I should have paid a bit more attention; 10 unauthorised transactions of £10 were taken from my credit card via my apple account last month, which it turns out has been hacked.
A trawl through my Gmail reveals Apple in their wisdom only emailed me one receipt for £10, which of course I didn't notice, rather than one receipt for ten transactions or an email for every transaction, which I'd have noticed straight away.
They've locked my account out thankfully, but didn't think to have a system generated email pinged to let me know.

Credit card is cancelled as of this morning, and RBS are on the case. It seems because I've used iTunes perviously though, I'll have to have some form of proof of what was and wasn't me, handy that apple haven't sent me all of the receipts then.
It'll all resolve itself, just a PITA, a (big) bit of a letdown with apple, and a heads up for everyone else.
