Hackers Using Law Enforcement Tools to Access iCloud Backups Unprotected by Two-Factor Authentication

icloud_icon_blueEarlier today, Apple issued a press release stating that an iCloud/Find My iPhone breach had not been responsible for the leak of several private celebrity photos over the weekend, instead pointing towards a "very targeted attack on user names, passwords, and security questions" hackers used to gain access to celebrity accounts.

The company did not divulge specific details on how hackers accessed the iCloud accounts, leading Wired writer Andy Greenberg to investigate the methods that hackers might possibly have used to acquire the stolen media.

Greenberg visited Anon-IB, a popular anonymous image board where some of the celebrity photos first originated, and discovered that hackers openly discuss exploiting software designed for law enforcement and government officials. Called ElcomSoft Phone Password Breaker (EPPB), the software in question lets hackers enter a stolen username and password to obtain a victim's full iPhone/iPad backup.

"Use the script to hack her passwd...use eppb to download the backup," wrote one anonymous user on Anon-IB explaining the process to a less-experienced hacker. "Post your wins here ;-)"

Acquiring just a user name and password allows hackers access to content on iCloud.com, but with the accompaniment of the ElcomSoft software, a complete backup can reportedly be downloaded into easy-to-access folders filled with the device's contents.

According to security researcher Jonathan Zdziarski, who spoke to Wired, metadata from some of the leaked photos is in line with the use of the ElcomSoft software and possibly the iBrute software, which exploited a vulnerability in Find My iPhone to allow hackers unlimited attempts to guess a password. Apple has, however, patched the exploit, and has suggested iBrute was not a factor in the attacks.

As noted by TechCrunch, using ElcomSoft's software to download an iPhone's backup successfully circumvents two-factor verification as the two-factor authentication system does not cover iCloud backups or Photo Stream.

Two-factor verification can make it much more difficult for hackers to acquire a user's login credentials in the first place, preventing many attacks, but an iCloud backup can be installed with just a user name and a password.

twostepverification
The ElcomSoft software does not require any credentials to buy and while it costs $399, it is also available on bittorrent sites. The vulnerability in iCloud backups has been known for some time, with ElcomSoft's own CEO pointing towards the lack of two-factor authentication for iCloud backups back in May of 2013.

Apple has explored expanding two-factor authentication to some iCloud services, but an official expansion of the security feature has not yet been introduced.

Popular Stories

iPhone 17 Pro Render Front Page Tech

iPhone 17 Pro Launching Later This Year With These 8 New Features

Tuesday March 4, 2025 3:15 pm PST by
While the iPhone 17 Pro and iPhone 17 Pro Max are not expected to launch until September, there are already plenty of rumors about the devices. iPhone 17 Pro's alleged design via Front Page Tech Below, we recap key changes rumored for the iPhone 17 Pro models as of March 2025: Aluminum frame: iPhone 17 Pro models are rumored to have an aluminum frame, whereas the iPhone 15 Pro and iPhone...
Apple MacBook Air hero

Apple Announces New MacBook Air With M4 and 'Sky Blue' Color Option

Wednesday March 5, 2025 6:02 am PST by
Apple today announced refreshed 13- and 15-inch MacBook Air models, now featuring the M4 chip, an upgraded camera, and a new "Sky Blue" color option. "Sky Blue" is an all-new blue finish that joins Midnight, Starlight, and Silver. Apple describes it as a "beautiful, metallic light blue that creates a dynamic gradient when light reflects off of its surface." Space Gray is no longer available. ...
ipad 11 feature

Apple Unveils 11th-Gen iPad With A16 Chip and More Storage

Tuesday March 4, 2025 6:06 am PST by
Apple today announced the 11th-generation iPad, now featuring the A16 chip and more storage. The announcement came alongside the debut of the new iPad Air, which now features the M3 chip. From Apple's press release: The A16 chip provides a jump in performance for everyday tasks and experiences in iPadOS, while still providing all-day battery life. Compared to the previous generation, the...
M3 iPad Air

