Skip to content
Naked Security Naked Security

Kid spends $5900 playing Jurassic World on Dad’s iPad. Here’s how to prevent that happening to you.

Nothing like memorizing dad's passwords - both for his iPad and his Apple ID! - to buy all the scaly goodness your little heart desires.

Nothing like memorizing dad’s passwords – both for his iPad and his Apple ID – to buy all the scaly goodness your little heart desires.

The latest “Dad, I shrank your bank account due to super easy in-app purchases” story involves a 7-year-old who racked up a £4000 bill (about $5900) by buying dinosaurs.

As the Metro reports, Mohamed Shugaa, from West Sussex, UK, found out his son had made the transactions during a 5-day dino spree in December, using Dino Bucks in the iTunes game Jurassic World on his dad’s iPad.

Sure, he knew his son could unlock his tablet with his passcode.

But Shugaa was (unpleasantly!) surprised to learn that his son, Faisall, had also memorized his Apple ID password.

That’s all you need to unlock the gates to flashy dinosaur upgrades.

Faisall made 65 purchases from Apple between 13-18 December, never realizing that Dino Bucks translate into real money.

His dad thought that Apple should have known a whole lot better than that:

I was so mad. I’m 32 years old. Why would Apple think I would be spending thousands of pounds on buying dinosaurs and upgrading a game?

Why didn’t they email me to check I knew these payments were being made? I got nothing from them. How much longer would it have gone on for?

This certainly isn’t the first time Apple’s been called out for letting kids make purchases in child-focused apps.

It got into trouble with the Federal Trade Commission (FTC) for making it too easy for kids to blow money through in-app purchases in January 2014, when the commission cited Apple’s use of a buy button that led to a password screen that 1) failed to inform parents of what they were authorizing and 2) opened up a 15-minute window following login: plenty of time in which to make additional purchases without parents’ knowledge.

While no judgement was ever made, Apple handed over at least $32.5 million to cover refunds to exasperated parents.

In a similar settlement in September 2014, Google handed over $19 million to the FTC .

In both cases, the FTC’s point was that it shouldn’t be too easy for kids playing games – games that are clearly targeted at kids – to click buttons that bill their parents in real money for shiny (or reptilian, in Shugaa’s case!) virtual objects.

Of course, we can’t expect either Google or Apple to shoulder all the responsibility in these cases.

If your kids are racking up charges against your credit card, that probably means you’re letting them have unsupervised access to your device.

Heaven knows that can lead to even more trouble than surprise credit card transactions, given that you’ve probably set up your device so it’s easy for you to read and send corporate email, automatically sync changed data with other computers you use, access your social networking accounts, and much more.

The FTC has a great infographic with simple but very good advice about how to keep up with kids’ apps, which can pull any of these stunts:

  1. Collect and share personal information. An investigation by privacy watchdogs in 2015 found that just over 2 in 3 apps and sites were collecting children’s names and email addresses.
  2. Let your kids spend real money even if the app’s free. Case in point: the free Jurassic World, which in spite of being free has a T. Rex-sized appetite for in-app purchases.
  3. They might include ads. So bad, for so many reasons, as we learned in eyeball-popping fashion with the naked selfie ads offered up in kids app My Talking Tom.
  4. They might link to social media. It’s hard enough for any of us, at any age, to think before we post. It’s probably not the best idea to mix kids high on Jurassic-level adrenaline with social media.

Even if you don’t have kids draining your bank account by in-app purchases, you should still keep an eye on your bank account statements.

After all, there’s no maximum age when it comes to fraudulently squeezing savings out of accounts.

One example: in April 2015, a California woman filed suit against Google, alleging that inadequate security enabled crooks to run through 650 transactions, worth thousands of dollars, on her Google Play account, all debited electronically without her sign-off.

Here are some ways to avoid unwillingly overinvesting in dinosaurs:

  • Enable Touch ID for all purchases, if your iDevice has the feature. It’s not impossible to skirt fingerprint readers – both the iPhone 5s and the Samsung Galaxy S5 fingerprint readers have been bypassed – but if your kid is that determined, at least the feature will slow him or her down as they nab some wood glue and a good print.
  • Create a separate iTunes account for the tot – one not associated with a credit card. It’s annoying to deal with more than one account on the same iDevice, but it might well be worth the aggravation.
  • Don’t show anybody, even family members, your passwords. After all, that tablet isn’t just a platform to play games. It’s what you use as a tool in your job, and as such, it can be the launchpad for electronic mayhem. You wouldn’t let the kids play with paper-cutting guillotines, so why let them near your email accounts, for example, by giving them the passwords? We often preach the creed of passwords needing to be long, complex and unique in order to make them hard to crack. Here’s a short, sweet video that shows you how to pick a proper one.

When Shugaa first contacted Apple Support to demand a refund, he was told there was no guarantee he’d get his money back. However, the father of two said he eventually managed to convince Apple to fork over a refund by telling the company that he needed the money to buy Christmas gifts for the kids.

13 Comments

Freumium scams. Any company that would charge $5900 to play a video game, should be put in jail with the same people that hack bank accounts. Search “freemium isn’t free”

Reply

£4000? That’s an Xbone elite and 70 full price games. In game transactions should have some sort of consumer protection regulations.

Reply

There’s also one other tip that should be added on here. Enable family sharing for iOS devices and turn on “Ask to buy”. Kids can request purchases and the parents can approve those purchases, even in-app purchases.
Family Sharing: http://www.apple.com/icloud/family-sharing/
Ask to Buy: https://support.apple.com/en-us/HT201089

Reply

I have less sympathy for the parents in this story than some other cases. Apple provides methods of restricting purchases by children but all of them are circumvented by allowing your 7 year old to have access to your AppleID.

Reply

I remove the credit cards and bank accounts and buy iTunes cards. If not enough funds, then nothing will happen.

Reply

My kid turned on the tap and wasted 1,000,000 litres of water.
Surely the water company should have known.
etc.

Reply

I was about to give this comment a thumbs up, but on second thoughts…water is very different from IT services which are much easier to track. If I spend to much money on my credit card my bank may automatically block my card and check with me if I know what is going on. A similar service seems possible for in-app purchases.

Maybe your question should have been if you kid wastes 1,000,000 litres of water why didn’t the water company contact you?

Reply

I was thinking of a similar analogy – back in the day when any child could dial certain services on a phone and rack up large phone bills. Is the phone company responsible for you not monitoring your children? So Dad gives kid ipad to babysit him for 5 days instead of doing some real parenting and now it’s Apple’s fault? This world is doomed. How can we teach children accountability for actions when adults blame everyone but themselves? Computing 101 – Never give ANYONE, ANY password.

Reply

Since all son’s micropurchases trigger a credit card authorization, it seems to me that daddy has a rather high credit card limit for being a heavily-taxed UK citizen. So daddy has a pretty nice income. Also daddy was probably already a loyal and established customer of the iTunes App Store since none of the numerous repeated transactions were flagged as suspicious nor by Apple nor by his bank. And finally daddy seems to be pretty well-connected too, as he was able to convince a press outlet to run his story. Smart daddy knew that Apple would refund him pretty quickly if his story got press attention. What about all the poor daddies in the world who aren’t that well-connected?

Reply

Very wild story. On the question of how is it possible to spend that much? Well the game is probably on the free to play setup. There is theoretically no “cap” on resources you would pay real money for & that’s how some game publishers/developers want it.

Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe to get the latest updates in your inbox.
Which categories are you interested in?
You’re now subscribed!