Apple 'Actively Investigating' Possible Hacking of Celebrity iCloud Accounts - MacRumors
Skip to Content

Apple 'Actively Investigating' Possible Hacking of Celebrity iCloud Accounts

icloud_icon_blueApple is investigating an alleged breach of several celebrity iCloud accounts that may have allowed hackers to access the private photos and videos of multiple well-known actresses, according to a statement an Apple spokesperson gave to Re/code.

Apple said it was "actively investigating" the violation of several of its iCloud accounts, in which revealing photos and videos of prominent Hollywood actresses were taken and posted all over the Web.

"We take user privacy very seriously and are actively investigating this report," said Apple spokeswoman Natalie Kerris.

Over the weekend, hundreds of nude photos of celebrities were leaked on 4chan before spreading to multiple Internet sites, with one of the involved hackers pointing towards iCloud as the source of the material.

Security researchers have postulated that weak passwords and a lack of two-factor authentication may have led to the breach if iCloud is the source of the leaked images, and it's also possible that a Python script shared on Github a few days ago may have allowed hackers to exploit a vulnerability in Find My iPhone.

As described by The Next Web, the tool allowed hackers to repeatedly guess passwords without being locked out of an iCloud/Apple ID account, brute forcing their way into accounts. Though it is unclear if the tool was responsible for any hacked celebrity accounts, Apple did fix the vulnerability earlier today. Attempting to use the tool now locks an Apple ID after five attempts to guess a password.

Multiple security researchers have suggested that any iCloud attacks may have been preventable with two-factor authentication, which Apple first introduced in March of 2013. The two-step verification system adds an additional layer of protection for Apple accounts, requiring both a security code and a "trusted" device to log into an account, in addition to a password.

Popular Stories

iOS 26

iOS 26.4 Adds Two New Features to CarPlay

Tuesday March 24, 2026 1:55 pm PDT by
iOS 26.4 was released today, and it includes a couple of new features for CarPlay: an Ambient Music widget and support for voice-based chatbot apps. To update your iPhone 11 or newer to iOS 26.4, open the Settings app and tap on General → Software Update. CarPlay will automatically offer the new features so long as the iPhone connected to your vehicle is running iOS 26.4 or later....
Apple Business hero

Apple Unveils 'Apple Business' All-in-One Platform

Tuesday March 24, 2026 8:53 am PDT by
Apple today announced Apple Business, a new all-in-one platform that unifies device management, productivity tools, and customer outreach features. The service is designed to be a consolidated replacement for several of Apple's existing business-focused offerings, including Apple Business Essentials, Apple Business Manager, and Apple Business Connect. It provides organizations with a single...
AirPods Pro Firmware Feature

Apple Releases New Firmware for AirPods Pro 3, AirPods Pro 2 and AirPods 4

Tuesday March 24, 2026 12:31 pm PDT by
Apple today released new firmware for the AirPods Pro 2, AirPods Pro 3, and the AirPods 4. The firmware has a version number of 8B39, up from 8B34 on the AirPods Pro 3, 8B28 on the AirPods Pro 2, and 8B21 on the AirPods 4. There is no word on what's included in the firmware, but Apple has a support document with limited notes. Most updates are limited to bug fixes and performance...

Top Rated Comments

151 months ago
Earlier today in Cupertino:

Tim – Phil, we can’t say a word about iCloud next week. Jennifer Lawrence is going to go hunger games on our a$$$$es. What do we do?

Phil – Talk bad about Android fragmentation as we always do!

Tim – You’re right! Android distribution numbers are always a classless punchline during our keynotes.

Phil – Lets have Craig do it. We can throw in a joke about his hair.

Tim – Just make sure you don’t use iCloud when saving the keynote. We don’t want the public to know our plans. Oh wait, that’s how the iPhone 6 parts got leaked on the internet.
Score: 58 Votes (Like | Disagree)
impulse462 Avatar
151 months ago
I love some people were so mad about the NSA violating privacy, but are praising some random guy who pretty much did exactly what the NSA does.

Anyway, I feel bad for the celebs, but typical 4chan.
Score: 34 Votes (Like | Disagree)
Xenc Avatar
151 months ago
That's a pretty big vulnerability they left open. I wonder if Apple will now force people to use 2 step authentication. As annoying as it is, it works.

I'm uncomfortable with dancing to login.
Score: 25 Votes (Like | Disagree)
Mr.Skynet Avatar
151 months ago
The internet is referring to the incident as "The Fappening". Be sure to tell your grandkids.. You were there.
Score: 23 Votes (Like | Disagree)
SgtPepper12 Avatar
151 months ago
It's still not clear if iCloud was the only source, but it certainly looks like at least a portion of the photos were obtained that way.
Maybe if these celebs weren't so careless (and clueless) this wouldn't happen.

I'm sure some of them will be happy they get some mention in the news nowadays.
I don't get why people are defending Apple on this one. You sound like you work for Apple's PR. At this point it is absolutely obvious that it's Apple's fault. They left their platform wide open for attacks like that.
Score: 21 Votes (Like | Disagree)
151 months ago
Earlier today in Cupertino:

Tim – Phil, we can’t say a word about iCloud next week. Jennifer Lawrence is going to go hunger games on our a$$$$es. What do we do?

Phil – Talk bad about Android fragmentation as we always do!

Tim – You’re right! Android distributions numbers are always a classless punchline during our keynotes.

Phil – Lets have Craig do it. We can throw in a joke about his hair.

Tim – Just make sure you don’t use iCloud when saving the keynote. We don’t want the public to know our plans. Oh wait, that’s how the iPhone 6 parts got leaked on the internet.

Took you long enough to post MacRumors. This has been reported by over 50% of the tech websites hours ago.
I guess unconfirmed Apple news from unconfirmed sources are more important to post before something that actually happened.

I think you just want to criticize Apple and/or Macrumors. Kind of a waste of time if you ask me, but hey don't let me tell you what to do.
Score: 21 Votes (Like | Disagree)