The Email Address Apple Promised to Hide
A paid Apple privacy feature contains a flaw that lets almost anyone recover the real email address it is meant to conceal, and more than a year after the researcher who found it reported it to Apple,
What Apple sells
Hide My Email is a feature Apple sells as part of iCloud+, its paid subscription tier. It generates a random address, usually two words and a number ending in icloud.com, that a person can give to a website, a newsletter, or a stranger in place of their real address, with mail sent to the alias forwarded to the real inbox behind it. Apple’s own documentation describes the purpose plainly, telling subscribers they can use the feature to keep your personal email address private so that they do not have to hand over their real address when filling out a form, signing up for a newsletter, or sending mail.1 When the feature is used through Sign in with Apple, the account-creation system built into many apps and websites, Apple’s documentation goes further, stating that only the app or website an account was created with can use that address to reach the user, and that the personal address stays private.2
The value of the feature rests entirely on that concealment holding. A person uses an alias precisely so that the party on the other end of it cannot learn, keep, or later leak the real address, whether the aim is to cut spam, to keep an account from being tied to their identity, or to limit the damage if the service is later breached.
What the researcher found
On July 1, 2026, the independent technology outlet 404 Media reported that Hide My Email contains a flaw that lets almost anyone take one of these aliases and recover the real address hidden behind it.3 The outlet did not rely on the researcher’s account alone. A 404 Media reporter generated a new Hide My Email address, an alias that had never been used, and passed it to the researcher, who returned the real email address tied to the reporter’s Apple account about five minutes later.3 Digital Trends, checking the same claim, described the same outcome.4
The researcher is Tyler Murphy, co-founder of EasyOptOuts, a service that removes people’s records from data brokers.3 In his own testing with volunteers, every alias he checked could be undone, though he was careful to say that the full scope is not known and that his sample was limited.3 What the reporting establishes about the attack, without describing how it works, is that it is fast, that it returned the correct answer each time it was run, and that its only starting material is the alias itself, the string the feature exists to make safe to share.
It helps to place this against the attacks a reader is more likely to have heard of. The familiar routes into an email account or the accounts attached to it, phishing and its telephone and text-message forms, credential stuffing, password spraying, and the various forms of brute-force password guessing, including dictionary and rainbow-table methods, share one feature, which is that each depends on the target doing something wrong, surrendering a password, reusing one across services, or entering credentials where they should not.5 What 404 Media reported requires none of that. The person whose address is exposed need not click anything, reuse anything, or make any mistake, because the only thing the attack consumes is the alias the feature already told them was safe to give away.
Neither the researcher nor the outlet published the method, and 404 Media said it was withholding the technical details because the flaw could still be exploited at the time it went to press.3 A method whose finders decline to release it because releasing it would put users at risk is one whose danger lies in how easily it can be followed once known, rather than in any special difficulty of following it.
The timeline
Murphy reported the flaw to Apple in June 2025, and gave the company instructions for reproducing it.3 Apple replied about a month later and said it was looking into the matter.3 In March 2026, Apple told him it had addressed the problem in a recent change to its systems, language that ordinarily signals a fix.4 Murphy tested the feature again, found the address still exposed, and sent Apple more information.3 Through the spring, Apple continued to tell him it was investigating, and asked him not to make the issue public until its work was finished.3 At the end of May 2026, Apple said a fix was expected in a security update in the coming weeks.3 That update had not arrived when Murphy, saying he no longer felt comfortable waiting, brought the issue to 404 Media, more than a year after he first reported it, and Apple did not respond to the outlet’s requests for comment.3
Apple publishes its own account of how it handles reports like Murphy’s. On its security research page, the company states that it resolves most reports within ninety days, and that it does not discuss a security issue publicly until its investigation is complete and any needed update has reached users.6 Murphy’s report was acknowledged, described at one point as addressed, and then left open past a year, while the feature it concerns remained on sale.
Figure 1. Apple’s handling of the report, set against its own stated ninety-day resolution target.
