🛡️ Cybersecurity / /via Bloomberg / updated 10h ago

Ransomware Group Claims Breach of 4.2 Million Apple iCloud Accounts

A ransomware group posted 4.2 million alleged Apple iCloud records on July 20 2026. Apple confirmed the data came from a third-party developer portal not its core systems. The incident affects users who enabled advanced data protection before June 2026.

#Apple
~/ Cybersecurity/ Ransomware Group Claims Breach of 4.2 Million A...

A group calling itself ShadowLock published 4.2 million Apple iCloud records on July 20 2026 demanding 50 million dollars in Bitcoin. Apple stated the data originated from a compromised third-party developer portal used for legacy iCloud API testing. No customer passwords or full encryption keys were exposed.

The leaked records include email addresses device identifiers and partial metadata from photos and notes. Apple disabled the affected portal within 90 minutes of detection on July 17. The company notified affected users via email on July 19.

Apple has faced increasing scrutiny over iCloud security after the 2025 FBI data request controversy. The company rolled out end-to-end encryption for iCloud Backup in December 2025. ShadowLock claims it will release decryption tools if the ransom is unpaid by July 27.

Security researchers verified sample records match real iCloud metadata formats. Apple offered two years of free identity monitoring to impacted accounts.

Why this matters

The breach highlights supply-chain risks even for companies with strong internal security. Third-party developer tools remain a persistent weak point across the industry.

Regulators in the EU and California are expected to open investigations within weeks. Apple may accelerate its timeline for default end-to-end encryption across all iCloud services.

Enterprises using Apple Business Manager are reviewing their own third-party integrations. Similar attacks on other cloud providers are considered likely in coming months.

share
𝕏 FB
← cd ../news