Skip to content
Saturday 25 July 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
City PM

European business, markets and politics

FTSE 100
10,736.23
+0.91%
DAX
25,099.00
+1.36%
CAC 40
8,372.28
+0.88%
STOXX 50
6,280.94
+1.14%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
What is City Talk? City Talk allows marketers to connect directly with our audience by publishing content on citypm.eu
Monday 07 August 2017 4:50 pm  |  Updated:  Tuesday 04 June 2019 7:44 pm

6 Types of App Piracy You Need to Know

By: Jason Hill

Add as a preferred source on Google

The risk of app piracy is high and with that comes significant risk to brand reputation, ranking and revenues. Luckily we’ve put together a handy guide on what how to avoid this growing issue.

As much as £3 billion is lost each year across 14 billion app instals globally to pirated apps, according to mobile security company Tapcore.

A must-read resource from ironSource offers some important insights and advice into the different types of app piracy and the different approaches that can be taken to protect the app.

There are six types of mobile app piracy and six actions you can take:

1. Impersonating attack

What it is? Using an external app, pirates impersonate the app to trick it into providing infinite in-app purchases (IAPs). In practice, when the app requests a billing receipt from the app store, the pirated app responds and gives a fake receipt.

What you can do? Check and double-check! Make sure the app validates all purchase receipts. Run your own signature using variables like the item and the time of purchase, then check they all match. If they don’t, cancel the receipt.

2. Replay attack

What it is? Hackers replay the attack approach above but also have a validated receipt that “looks” legitimate. Think of a bus, subway or train ticket validated for “a ride”, but only discerning eyes can tell if it is valid for “the ride” in question.

What you can do? Send the receipt to your app’s personal server – since it is generally harder for a pirate to hack your server, than your app. Run the signature (same as above), and that will allow you to determine if the receipt is really valid – or if it’s been used before.

3. Bypassing the validation server

What it is? Pirates have hacked both the app and the server. The loop is closed as the compromised app queries a server that has been hacked and is looking the other way.

What you can do? This is a sophisticated attack that needs a smart response. Each time the IAP is made, send a random number to your server along with the receipt. Since each IAP is paired with a random number, it’s tougher for the pirate to game the system.

4. Refunds

What it is? Hackers exploit the refund feature and policy – trying to get back virtual currency they didn’t purchase in the first place.

What you can do? Keep a local record of the items bought by every user. When you see a purchase for with there is no receipt, or the receipt is marked as cancelled, take the product and send an event that the purchase was refunded. (Be warned – ironSource notes this approach “might only be possible for non-consumables.”)

5. Trainers

What it is? Corrupt software modifies the game’s memory. In practice, the trainer scan’s a game’s memory and looks a number of IAPs and changes that number – say, from 100 gold bars to 1 billion.

What you can do? Double-check transactions using a log and – when virtual currency is cashed in – compare the sum total with the balance in the game. If they don’t match, chances are the user (hacker) has manipulated the game’s memory.

6. Mods

What it is? Hackers get their hands on your APK (Android Package Kit) and change the values in the code to their advantage.

What you can do? It’s a trade-off. It would be best to simply move everything to your server. It protects your app – but it also prohibits your users from playing offline. Not good for the user experience – and prohibitively expensive to boot.

It’s clear that combatting app piracy is a moving target, and an ongoing activity that will command a huge amount of your effort and resources. This is where monitoring your app across all of the App Stores is an important element of your app management strategy.

 

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech

Trending Articles

  • BT braces for loss of 800,000 customers as it banks on fibre to keep turnaround ‘on track’

  • Wise denied US banking licence in blow to expansion plans

  • Regulator flags BDO’s ‘unacceptable’ audit issues for fifth year in a row 

  • Housebuilder hits a wall: How did Vistry become the UK’s most shorted stock?

  • Scotch whisky sales are falling, but what’s really behind the decline?

More from City PM

  • ACE Welcomes Telekom Srbija Group as Newest Member, Expanding Anti-Piracy Fight in Southeast Europe

    Business Wire
  • Oura Ring 5 vs Google Fitbit Air: The battle of the fitness trackers 

    Life&Style
    Close-up of Oura Ring 5 showcasing sleek design and advanced health tracking features in a tech-focused setting.
  • Tote Bet 5 Get 20 in Free Bets: Tote Free Bet Review for July

    betting
    Tote Bet sign-up offer display with promotional text and graphics for new customers on a bright, engaging background
  • Bolt eyes former Zipcar customers with London car-sharing push

    Tech
    Electric Bolt car parked in urban setting, showcasing sleek design and eco-friendly transportation for modern city living.
  • bet365 Jackpot365 Review 2026: Prizes Up To £9,000,000 Every Month

    Betting
    bet365 Jackpot365 promotional banner with jackpot amount, vibrant graphics, and actionable call-to-action for users
CityPM

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About City PM
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 City PM Ltd · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook