{"id":19232,"date":"2022-06-02T08:30:19","date_gmt":"2022-06-02T16:30:19","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/06\/02\/news-12965\/"},"modified":"2022-06-02T08:30:19","modified_gmt":"2022-06-02T16:30:19","slug":"news-12965","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/06\/02\/news-12965\/","title":{"rendered":"Apple confirms the scale of App Store fraud"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/idge\/imported\/imageapi\/2022\/05\/16\/11\/cso_nw_cloud_security_threats_theft_breach_fraud_phishing_by_youngid_gettyimages-468701250-100813539-large.3x2-100928023-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Thu, 02 Jun 2022 08:30:00 -0700<\/strong><\/p>\n<p>Apple says millions of fraudulent attempts are made against the App Store and its users each year. The company prevented $1.5 billion in fraudulent transactions in 2021, it said, in line with <a href=\"https:\/\/www.applemust.com\/12-apple-statistics-about-app-store-fraud-in-2020\/\" rel=\"nofollow noopener\" target=\"_blank\">similar levels<\/a> of fraud in 2020.<\/p>\n<p>The company <a href=\"https:\/\/www.apple.com\/newsroom\/2022\/06\/app-store-stopped-nearly-one-point-five-billion-in-fraudulent-transactions-in-2021\/\" rel=\"nofollow noopener\" target=\"_blank\">explains<\/a> how fraudsters attempt to commit fraud via the store.<\/p>\n<p>These attempts span the gamut from relatively unsophisticated attempts to make purchases using stolen or fraudulent credit cards to more complex scams consisting of apps that otherwise work fine but quietly gather data or carry malware to trick or defraud users.<\/p>\n<p>Attempts to smuggle malware into apps to perform on-device fraud are intensifying in 2022. It is worth noting that there has been an <a href=\"https:\/\/threatfabric.com\/blogs\/h1-2022-mobile-threat-landscape.html\" rel=\"nofollow noopener\" target=\"_blank\">increase of over 40%<\/a> in malware\u00a0 attempts against Android to perform on-device fraud so far this year, which shows that Apple&#8217;s concern is justified.<\/p>\n<p>Apple has rejected tens of thousands of apps, including apps with hidden code and misleading, copycat, and privacy abusing apps. Millions of attempts to create fraudulent customer or developer accounts are made each year, the company said, while 3.3 million stolen credit cards have seen attempted use.<\/p>\n<p>Review fraud \u2014 in which competitors file illegitimate ratings and reviews to suppress sales of competing apps or to encourage users to download untrustworthy apps \u2014 also gets a mention.<\/p>\n<p>Apple says over a billion ratings and reviews were made across 2021, and Apple had to detect and block over 94 million reviews and 170 million ratings for \u201cfailing to meet moderation standards.\u201d Apple also ditched 610,000 reviews after publication following complaints and subsequent evaluation.<\/p>\n<p>That data suggests the scale of review fraud is relatively high, as it hints that a very large percentage of the billion ratings and reviews made each year are at fault.<\/p>\n<p>App Store developers have complained about this practice for years, and the data Apple has released justifies that concern. Having said that, this also suggests the risks of review fraud would be far, far higher if the App Store were left unmoderated.<\/p>\n<p>We know that part of the reason the company is sharing this information is to justify the fees it levies against some developers for selling apps via its store. Apple continues to pull together data to support the way it runs the App Store business, and fraud detection at the level Apple explains does not come cheap. While other app stores may levy lower fees, do they offer the same security or user experience? What happens in the event Apple cannot?<\/p>\n<p>Apple really wants regulators to think again on plans to force sideloading of apps and other <a href=\"https:\/\/www.computerworld.com\/article\/3631529\/developers-regulators-say-apples-app-store-changes-dont-do-enough.html\">poorly thought out proposals<\/a> that would serve to dilute the security and safety of its platforms. In that context, the company likely seeks data to show the extent to which its products are today used across highly confidential and <a href=\"https:\/\/www.computerworld.com\/article\/3662131\/why-industry-40-must-think-more-like-apple.html\">strategically essential industries<\/a>.<\/p>\n<p>What use are <a href=\"https:\/\/www.computerworld.com\/article\/3658552\/jamf-adds-network-and-endpoint-security-tools-for-enterprise-macs.html\">network and endpoint protection systems<\/a> when the platforms themselves are made inherently insecure? How can any enterprise remain confident in their increasingly digital processes in the event their devices carry government-mandated backdoors?<\/p>\n<p>These important questions need to be rigorously answered before any decisions are made.