iCloud hacker stole intimate photos from hundreds of Apple customers

scammers
(Image credit: Shutterstock / Brazhyk)

A man has admitted to breaking into the accounts of Apple iCloud users in order to steal intimate images and videos, court filings show. 

Hao Kuo Chi, who lives in California, was found to have conspired with others to unlawfully access the cloud storage accounts of more than three hundreds Apple customers across the US. This campaign extended at least as far back as September 2014.

As noted in a document from the US Department of Justice, once inside, Chi “specifically sought out nude photographs and videos of young women”. These assets were then traded with “conspirators”, some of whom later leaked the content into the public domain.

Although Chi has not yet been sentenced, the joint penalties for conspiracy and computer fraud carry a maximum of 20 years in federal prison. As part of the plea agreement, he has agreed to testify against others involved in the scheme, which may or may not result in a more lenient sentence.

iCloud security

Under the online pseudonym “icloudripper4you”, Chi boasted frequently of his ability to break into iCloud accounts and exfiltrate the images and videos stored therein.

To gain access to iCloud accounts, Chi masqueraded as a member of the Apple customer support team using a series of fake email accounts. Although the court documentation does not specify, victims were presumably encouraged to hand over their login credentials under false pretences.

The documentation also makes reference to instances in which conspirators themselves provided Chi with the Apple IDs and passwords of victims.

Although Chi sold the stolen content to others online, he also maintained a 1TB cloud storage subscription to house a large bank of nude images and footage for his personal collection. In total, this collection is said to have comprised hundreds of thousands of items.

While Chi’s scheme ultimately affected only a tiny fraction of Apple iCloud customers, of which there are thought to be roughly one billion, the duration and sexually-motivated nature of the crime will be cause for concern for many.

TechRadar Pro asked Apple for comment on the steps users can take to shield their iCloud accounts from campaigns of this kind, but did not receive an immediate response.

Update:
Apple has since provided a link to a support page designed to help customers recognize phishing messages and other scams.

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
US soldier pleads guilty to AT&T and Verizon cyberattacks, linked to Snowflake data theft
A hand holding an iPhone with the iCloud logo on screen.
US lawmakers want Trump to call out UK Apple iCloud encryption backdoor demand
Microsoft
Microsoft names cybercriminals who created explicit deepfakes
China
Chinese hackers who targeted key US infrastructure charged by Justice Department
A hand holding an iPhone with the iCloud logo on screen.
UK's Apple iCloud backdoor "jeopardizes the security and privacy of millions," warn experts
Kaspersky Report on Stalkerware
Security flaw in popular stalkerware apps is exposing phone data of millions
Latest in Pro
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
European Union technical background
EU tech companies push for digital sovereignty, reducing reliance on US and others
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
Adobe Summit 2025
Adobe Summit 2025 - all the news and updates as it happens
Latest in News
Panos Panay and Alexa Plus
Amazon's Panos Panay teases future Alexa+ devices from speakers to possible wearables
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Samsung Galaxy Z Fold 6
New rumors predict a foldable iPhone will launch next year – and cost almost twice as much as the iPhone 16 Pro Max
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments