Technology
App Store scammers are making thousands of dollars by exploiting TouchID
Shady developers have found a new way to trick users into spending ridiculous sums of money on worthless services.
The scheme, which was discovered by Redditors and reported by the welivesecurity blog, uses TouchID to trick users into in-app purchases, which can be as high as $99.99.
The blog uncovered two such examples, both from purported fitness apps. In both cases, the apps instruct users to hold their finger over their iPhone’s home button in order to “scan” their fingerprint for health data. While the “scan” is happening, though, the app triggers an in-app purchase, which is then authenticated via TouchID and completed before the user even realizes what is happening.
Welivesecurity blog uncovered two examples of this tactic, one called “Calories Tracker app” and one called “Fitness Balance.” Both apps have since been removed by from the App Store by Apple, but you can see it in action in the video below. Apple didn’t immediately respond to a request for comment.
Shady though they are, it appears that these developers’ tactics were extraordinarily successful. “Calories Tracker app,” pulled in $60,000 in November while “Fitness Balance” made $10,000, according to data from app analytics firm Sensor Tower.
The incident also raises the questions about Apple’s ability to detect scams in the first place.
Though Apple’s App Store has a reputation for being safer than other app stores, this isn’t the first time shady developers have been allowed to get their apps into the store. Last year, a number of barely-functional apps were removed for tricking users into paying for exorbitantly-priced subscriptions.
One such app, which also took advantage of the App Store’s search ads, was charging $99.99 weekly for a worthless VPN service. The app was pulling in $80,000 a month before it was eventually removed.
!function(f,b,e,v,n,t,s){if(f.fbq)return;n=f.fbq=function(){n.callMethod?
n.callMethod.apply(n,arguments):n.queue.push(arguments)};if(!f._fbq)f._fbq=n;
n.push=n;n.loaded=!0;n.version=’2.0′;n.queue=[];t=b.createElement(e);t.async=!0;
t.src=v;s=b.getElementsByTagName(e)[0];s.parentNode.insertBefore(t,s)}(window,
document,’script’,’https://connect.facebook.net/en_US/fbevents.js’);
fbq(‘init’, ‘1453039084979896’);
if (window._geo == ‘GB’) {
fbq(‘init’, ‘322220058389212’);
}
if (window.mashKit) {
mashKit.gdpr.trackerFactory(function() {
fbq(‘track’, “PageView”);
}).render();
}
-
Entertainment7 days ago
Trump taps Musk for ‘Department of Government Efficiency’: What it is and what’s at risk.
-
Entertainment7 days ago
Trump appoints Elon Musk to DOGE, a new U.S. government department
-
Entertainment6 days ago
Greatest birthday gifts for men: Practical and posh presents that are sure to please
-
Entertainment5 days ago
‘Interior Chinatown’ review: A very ambitious, very meta police procedural spoof
-
Entertainment6 days ago
Stocking up on holiday gift cards? Watch out for this scam.
-
Entertainment5 days ago
6 gadgets to help keep your home clean, from robot vacuums to electric scrubbers
-
Entertainment4 days ago
Earth’s mini moon could be a chunk of the big moon, scientists say
-
Entertainment5 days ago
X users are fleeing to BlueSky: Here’s a quick-start guide on how to sign up