Unknown Device linked to ID and spam texts from my own number?
Hello! I'm not sure what exactly was compromised/how and was hoping someone could help me make sure I'm taking the right security steps!
I got a pop up message on my iPhone saying that a Mac was now linked to my Apple ID and phone number for iMessage. I didn't do this and don't share my ID passwords with anyone. I disconnected the device, changed my Apple ID password and the password of the email it's associated with. I also turned on 2 factor authentication as well.
Here's the message I saw:
I then saw that I had a text history on my phone that seemed to show I was in a text group with an app (www66338app followed by some Chinese characters). There were 3 participants in the group. 1 was this app, the other 2 were my phone number. The texts appear to show as if I sent them (messages appearing on the right like in this pic)
About an hour prior to this, I did make a purchase on a totally unrelated app (Toreba) where I was prompted to log into my into my Apple ID to confirm the purchase. I've used that app for a while and have made purchases before. I don't see that any new apps have been downloaded on my iTunes app history.
I took a look later and one of the duplicate (my) numbers had left the chat. I've also blocked the app sender.
I'm having trouble pinpointing what the core issue is... How did someone get to my Apple ID? (what other security holes do I need to patch?) What can I do to keep my phone number safe as well since I don't want another person using it to either make calls or send messages. Is there a way to make sure that there's no way someone else can make a call/send texts using my number (the real one, I understand spoofing is a thing) other than my physical phone? Does this mean that the unknown person had access to my text messages if they logged into iMessage on some other device?
Thanks for any help -- I'm a bit frazzled.
iPhone 6s