# Apple Blocks Record $11 Billion in App Store Fraud Over Six Years, with $2.2 Billion Stopped in 2025 Alone


Apple revealed this week that it has successfully blocked over $11 billion in fraudulent App Store transactions across the last six years, with fraud detection reaching unprecedented scale in 2025. The company's latest security report demonstrates both the sophistication of modern app-based fraud schemes and the increasingly aggressive measures required to defend against them—stopping more than $2.2 billion in potentially fraudulent transactions in 2025 alone, rejecting over 2 million problematic app submissions, and terminating 193,000 developer accounts suspected of fraud.


The disclosure underscores a critical reality facing the mobile app ecosystem: as legitimate commerce on iOS grows, so does the volume and complexity of fraudulent activity targeting Apple's 850 million weekly App Store visitors across 175 global storefronts.


## The Threat


App Store fraud encompasses multiple attack vectors, each with distinct financial and security consequences:


  • Stolen financial instruments: Criminals use compromised credit cards to make fraudulent purchases, often rapidly depleting card limits before victims detect the activity
  • Fake account creation: Coordinated attacks generating millions of fraudulent accounts to circumvent purchase limits and exploit free trial systems
  • Deceptive apps and scams: Applications designed to mislead users into unauthorized charges, subscriptions, or credential theft
  • Review manipulation: Fraudulent ratings and reviews designed to artificially boost app visibility and credibility
  • Counterfeit apps and piracy: Illegitimate clones and bootleg versions appearing on unauthorized storefronts

  • The financial impact extends beyond direct transaction fraud: compromised payment instruments damage consumer trust, increase merchant dispute rates, and force payment networks to absorb costs through fraud liability insurance and chargeback processing.


    ## Background and Context


    Apple's App Store, launched in 2008, pioneered centralized mobile app distribution. While this model provides inherent security advantages—curated submissions, staged rollout, ability to revoke apps post-release—it has also created a high-value target. Fraudsters have consistently adapted their tactics to exploit new payment methods, subscription systems, and user acquisition channels.


    The volume of fraud attempts has grown in tandem with iOS commerce. In 2024, Apple blocked over $2 billion in fraudulent transactions. The 10% increase to $2.2 billion in 2025 reflects both growing fraud sophistication and larger transaction volumes on the platform. More alarming is the 14% jump in rejected app submissions (from 7.7 million to 9.1 million), indicating fraudsters are submitting apps at accelerating rates.


    A particularly striking shift occurred in bait-and-switch tactics: Apple removed nearly 59,000 such apps in 2025—nearly three times the 17,000 removed in 2024. This suggests fraudsters have discovered bait-and-switch to be a reliable, profitable exploit of App Review processes.


    ## Technical Details: How Apple Detects and Prevents Fraud


    Apple employs a dual approach combining human review with machine learning systems:


    Human Review: Apple's App Review team manually evaluated over 9.1 million app submissions in 2025, examining code, user interface elements, and payment flows for suspicious patterns.


    Machine Learning & Pattern Detection: Apple leverages ML models to identify:

  • Stolen financial data by cross-referencing compromised credit cards against fraudster databases
  • Coordinated fraudulent accounts by analyzing device fingerprints, IP addresses, and transaction patterns across accounts
  • Deceptive app behavior through behavioral analysis of app permissions, network requests, and user interaction patterns
  • Review manipulation by detecting voting patterns inconsistent with organic user bases

  • Real-Time Blocking: Apple's infrastructure processes transactions at scale, allowing immediate intervention when ML models flag suspicious activity with high confidence.


    ### 2025 Fraud Prevention Metrics


    | Category | 2025 Volume | Change from 2024 |

    |----------|-------------|------------------|

    | Fraudulent transactions blocked | $2.2B | +10% |

    | App submissions rejected | 2M+ | +18% |

    | Fraudulent account creations blocked | 1.1B+ | -25% |

    | Developer accounts terminated | 193,000 | N/A |

    | Stolen credit cards stopped | 5.4M | +15% |

    | Customer accounts deactivated (fraud/abuse) | 40.4M | Significant increase |

    | Bait-and-switch apps removed | 59,000 | +247% |

    | Fraudulent ratings/reviews blocked | 195M+ | N/A |


    ## Implications for Developers and Users


    For Developers: These metrics highlight Apple's aggressive approach to maintaining App Store integrity. Legitimate developers face longer review times (9.1M submissions reviewed), but fraud-associated delays and rejections protect their reputation and prevent competitive disadvantage from fraudulent competitors. The 193,000 terminated accounts serve as a warning that policy violations result in permanent banishment from the ecosystem.


    For Users: The scale of fraud prevention—1.1 billion blocked account creations, 40.4 million accounts deactivated for fraud—indicates users are frequent targets of exploitation. The increase in removed deceptive apps (59,000 in 2025 vs. 17,000 in 2024) suggests fraud tactics are evolving faster than historical norms.


    For Payment Networks: Credit card fraud blocking (5.4 million stolen cards prevented from transactions) represents significant value recovery for Visa, Mastercard, and other payment processors, reducing downstream chargeback volumes and fraud investigation costs.


    For the Industry: These statistics demonstrate that centralized, curated app stores can effectively reduce fraud at scale—a meaningful counterpoint to arguments that open, decentralized app distribution offers equivalent security. However, the 247% increase in bait-and-switch removals indicates adversaries are discovering new categories of exploits faster than they can be patched.


    ## Recommendations


    For App Users:

  • Enable two-factor authentication on your Apple ID
  • Review subscriptions and purchase history regularly at appleid.apple.com
  • Report suspicious app behavior immediately via reportaproblem.apple.com
  • Be skeptical of apps requiring payment before providing promised functionality
  • Check app ratings for signs of artificial inflation or suspicious review patterns

  • For Developers:

  • Ensure apps conform to Apple's subscription and payment guidelines before submission
  • Implement transparent pricing and clear cancellation paths
  • Maintain detailed development documentation to expedite review
  • Monitor your developer account for suspicious activity

  • For Merchants Accepting iOS Payments:

  • Use Apple's in-app purchase system rather than redirecting users to external payment processors (which increases fraud risk)
  • Monitor chargeback rates and investigate patterns
  • Implement address verification and velocity checks on high-value transactions

  • ## HackWire Analysis


    Apple's reported figures reveal a contradiction worth examining: the company blocked 1.1 billion fraudulent account creations in 2025, yet this number *decreased* 25% from 2024. Is fraud slowing, or are attackers shifting tactics?


    The data suggests the latter. While account-creation fraud declined, bait-and-switch app removals nearly tripled. Fraudsters are pivoting from volume-based attacks (creating millions of fake accounts) toward precision-targeted deception (submitting individually crafted scam apps designed to evade review). This is rational: submitting 100 bait-and-switch apps has higher success probability than creating 100 million fake accounts.


    The 247% increase in bait-and-switch removals also indicates a dangerous gap in Apple's review process. If fraudsters have discovered that bait-and-switch tactics work sufficiently often to make the strategy worthwhile, then Apple's human review team is failing to catch these submissions at the rate required to disincentivize the attack. This could reflect human fatigue (9.1M submissions is exhausting to review manually) or simply that bait-and-switch is sufficiently variable in implementation that pattern-matching becomes difficult.


    Most concerning: stolen credit card fraud increased 15% year-over-year despite all this investment in detection. This suggests attackers have discovered new vectors—possibly subscription recycling, regional arbitrage, or exploitation of delayed chargeback processing—that circumvent current controls. Payment networks and Apple should jointly investigate why blocking 5.4 million stolen cards represents only partial success.


    For defenders, the lesson is clear: high fraud volumes require constant tactical adaptation. Yesterday's blocked scheme enables today's refined attack. — HackWire Editorial


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)