved from app to app, compiling a profile of user behavior that could be sold or used for ad targeting.

Trudy Muller, an Apple spokeswoman, said Apple recently introduced a new system to replace the use of the U.D.I.D. and would soon be banning apps that tried to use them. "As an app developer, BlueToad would have access to a user's device information, such as U.D.I.D. device name and type," she said. Ms. Muller noted that developers would not have access to more sensitive information like passwords or credit card information, "unless a user specifically elects to provide that information to a developer."

Mr. DeHart said BlueToad collected U.D.I.D. information to keep count of how many people used its services, but reengineered its code to stop collecting identifiers after Apple discouraged their use last year. He said the stolen file contained identifiers collected by older BlueToad mobile apps. That file, he said, contained only three pieces of information: the identifier, the type of device used and the names that owners gave their devices, like "Paul's iPad."

Security experts said the release of that information posed little risk. They said that without more information about device owners - like their e-mail addresses or date of birth - it would be hard for someone to use the data to do harm.

Mr. DeHart said law enforcement officials were still investigating the attack, but suspected that the hackers who conducted the attack were different from the ones who claimed credit for it online. "The way we understand it, somebody got into our systems, took the information and, to prove themselves, handed it to this other group who exploited it for their own purposes," he said.

AntiSec, the hacking group that said it had taken the file from the F.B.I., is a subset of the loose hacking collective known as Anonymous. The group has frequently aimed at the F.B.I. Last February, hackers intercepted a call between law enforcement agents at the bureau and Scotland Yard. But the frequency of such attacks tapered off in March after several members of Anonymous and a spinoff group, LulzSec, were arrested with the help of another hacker turned F.B.I. informant.

Peter Donald, an F.B.I. spokesman, declined to comment on BlueToad's announcement.

Nick Bilton contributed reporting.

© 2012, The New York Times News Service

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. HP OmniBook X 14, Ultra 16 Refreshed With Nvidia RTX Spark 'Superchip'
  2. Huawei Nova 16 Pro, Nova 16 Ultra Debut With 7,000mAh Battery: See Price
  3. WWE 2K26 Review: The Show Must Go On
  1. Asus ROG Edition 20 Lineup Unveiled at Computex 2026 to Commemorate 20 Years of ROG Series Products
  2. Indian Startup Pawzeeble Is Building a Pet-Focused Social Networking Space for Indian Users
  3. Asus ROG Strix Scar 18 (2026) With 240Hz 4K Mini-LED Display Showcased at Computex 2026
  4. Huawei Nova 16 Pro, Nova 16 Ultra Launched With Kirin 9010S SoC, 7,000mAh Battery: Price, Specifications
  5. Huawei Nova 16 Launched With 7,000mAh Battery, 50-Megapixel Camera, Nova 16z Tags Along: Price, Specifications
  6. Computex 2026: AMD Unveils Ryzen 7 7700X3D, Radeon RX 9070 GRE; Extends AM5 Support to 2029
  7. Itel Aqua Launched in India With IP67 Rating, 1,200mAh Battery: Price, Features
  8. Vivo X Fold 6 Launch Timeline Leaked; Tipped to Arrive With MediaTek Dimensity 9500 Chip
  9. HP OmniBook Ultra 16 (2026), OmniBook X 14 (2026) Unveiled With Nvidia's RTX Spark 'Superchip'
  10. Acer Swift Air 14 Launched With Intel Core Series 3 CPU, Lightweight Design at Computex 2026
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.