Why an exposed address matters
The reason an exposed email address is a question of safety rather than nuisance is that an address is a durable key into a large and well-documented market in personal information. In 2014 the Federal Trade Commission published a study of nine data brokers, companies that assemble profiles of individuals from public records, purchases, and online activity and sell them on, generally without the knowledge of the people described.7 The Commission found that these firms hold billions of records covering nearly every American, with a single broker in the study holding information on more than 1.4 billion consumer transactions and hundreds of billions of individual data points.8 One of the nine, the aggregator Rapleaf, held at least one data point tied to more than eighty percent of all United States consumer email addresses, and attached to those addresses details such as age, marital status, and dozens of further attributes.7
The address does not by itself create any of this information. It connects to it. Almost every adult already sits in these databases in the ordinary course of life, through property records, voter rolls, court filings, purchases, and public social accounts, and that profile exists whether or not anyone holds the person’s email.7 What the real address supplies is the link between a particular alias and that existing file, the point at which an entry that reads only as a random string of characters becomes attached to a name the database already held. Recovering the address behind an alias is in that sense less the disclosure of a dossier than the bridge to one already assembled.
Figure 2. The recovered address does not build the file; it connects the alias to one the brokers already hold.
A particular kind of data broker, the people-search site, sits at the retail end of this market. The FTC describes these sites as businesses that gather personal information from public records, social media, and other brokers, compile it into a report, and sell that report to anyone willing to pay.9 There is, the Commission notes, no federal law that prevents a company from publishing this information, and the burden of removal falls on the individual, one site at a time.10 For most people the result is unwanted exposure, and for some, including survivors of stalking and domestic violence, the exposure is dangerous enough that a number of states maintain address-confidentiality programs to keep their whereabouts out of these databases.10 Murphy pointed directly at this market when he noted that free, publicly accessible people-search sites make it simple to turn an address into a name and more, which is why, in his account, the people most likely to rely on Hide My Email for their safety are the ones the flaw most exposes.3
What Hide My Email does not conceal
The concealment Apple offers has a second limit, one that is not a flaw and was never promised away, but that sits at a distance from the sense of anonymity the feature’s name invites. Hide My Email hides the real address from the app, the site, or the sender that receives an alias. It does not hide the connection from Apple, which holds the mapping between every alias and the account behind it, and produces that mapping in response to lawful demands.
In early 2026, court records reported by 404 Media and TechCrunch showed how this works.11, 12 Federal agents investigating a threatening message sent to Alexis Wilkins, identified in filings as the girlfriend of FBI Director Kash Patel, traced the message to a Hide My Email alias.11 Apple, served with a legal request, provided the account holder’s real name and address, identifying the sender, and turned over records for the 134 aliases that account had generated.12, 13 TechCrunch reviewed a second warrant in which Apple provided similar records to Homeland Security Investigations during an identity-fraud inquiry.12 In each case the feature worked as designed against the third parties who received the aliases, and provided no barrier at all to a subpoena, because it was never built to.
The change now underway
While the flaw sat open, Apple prepared a separate change to the feature that will reduce its usefulness for reasons unrelated to the vulnerability. In June 2026, TechCrunch reported that Apple intends to move newly generated aliases from the icloud.com domain to a distinct private.icloud.com domain, and to shift the addresses created through Sign in with Apple away from the privaterelay.appleid.com domain used today.14, 15 An address that announces on its face that it is a relay is one that a website or a mailing list can identify and refuse, which would leave users of the feature to supply a real address after all.15 The stated purpose of the change is to help email systems prepare for the switch, and its effect is to make the aliases easier to block at the point where they are meant to protect the user.15
What a reader can do
For a reader who uses Hide My Email, the practical meaning of the flaw follows from what an exposed address does. The immediate and visible effect of recovery may be no more than additional unwanted mail reaching the real inbox. The consequential effect, and the one that matters for the people the feature is meant to protect, is that an identifier the reader had kept concealed becomes a known one, and a known address is what allows the alias to be tied through the data-broker and people-search market to a name and a location, in the way set out above.7, 9 The full extent of who is affected is not established, because the researcher’s testing was limited and the method is not public.3
There are steps within a reader’s own control, though it should be said plainly that none of them closes the flaw, because the flaw is Apple’s to fix and no setting available to a user removes it. A person especially concerned about a particular alias can deactivate it in the Hide My Email settings, after which it no longer forwards mail, and can generate a new address for the service in question, though deactivating an alias does not change the real address behind it and so does not undo a recovery that has already occurred.1 The more durable protection is against the downstream harm rather than the flaw itself, because the danger of a recovered address lies in what the people-search market can attach to it, so a reader can reduce that exposure by opting out of those sites, a process the Federal Trade Commission sets out, which requires a separate request to each site and repetition over time as records reappear.9 And because an alias no longer carries the assurance the feature’s name implies, the concealment cannot be relied on when deciding whether to share one with a party a reader does not trust, until Apple ships the fix it said in late May was expected in the coming weeks.3
The record
The record now stands as follows. Apple sells a feature whose stated purpose is to keep a person’s real email address private from the parties they share an alias with, and charges a subscription for it. A researcher found that the address can be recovered from the alias by almost anyone, in about five minutes, with the alias as the only input, reported it to Apple with reproduction steps in June 2025, was told in March 2026 that it had been addressed, found that it had not, and watched the feature remain both exploitable and on sale more than a year later. Separately, the same feature has been shown to yield its users’ real identities to law enforcement on request, and is being changed in a way that will make its aliases easier for websites to reject. Each of these is documented, and each is left for the reader to weigh.
