Skip to content
Saturday 5 September 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE · FR
MorningWire

European business, markets and politics

FTSE 100
10,831.09
0.00%
DAX
26,046.40
+0.17%
CAC 40
8,278.77
-0.09%
STOXX 50
6,392.93
+0.16%
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
More
GermanyFranceEU InstitutionsCompetitionPublic AffairsBankingTechnologyEnergy
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
  • DE
What is City Talk? City Talk allows marketers to connect directly with our audience by publishing content on morningwire.eu
Monday 07 August 2017 4:50 pm  |  Updated:  Tuesday 04 June 2019 7:44 pm

6 Types of App Piracy You Need to Know

By: Jason Hill

Add as a preferred source on Google

The risk of app piracy is high and with that comes significant risk to brand reputation, ranking and revenues. Luckily we’ve put together a handy guide on what how to avoid this growing issue.

As much as £3 billion is lost each year across 14 billion app instals globally to pirated apps, according to mobile security company Tapcore.

A must-read resource from ironSource offers some important insights and advice into the different types of app piracy and the different approaches that can be taken to protect the app.

There are six types of mobile app piracy and six actions you can take:

1. Impersonating attack

What it is? Using an external app, pirates impersonate the app to trick it into providing infinite in-app purchases (IAPs). In practice, when the app requests a billing receipt from the app store, the pirated app responds and gives a fake receipt.

What you can do? Check and double-check! Make sure the app validates all purchase receipts. Run your own signature using variables like the item and the time of purchase, then check they all match. If they don’t, cancel the receipt.

2. Replay attack

What it is? Hackers replay the attack approach above but also have a validated receipt that “looks” legitimate. Think of a bus, subway or train ticket validated for “a ride”, but only discerning eyes can tell if it is valid for “the ride” in question.

What you can do? Send the receipt to your app’s personal server – since it is generally harder for a pirate to hack your server, than your app. Run the signature (same as above), and that will allow you to determine if the receipt is really valid – or if it’s been used before.

3. Bypassing the validation server

What it is? Pirates have hacked both the app and the server. The loop is closed as the compromised app queries a server that has been hacked and is looking the other way.

What you can do? This is a sophisticated attack that needs a smart response. Each time the IAP is made, send a random number to your server along with the receipt. Since each IAP is paired with a random number, it’s tougher for the pirate to game the system.

4. Refunds

What it is? Hackers exploit the refund feature and policy – trying to get back virtual currency they didn’t purchase in the first place.

What you can do? Keep a local record of the items bought by every user. When you see a purchase for with there is no receipt, or the receipt is marked as cancelled, take the product and send an event that the purchase was refunded. (Be warned – ironSource notes this approach “might only be possible for non-consumables.”)

5. Trainers

What it is? Corrupt software modifies the game’s memory. In practice, the trainer scan’s a game’s memory and looks a number of IAPs and changes that number – say, from 100 gold bars to 1 billion.

What you can do? Double-check transactions using a log and – when virtual currency is cashed in – compare the sum total with the balance in the game. If they don’t match, chances are the user (hacker) has manipulated the game’s memory.

6. Mods

What it is? Hackers get their hands on your APK (Android Package Kit) and change the values in the code to their advantage.

What you can do? It’s a trade-off. It would be best to simply move everything to your server. It protects your app – but it also prohibits your users from playing offline. Not good for the user experience – and prohibitively expensive to boot.

It’s clear that combatting app piracy is a moving target, and an ongoing activity that will command a huge amount of your effort and resources. This is where monitoring your app across all of the App Stores is an important element of your app management strategy.

 

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech

Trending Articles

  • Victoria Beckham owed £350,000 by Harvey Nichols

  • M&G: FTSE 100 giant hits out at Rayner’s ground rent cap as it suffers loss

  • Fulham owner Khan sees his £1bn stadium construction project take next steps

  • John Lewis boss: UK economy facing a ‘permacrisis’ 

  • My stressful night at London’s ultra luxe £1k a night hotel where I found glass in my food

More from Morning Wire

  • Government urged to do more to tackle £1bn piracy problem in sport and entertainment

    Sport Business
    Person in a rainbow clown wig and red nose using a flip phone, next to a man in a red and white bucket hat.
  • Football finance experts urge caution over Premier League + price promotion

    Sport Business
    Premier League trophy on display at a stadium with spectators in the background
  • BoyleSports Mobile Offer 2026: Bet £10 Get £20 in Free Bets

    Betting
    BoyleSports logo on a blue background with MOBILE OFFER in yellow text, highlighting a special promotion
  • Why Manchester City’s £86m Bouaddi signing should ring alarm bells in French football

    Sport Business
    A male soccer player with long dark curly hair in a white LOSC Lille jersey adjusts his hair on the field.
  • Lloyds Bank and Halifax users unable to use app in latest outage

    Banking
    Hand holding a smartphone displaying the Lloyds Bank mobile app logo on a green screen.
  • Google to pay £260m to settle ‘unfair’ pricing class action lawsuit

    Lawsuit
    Googles modern Kings Cross headquarters showcasing innovative architecture in Londons dynamic tech district
  • Experian Brings Personalised Credit Scores to ChatGPT in a UK First

    Business Wire
  • Monzo faces outage as thousands of users unable to make payments or transfers

    Fintech
    UK fintech Monzo is ramping up its lifestyle reach.
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • EU Institutions
  • Europe

Business

  • Markets
  • Business
  • Economy
  • Regulation
  • Competition
  • Public Affairs

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook