You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

MDM on personal iPhone - Businesses, unauthorized developer activity HELP!

I am a personal 'User' I have cycled through many hours and days with support. No one knows what is going on. Most likely because I am never able to speak with someone that understands the Enterprise platform. I feel this is happening via my carrier- but Fraud sent me to Tech support. Tech support told me my phone is hacked and to file a police report.

In combination I suspect that MDM is a gateway for an external developer to access my phone via various methods: webkit, Xcode, Apple Store Connect, SDK

I am about 99.99% sure I know why, but that is something that I will not disclose because most likely all of my activity is monitored; despite the very strict privacy settings I try to maintain.


Symptoms:

  1. My apps will sometimes tell me they did not come from the App Store (Maps, FindMyiPhone, etc..)
  2. When I make an attempt to chat with Apple support I receive a message to Use Messages to Connect with Business. When I have my iPhone in LOCKDOWN mode I receive a message that I cannot use Messages for Business when my device is locked down.
  3. I only have one device. However, I am sharing across devices- many times or I have the option to. The choice is not grayed out.
  4. I am unable to perform an Emergency Reset because I am usually sharing something - Notes, Home, Health, Books....
  5. I do not use iCloud Drive due to multiple security concerns. Almost every time that I double check those settings apps show that they are using iCloud Drive. (Game Center, Health or Fitness, Notes, Books, Apple Support, Wallet) While clicking to turn OFF syncing I have had a battle with it changing right back before my eyes. (I have screen recordings)
  6. Game Center will come on even though I have strict Screen Time settings.
  7. I am generally either sharing, or my phone is gathering data from Health; even though that privacy option is supposed to keep that from happening.
  8. Sometimes I am unable to even sign out of my phone due to 'restrictions'.
  9. I have 'Share with Family' sometimes

*Those are only a few symptoms. That is minus the horror I see from the extraction of information I backed up into Kali Linux

As I have mentioned I have spent many many many hours with Support. One Senior Director did spend time Googling the services that show up in my Analytics. I have even uploaded screen shots and documents, but I never heard back.

I REALLY REALLY need help here.

I will add attachments. They won't be nearly the amount I have. I am begging!!!



iPhone 13, iOS 16

Posted on Apr 2, 2023 2:32 PM

Reply
Question marked as Top-ranking reply

Posted on Apr 3, 2023 6:45 AM

Sadly, there doesn't seem to be any help and the ones that will respond, will tell you you are either crazy or you can't be hacked unless you have your device to someone.


For what it is worth I have been dealing with this and here is what I have learned; you need to delete your old apple id's and confirm that they are deleted. You may not be logged in to any (neither was I) but it has something programmed into the IOKIT boot so you cannot reset the NVRAM properly, leaving find my process to look as if the activation lock is on.


Make appointments for each apple product to have a firmware/software update through DFU mode and make sure it is DFU because a factory restore will not remove the cache that is lingering in the files. This should all be done at the same time otherwise it will talk to the other device and reestablish itself.


The factor reset you are doing doesn't work because it does not empty the trash and it seemingly blocks any terminal command to do so as well.


Before you boot up your computer(s) & phone(s) delete and confirm you have deleted all of your previous apple id's. Write down the code it provided to delete the id because chances are you will have to call to

confirm its deletion.


If you have a google ID, check to see if you are enrolled in any trial based workspace or fire base programs. Workspace allows device control as well.


I have changed our TV's and printers but it still seems to latch on to any printer so now we do not print. Debilitating to say the least.


I believe that there are enough of us out there to confirm that this problem exists but apple will not respond until they have fixed it. I know it sucks. Two factor everything and I wouldn't suggest any external usb or thunderbolt security keys.


I also would not suggest any products other than apple. That will only make your situation worse.. even the keyboards because it will load a generic driver onto your device. Only use apple wires as well. I am definitely not an apple advocate, only sharing what I have come to accept and learn.


You may have to go line by line in settings on your iPhone to turn off everything that you do not use and if there is an arrow on it, click to make sure there is not an opportunity to bypass your defaults. The Mac computer is the same and there are probably about 100 Plists that will try to alter your default settings so do not take anything for granted until you have clicked through it all. Plists are just preference and apple will tell you that it does not mean that they are being used. That is absolutely correct but the Plists I have seen start with NVRAM and a fmm (find my

mac activation) which is huge problem.


for whatever reason it uses nfc and mdm BUT mdm does get removed later on during the process. It keeps respawning. So it isn't necessarily MDM as much as it is trying to be so I presume that there is some detail in the MDM program that helps it get what it needs.


