What happened
The 2014 mass leak of private celebrity photographs, widely reported as an iCloud hack, was in fact a credential phishing campaign. Ryan Collins of Lancaster, Pennsylvania sent emails that appeared to come from Apple or Google asking recipients for their usernames and passwords, then used the harvested credentials to access more than 100 accounts including at least 50 iCloud and 72 Gmail accounts. Investigators identified over 600 victims. Collins was sentenced on 26 October 2016 to 18 months in federal prison.
How the deception worked
Collins sent messages that mimicked Apple and Google account security notices, using the vendors' visual conventions and a plausible security pretext to make responding feel like protecting the account rather than surrendering it. Victims replied with, or entered, their account usernames and passwords. Collins then signed in directly and downloaded the full contents of iCloud backups, which on Apple devices at that time included the entire camera roll and message history. No platform vulnerability was exploited; the whole compromise rested on the victim voluntarily supplying credentials to a convincing imitation of the provider.
AI involvement · No AI reported
No AI involvement.
The control that would have caught it· our reading, not a claim from the sources
Mandatory two-factor authentication on consumer cloud backup accounts, and provider policies that never request passwords by email, would have neutralised the harvested credentials.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.