Apple Announces New iPad Air With M3 Chip, Updated Magic Keyboard

Tuesday March 4, 2025 6:04 am PST by
Apple today introduced new 11-inch and 13-inch iPad Air models with the M3 chip, along with an updated Magic Keyboard for the device. With the M3 chip, the new iPad Air should offer up to 20% faster performance compared to the previous-generation model with the M2 chip, which was released in May 2024. In addition, the M3 chip brings hardware-accelerated ray tracing to the iPad Air for the...
CarPlay Hero

iOS 18.4 Upgrades CarPlay in Two Ways

Tuesday March 4, 2025 8:39 am PST by
The upcoming iOS 18.4 update for the iPhone includes two smaller but meaningful improvements for Apple's in-car iPhone mirroring system CarPlay. First, CarPlay now shows a third row of icons, up from two rows previously. However, this change is only visible in vehicles with a larger center display. For example, a MacRumors Forums member noticed the change in a Toyota Tundra with a 14-inch...
Apple MacBook Air hero

Apple Has Finally Solved One of the MacBook Air's Biggest Limitations

Wednesday March 5, 2025 11:29 am PST by
The new MacBook Air has a useful upgrade: it natively supports up to two external displays, in addition to the laptop's built-in display. In other words, the latest MacBook Air can be used with a pair of external displays without needing to keep the laptop's lid closed. Apple's tech specs for the new 13-inch and 15-inch MacBook Air:Simultaneously supports full native resolution on the...
Mac Studio 2025

Apple Announces New Mac Studio With M4 Max and M3 Ultra Chips, Thunderbolt 5, and More

Wednesday March 5, 2025 6:01 am PST by
Apple today announced that it has updated the Mac Studio with M4 Max and M3 Ultra chip options, Thunderbolt 5 ports, and more. The M4 Max chip was already released last year in the 14-inch and 16-inch MacBook Pro. It can be configured with up to a 16-core CPU, up to a 40-core GPU, and up to 128GB of unified RAM. Geekbench 6 benchmark results indicate that the M4 Max is up to 75% faster than...
Apple MacBook Air hero

Here Are Real-World Photos of the New Sky Blue MacBook Air

Wednesday March 5, 2025 1:47 pm PST by
Apple today updated the MacBook Air with the M4 chip, and the laptop is also available in an all-new Sky Blue finish alongside Silver, Starlight, and Midnight. YouTuber Andru Edwards has showed off the Sky Blue color in a few real-world photos. Keep in mind that the Sky Blue finish is not very saturated. However, the color's appearance will vary based on lighting conditions. View ...
ipad air magic keyboard

Apple Announces Redesigned Magic Keyboard for iPad Air

Tuesday March 4, 2025 6:36 am PST by
Apple today announced a completely redesigned Magic Keyboard accessory for the iPad Air. The new keyboard features a larger built-in trackpad, a 14-key function row, and a new aluminum hinge. From Apple's press release: The all-new Magic Keyboard for iPad Air expands what users can do at an even lower price. The larger built-in trackpad brings greater precision for detail-oriented...

Top Rated Comments

krashx7 Avatar
137 months ago
The Fappening 2014. Never forget
Score: 25 Votes (Like | Disagree)
Santabean2000 Avatar
137 months ago
It seems there are no end if tricks available to the scumbags out there willing to do hurtful things.

However, bottom line (pun intended) is, if you want nude snaps of yourself, fine, take some, but don't keep them on your phone or in the cloud where they are most vulnerable.

While I have some sympathy for the victims, I also believe ignorance is not really an excuse these days.

People have to accept more responsibility for their actions, even if the consequences are far beyond what they initially imagined. The sad fact is in our cottonwool society is far easier to blame everyone else for everything than accept some responsibility personally. If you don't agree then you're part of the problem.
Score: 17 Votes (Like | Disagree)
mozumder Avatar
137 months ago
The ripping process, which has been going on for months:




Lots of security holes here, including weak password reset verification questions.
Score: 17 Votes (Like | Disagree)
apolloa Avatar
137 months ago
I think you need to change the headline for this article, so you are not claiming that someones opinion is fact.

Hackers Using Law Enforcement Tools to Access iCloud Backups Unprotected by Two-Factor Authentication

Should be changed to:

Hackers May Be Using Law Enforcement Tools to Access iCloud Backups Unprotected by Two-Factor Authentication
Score: 16 Votes (Like | Disagree)
jdawgnoonan Avatar
137 months ago
If, and that obviously is an IF, that is what happened then Apple should not claim that the images were not stolen due to weaknesses in their security. In fact, this is an even bigger potential hole in their security in my opinion. And to those who want to make it the victims fault that these photos were stolen: You are messed up in the head.
Score: 14 Votes (Like | Disagree)
swingerofbirch Avatar
137 months ago
Interesting timing with Apple about to come out with a mobile payments system.
Score: 14 Votes (Like | Disagree)