Security Researcher Allegedly Exploited Internal Apple Tool to Steal Millions

A security researcher who reported bugs to Apple was arrested in January for defrauding the company out of millions of dollars, according to a report from 404 Media.

The researcher, Noah Roskin-Frazee, was accused alongside a co-conspirator obtaining over $3 million in products and services through more than two dozen fraudulent orders. That included around $2.5 million in gift cards and over $100,000 in “products and services.”

While Apple is not explicitly named in the court records, an unnamed “Company A” is located in Cupertino, California, and is clearly Apple. The court mentions that one of the perpetrators used gift cards to “purchase Final Cut Pro on Company A’s App Store,” and Apple is the only company that sells the software.

In 2019, Frazee and his accomplice used a password reset tool to gain access to an employee account that belonged to an unnamed “Company B,” which does customer support for Apple. That account led to access to additional employee credentials, and Frazee accessed Company B’s VPN servers. From there, Frazee was able to get into Apple’s systems, placing fraudulent orders for Apple products.

He used Apple’s “Toolbox” program that could be used to edit orders after they were placed, and he changed order values to zero, added products to orders, and extended AppleCare contracts. He abused Apple’s program from January to March 2019.

The defendants remoted into computers located in India and Costa Rica as part of the scheme, the indictment adds. The scam itself involved changing order monetary values to zero, adding products to existing orders without cost such as phones and laptops, and extending existing service contracts, the indictment adds. That included extending a customer service contract that was associated with one of the defendants and his family for an extra two years without paying.

Apple thanked Frazee for in a January support document for finding several bugs in macOS Sonoma, and the document was published less than two weeks after he was arrested. “We would like to acknowledge Noah Roskin-Frazee and Prof. J. (ZeroClicks.ai Lab) for their assistance,” reads Apple’s page in reference to a Wi-Fi vulnerability.

Frazee has been charged with wire fraud, mail fraud, conspiracy to commit wire fraud and mail fraud, conspiracy to commit computer fraud and abuse, and intentional damage to a protected computer. He will be required to forfeit all of the stolen goods, and he could be sentenced to more than 20 years in jail if convicted.
This article, “Security Researcher Allegedly Exploited Internal Apple Tool to Steal Millions” first appeared on MacRumors.com

Discuss this article in our forums

Related posts

Latest posts

Google Gemini among the top three AI services, with 350 million monthly users

Despite significant growth, it appears Google's Gemini chatbot lags behind rivals like OpenAI's ChatGPT and Meta AI in terms of its monthly active user base.

Gemini AI is coming to cars, wearables, and more this year, Google confirms

It's officially confirmed - Gemini is coming to Android Auto, wearables, and more.

More iPhones could get a memory upgrade, but some will have to wait

Many iPhones are due for a memory upgrade, and it seems that more models will get the boost than expected.

Google Pixel 9a offers a significant battery gain over other Pixels

If you’re in the market for a Pixel phone and can’t decide between the Pixel 9 or Pixel 8a and the recently released Pixel 9a, we’ve got some news to consider. Android Authority discovered that Google’s newest budget model offers, in many cases, substantial battery gains compared to the older models. In recent tests, the […]

Samsung’s rumored trifold might not match the Huawei Mate XT in size

Huawei's Mate XT ushered in a new smartphone form factor, and it seems Samsung's rival might not quite match.

7 of our favorite iPhone colors since 2007

There have been several very colorful iPhones over the years. Here are some of our favorites.

New AMD laptop GPUs have leaked, and Nvidia might be in trouble

A new leak tells us that AMD might have a whole lot of laptop GPUs in store, and there's an interesting model hidden among the rest.

The Fitbit Versa 4 is back to its good price of just $150 for a very short time

This is the time to get the Fitbit Versa 4. If you don't get it now, you'll end up paying $50 more.

Amazon’s No. 1 New Release is the Kindle Colorsoft Signature Edition — And it’s 20% off

Get a Kindle Colorsoft Signature Edition at a reduced price for a limited time.

OPPO Find X8 Ultra vs. Samsung Galaxy S25 Ultra: It’s not even a contest

With the Find X8 Ultra, OPPO has one of the best overall packages of 2025. Thanks to outstanding cameras and