In September 2014, Apple said its investigation into stolen celebrity photographs found targeted attacks on account credentials and security questions—not a breach of Apple’s systems in the cases it examined. The FBI said it was addressing allegations of computer intrusions and unlawful release, but that statement was not a final technical finding. Later prosecutions established that one man used phishing to access accounts; they did not establish who published the images.
What happened in the September 2014 celebrity photo theft?
Private photographs of high-profile individuals were stolen and released publicly, prompting the question captured in the headline: had an iCloud flaw exposed the images, or had attackers compromised individual accounts? The word “hack” described the incident broadly; it does not, by itself, prove that a single system vulnerability or exploit was responsible.
What did Apple’s investigation conclude?
Apple said it had investigated the cases and found targeted attacks on account credentials and security questions. It said its investigation found no breach of Apple systems in those cases. That conclusion is limited to the cases Apple examined; it is not evidence that every account or system was beyond risk. Apple’s September 2014 statement.
What did the FBI say?
The FBI said it was addressing allegations of computer intrusions and the unlawful release of material involving high-profile individuals. That was a statement about the allegations being addressed, not a final technical finding identifying a vulnerability, the full method of access, or the person who released the images. FBI statement on the unauthorized release of personal photos.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
What did the later phishing case establish?
In a later Department of Justice case, Ryan Collins pleaded guilty to using phishing to obtain credentials and access accounts. He was sentenced to 18 months. The DOJ said investigators found no evidence that Collins posted or shared the leaked images. The case therefore establishes account access by phishing, not that Collins was the person who published the photographs or that his case explained every intrusion involved in the 2014 incident. Department of Justice account of Collins’s sentencing.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What security advice did Apple give in 2014?
Apple advised users to use strong passwords and enable two-step verification. This was advice given in the context of Apple’s 2014 response; it should not be read as a complete or current security checklist. Apple’s September 2014 statement.
Quick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




