惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
G
Google Developers Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
腾讯CDC
有赞技术团队
有赞技术团队
Vercel News
Vercel News
MongoDB | Blog
MongoDB | Blog
M
MIT News - Artificial intelligence
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
B
Blog RSS Feed
I
InfoQ
Blog — PlanetScale
Blog — PlanetScale
博客园_首页
The Cloudflare Blog
B
Blog
C
Check Point Blog
Stack Overflow Blog
Stack Overflow Blog
IT之家
IT之家
U
Unit 42
D
Docker
月光博客
月光博客
aimingoo的专栏
aimingoo的专栏
博客园 - Franky
A
About on SuperTechFans

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner
Apple Blocks Over 2 Million Apps in 2025 Fraud Crackdown
Pierluigi Pa · 2026-05-22 · via Security Affairs

Apple 2025 fraud report shows major App Store protections: over 2M apps rejected, 1B fake accounts blocked, and billions in fraud prevented.

Apple ‘s annual fraud prevention report for 2025 paints a striking picture of just how much effort goes into keeping the App Store clean. The numbers are significant: more than two million app submissions rejected, over a billion fake account creations stopped, and billions of dollars in fraudulent transactions prevented. Behind all of it sits a combination of artificial intelligence and human review that Apple has been quietly refining for years.

The scale of the problem is easy to underestimate. Every week, more than 850 million people visit the App Store across 175 storefronts worldwide. That kind of traffic attracts bad actors constantly, developers trying to slip malicious or deceptive apps through the review process, fraudsters creating fake accounts to manipulate charts and reviews, and criminals using stolen payment credentials to push through unauthorized purchases.

In 2025 alone, Apple’s systems processed over 9.1 million app submissions. Of those, more than 1.2 million new apps and roughly 800,000 updates were rejected before reaching users. The reasons ranged from bait-and-switch tactics and hidden features to cloned apps, spam submissions, and outright policy violations. AI has become central to catching these patterns faster and at a scale no human team could manage alone.

“In 2025, Apple’s Trust and Safety teams stopped multiple large-scale attempts to create fraudulent accounts. Last year, Apple’s systems also successfully rejected 1.1 billion fraudulent customer account creations — blocking bad actors at the outset — and deactivated an additional 40.4 million customer accounts for fraud and abuse.” reads the report published by the company. ” In 2025, Apple terminated 193,000 developer accounts over fraud concerns and rejected more than 138,000 developer enrollments.”

On the developer side, the company terminated 193,000 accounts over fraud concerns and rejected more than 138,000 enrollment attempts from bad actors trying to enter the ecosystem in the first place.

The financial dimension is equally notable. Apple says it prevented more than $2.2 billion in potentially fraudulent transactions in 2025. Over the past six years, that cumulative figure has crossed $11 billion.

“Apple prevented more than $2.2 billion in fraudulent transactions, stopped more than 5.4 million stolen credit cards from being used to make fraudulent purchases, and banned nearly 2 million user accounts from transacting again.” continues the report.

Beyond account and payment fraud, Apple is also fighting a less visible battle against pirate app distribution. In 2025, the company detected and blocked 28,000 illegitimate apps on unauthorized storefronts distributing malware, pirated software, and other harmful content. It also blocked 2.9 million attempts in a single month alone to install or launch apps distributed outside the App Store or approved alternative marketplaces.

Of the 1.3 billion ratings and reviews submitted last year, nearly 195 million were flagged and removed as fraudulent, fake reviews designed to artificially boost or bury apps.

What makes this report worth reading is not just the numbers. It is the reminder that app marketplaces are not neutral platforms. They require constant, active enforcement to remain trustworthy. The combination of machine learning and human expertise Apple describes is not a new idea, but the scale at which it now operates is genuinely impressive. Every rejected app or blocked account represents a threat that never reached an end user — and that, more than any headline figure, is the real measure of the system working.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, App Store)