End Notes
1. Apple Support, “Create and manage Hide My Email addresses in Settings on iPhone.” https://support.apple.com/guide/iphone/create-and-manage-hide-my-email-addresses-iphcb02e76f7/ios
2. Apple Support, “How to use Hide My Email with Sign in with Apple.” https://support.apple.com/en-au/105078
3. Joseph Cox, “Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email Addresses,” 404 Media, July 1, 2026. https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/
4. “Apple’s Hide My Email feature has an unfixed bug that leaves email addresses exposed,” Digital Trends, July 2026. https://www.digitaltrends.com/computing/apples-hide-my-email-feature-has-an-unfixed-bug-that-leaves-email-addresses-exposed/
5. For these attack categories, see Cybersecurity and Infrastructure Security Agency, National Initiative for Cybersecurity Careers and Studies, “Password Spraying and Credential Stuffing.” https://niccs.cisa.gov/training/catalog/cybrary/password-spraying-and-credential-stuffing
6. Apple Support, “Report a security or privacy vulnerability.” https://support.apple.com/en-us/102549
7. Federal Trade Commission, “Data Brokers: A Call for Transparency and Accountability,” May 2014. https://www.ftc.gov/system/files/documents/reports/data-brokers-call-transparency-accountability-report-federal-trade-commission-may-2014/140527databrokerreport.pdf
8. Federal Trade Commission, “FTC Recommends Congress Require the Data Broker Industry to be More Transparent,” May 27, 2014. https://www.ftc.gov/news-events/news/press-releases/2014/05/ftc-recommends-congress-require-data-broker-industry-be-more-transparent-give-consumers-greater
9. Federal Trade Commission, “What To Know About People Search Sites That Sell Your Information.” https://consumer.ftc.gov/articles/what-know-about-people-search-sites-sell-your-information
10. Privacy Rights Clearinghouse, “FAQ: Online Data Brokers and People Search Sites.” https://privacyrights.org/resources-tools/archives/faq-online-data-brokers-people-search-sites
11. Joseph Cox, “Apple Gives FBI a User’s Real Name Hidden Behind ‘Hide My Email’ Feature,” 404 Media. https://www.404media.co/apple-gives-fbi-a-users-real-name-hidden-behind-hide-my-email-feature/
12. “Apple will hide your email address from apps and websites, but not cops,” TechCrunch, March 30, 2026. https://techcrunch.com/2026/03/30/apple-will-hide-your-email-address-from-apps-and-websites-but-not-cops/
13. “Apple revealed ‘Hide My Email’ user identity in FBI investigation,” CyberInsider, March 2026. https://cyberinsider.com/apple-revealed-hide-my-email-user-identity-in-fbi-investigation/
14. “Apple plans to change its Hide My Email privacy feature that could make it less effective,” TechCrunch, June 16, 2026. https://techcrunch.com/2026/06/16/apple-plans-to-change-its-hide-my-email-privacy-feature-that-could-make-it-less-effective/
15. “Apple hasn’t fixed a Hide My Email privacy bug in over a year,” AppleInsider, July 1, 2026. https://appleinsider.com/articles/26/07/01/apple-hasnt-fixed-a-hide-my-email-privacy-bug-in-over-a-year