<\/p>\n<p>That the App Store experiences fraudulent activity at the level it has described should give regulators pause for thought before <a href=\"https:\/\/www.computerworld.com\/article\/3660491\/europe-puts-apples-csam-plans-back-in-the-spotlight.html\">imposing rash remediation<\/a>, particularly as criminals become increasingly creative in apps, app services, and the growing potential for <a href=\"https:\/\/www.justice.gov\/usao-sdca\/pr\/brazilian-national-pleads-guilty-nationwide-fraud-exploited-app-based-food-delivery\" rel=\"nofollow noopener\" target=\"_blank\">ID fraud<\/a>.<\/p>\n<p>Fraudsters are also targeting older mobile devices, according to a <a href=\"https:\/\/www.nice.com\/press-releases\/nice-actimize-releases-2022-fraud-insights-report\" rel=\"nofollow noopener\" target=\"_blank\">NICE Actimize<\/a> study. That study found banking fraud attempts increased by 41% in 2021, with devices running operating systems made prior to 2016 three times more likely to be victims of fraud.<\/p>\n<p><a href=\"https:\/\/gs.statcounter.com\/android-version-market-share\/mobile-tablet\/worldwide\" rel=\"nofollow noopener\" target=\"_blank\">Approximately 4%<\/a> of 2.5 billion currently active Android devices run at-risk iterations of that OS, in comparison with <a href=\"https:\/\/developer.apple.com\/support\/app-store\/\" rel=\"nofollow\">just 2%<\/a> of iPhone users who run an OS over two years old. (The number of iPhones running 2016 versions of iOS is incalculably small).<\/p>\n<p>However, any move to dilute the security iOS enjoys could make many more of us vulnerable, and the <a href=\"https:\/\/www.computerworld.com\/article\/3622416\/apple-sideloading-apps-will-undermine-ios-security.html\">introduction of a non-curated app store would do just that<\/a>.<\/p>\n<p>Apple\u2019s decision to publish information concerning its work to battle App Store fraud just days before it hosts its annual developer event sends a message that the company will continue working toward its goals around privacy and security across its mobile ecosystem. Most recently the company announced that it will <a href=\"https:\/\/www.computerworld.com\/article\/3659800\/why-apple-needs-to-evict-old-and-unsupported-app-store-apps.html\">evict older apps<\/a> that have not been updated for three or more years from the App Store.<\/p>\n<p>Given the scale to which App Store fraud is taking place, this seems a sensible move to help protect users against inadvertent use of apps that may still contain exploits or vulnerable code.<\/p>\n<p><em>Please follow me on\u00a0<a href=\"https:\/\/twitter.com\/jonnyevans_cw\" rel=\"nofollow noopener\" target=\"_blank\">Twitter<\/a>, or join me in the\u00a0<a href=\"https:\/\/mewe.com\/join\/appleholics_bar_and_grill\" rel=\"nofollow noopener\" target=\"_blank\">AppleHolic\u2019s bar &amp; grill<\/a>\u00a0and\u00a0<a href=\"https:\/\/mewe.com\/join\/apple_discussions\" rel=\"nofollow noopener\" target=\"_blank\">Apple Discussions<\/a>\u00a0groups on MeWe.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3663009\/apple-confirms-the-scale-of-app-store-fraud.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/idge\/imported\/imageapi\/2022\/05\/16\/11\/cso_nw_cloud_security_threats_theft_breach_fraud_phishing_by_youngid_gettyimages-468701250-100813539-large.3x2-100928023-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Thu, 02 Jun 2022 08:30:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>Apple says millions of fraudulent attempts are made against the App Store and its users each year. The company prevented $1.5 billion in fraudulent transactions in 2021, it said, in line with <a href=\"https:\/\/www.applemust.com\/12-apple-statistics-about-app-store-fraud-in-2020\/\" rel=\"nofollow noopener\" target=\"_blank\">similar levels<\/a> of fraud in 2020.<\/p>\n<h2>How people attempt to commit App Store fraud<\/h2>\n<p>The company <a href=\"https:\/\/www.apple.com\/newsroom\/2022\/06\/app-store-stopped-nearly-one-point-five-billion-in-fraudulent-transactions-in-2021\/\" rel=\"nofollow noopener\" target=\"_blank\">explains<\/a> how fraudsters attempt to commit fraud via the store.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3663009\/apple-confirms-the-scale-of-app-store-fraud.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[2211,10554,11066,714,24580],"class_list":["post-19232","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-apple","tag-mobile","tag-mobile-apps","tag-security","tag-small-and-medium-business"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19232","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19232"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19232\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19232"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19232"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19232"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}