iPhone hacked

MDM at the phone side is mostly just a profile - restrict this, allow that, check server to see if need to install software etc - that sort of thing.

Different iOS (and Android) versions will have differing capabilities, but should be similar - I haven't really delved into it too deeply.

I'm probably feeding paranoia at this point though, I agree completely with what @SauRoNZA wrote above ( #65 )
Camera, pic gallery, WhatsApp, email, safari and location are all logged on MDM. Location was used easily and consent given by the employee. Remote wipe and contacts are most common.
Thing is it’s easily monitored with no reference to the employee. So if you on a rude WhatsApp group, pics and content are saved to the gallery. And WhatsApp is monitored. There was a case with some bank employees gossiping on WhatsApp, it was the MDM that pulled the information from their phones.
 
Any bank clerk can reset my internet banking password, yet they also can't log in to my internet banking.

MS employees can not "hack" your email or log into your email account.

The only access 99.9999999999% employees have to production data, is that which is specifically allowed through an interface designed to give them access.
Trust me on this. I work for a company that also offers a "Software as a Service" type offering, like email is. Even if a customer logs a ticket about a bug, I can not access that customer's data directly. I have to submit a request to the 0.00001% of employees who can access it, and they need the customer's explicit permission. There needs to be a record of why the supplied me with it, with the customer's permission. It needs to be done this way for compliance reasons, and it is audited.

The protection of information acts around the world is pretty serious. If MS allowed an employee to access anyone's email, they would be sued, fined, and you would have read about it all over the internet.

You need to trust that you don't know enough about how stuff works to make the claims that you are making.
Bank employees have chameleon access to your accounts and balances with just Your ID number.
 
Ok so it was MDM initially.
Now to figure out what was used when MDM was removed or if it’s completely removed.
Where is the bookmarks in safari pulling from? iCloud is off.
 
So, in summation, looks like op has a MDM managed device (typically a company supplied phone vs personal one).

Doesn't smell like any hacking, just some paranoia.

Although as op doesn't want to answer basic questions, thats my best guesstimate, vs a 100% answer.
 
Also, if it is Pegasus, who’s using it in SA? It can’t be cheap or easily accessible.
 
So, in summation, looks like op has a MDM managed device (typically a company supplied phone vs personal one).

Doesn't smell like any hacking, just some paranoia.
MDM is removed, I checked the profiles. I also removed the device password, which you can’t do when MDM is enabled.
 
How do I see if it’s something simple like just another device paired with mine and every time that device is turned on it’s automatically data dumps and syncs with mine?
 
How do I see if it’s something simple like just another device paired with mine and every time that device is turned on it’s automatically data dumps and syncs with mine?
As you say no MDM profiles are present, lets exclude that.

Do you have icloud enabled?
Perhaps with family sharing?
 
As you say no MDM profiles are present, lets exclude that.

Do you have icloud enabled?
Perhaps with family sharing?
iCloud is off, 0% used.
Family sharing is off.
I have 4 Apple IDs, I checked all and it’s the same, all are off.
 
iCloud is off, 0% used?

0% used doesn't mean its turned off, just means you haven't used the storage.

If you go to Settings, Apple ID, iCloud is it logged in?
Yes, it’s logged in but everything switched off. Yes 0% storage.
 
How do I see if it’s something simple like just another device paired with mine and every time that device is turned on it’s automatically data dumps and syncs with mine?

This only exists in the movies.

You can see other devices using your Apple ID and syncing via iCloud via the Apple ID Management website and also remove them from there.

But since you said iCloud is off this isn't a concern.
 
Camera, pic gallery, WhatsApp, email, safari and location are all logged on MDM. Location was used easily and consent given by the employee. Remote wipe and contacts are most common.
Thing is it’s easily monitored with no reference to the employee. So if you on a rude WhatsApp group, pics and content are saved to the gallery. And WhatsApp is monitored. There was a case with some bank employees gossiping on WhatsApp, it was the MDM that pulled the information from their phones.
Amazing how you went from knowing nothing about anything to suddenly knowing exactly how MDM works.

MDM cannot access your camera or picture gallery.

MDM also cannot read your WhatsApp or other messenger platforms.

MDM cannot read your email, but your company provided email could be read by other means. Not your personal email.

MDM can only see your actual location data when put into lost mode and you would be aware of this as you couldn't take it out of lost mode without their intervention.

Safari also cannot be directly monitoring via MDM, but your company could have an enforced VPN in place from which they could track your usage.

MDM cannot see your contacts, but yes it can wipe them.
 
This only exists in the movies.

You can see other devices using your Apple ID and syncing via iCloud via the Apple ID Management website and also remove them from there.

But since you said iCloud is off this isn't a concern.
What’s the Apple ID management website?
 
Besides Apple Keychain and some iCloud stuff (I dunno, maybe photos and nude photos to leak), what incentive does a person have to hack your Apple Account?
 
Besides Apple Keychain and some iCloud stuff (I dunno, maybe photos and nude photos to leak), what incentive does a person have to hack your Apple Account?

You only need the key to one thing to get the keys to everything else.

It's always the lowest common denominator that opens the door to everything else.

Then of course there is the ransom option to get your data back, or to threaten with blackmail based on what has been found.
 
Top
Sign up to the MyBroadband newsletter
X