The shared cache you are seeing is at best guess, all of the info it has collected on you and will keep looping together. This is just a guess but I have been watching it on mine as well. I could 100 percent be wrong but I believe the cache is what keeps this process communicating between devices.


There are enough of us out there with this problem. I am sure that we have a common thread but I have no idea what it could be. I just know that no one is going to help me or my family and I am just going to have to do my best to keep my kids safe.


I could bring a new computer into this house and within ten minutes watch it try to harvest my old apple ids, while Bluetooth sniffing and try to connect to something nonstop. Eventually, it gets back in and the new id becomes corrupt, I delete it and start again hoping the last apple update resolved this issue. Two years later and I am headed back to the Apple Store today to pick up a couple of devices.


I wish someone had better news for the both of us but this is the best advice I can give you.

Similar questions

160 replies

Feb 26, 2024 11:03 AM in response to AgentDragonfly

I’m trying to follow you but I can’t press the follow button it’s erased out and I can’t like your post either.


I’m have been going through this for a year. Everything is hacked. I have nothing. My bank watched for a month and believes me. I got an iPad luckily but it immediately got hacked as soon as I set it up. I have had a lot of information. I am sick of being looked at like I’m a crazy person. I really like to get a hold of everybody that said this happened to . I know where to talk safely I know how to figure out a lot of things but I really like to talk to some other people this is ****. ****. ****. I can’t even type without being harassed. I’m going to look And see if I can find any of this group.


I have an iPad 10 completely up-to-date I have touch ID I haven’t bothered in ambling anything besides two factor but it always gets deleted anyways. A lot of good the iCloud email address does because they won’t give it back to me . Recovery days I never get an email to say I’ve proven it’s me it doesn’t take a genius I’ve had account for over over over 10 years but the hackers get to spend more time in my business than I do. The thing

I hate the most, stealing and copying my Stories and letters and blogs participation, rough drafts, short stories.

my contact list.

I have impeccable credentials or had, I don’t know what’s going on my social accounts I can’t even imagine.


I don’t know what kind of delusional world that some of these moderators live in but you only need to go listen to the Washington Post podcast the very same thing happened to a Washington Post journalist, it’s all documented . The fact what this is. yes, very sadly , because I love apple products but I can use them very well right now , they have done it isn’t even hacking. It’s outright theft.



Feb 27, 2024 4:42 PM in response to ChSDude

I’m just now seeing this thread and have had the same horrific experience! I have not been through all of the posts yet before my urge to comment because you describe the mental stress this has caused. Going on two years now trying to figure this out on my own and in my own time has been a lonely journey for the simple fact that it’s “too much” for most people because if you mention why you always have an updated email address or why you did not get their message or email you get the crazy raised eyebrow look and seen as insane!

it can not be ignored because it effects your life every day! I have lost access to email accounts and social media profiles and accounts yet I see them show up and have no access to them at all! When I communicate to the source nothing is ever done.

Apple is always friendly and trys but after they learn the scope of the problem, I don’t hear back or I get disconnected.

i have developer privileges I should not and did not know until things began really messing up and strange email accounts and media profiles were created using my identity. Apple ID has been stolen or I get locked out and have had no choice but to wipe device and reset. With 4 iPhones now and a MacBook Air M1.


I could go on and on about all of the things I have found out but no one would listen.


I have recently discovered too the nfc technology and how it can transfer data between devices without needing power or to authorize connection like Bluetooth. It runs on minimal charge and low latency. Can’t transfer large amounts of data at a time but if you set up a automation triggered to pull at certain times throughout the day it can pretty much act as a monitor of your data flow building a entire investigation of your every move.

creepy?? **** yeah and I’m still stuck and without control over my own privacy and I can’t communicate normally because of it. It has really taken over my world and it is disgusting!


I don’t understand why it is happening to me personally either. I want to know if anyone with same experience has found more of us struggling with this and if there is a forum.

I can post some screenshots as well


Mar 1, 2024 3:04 AM in response to Katefromouterspace

Hey “Kate from space”! (since this thread doesn’t seem to connect) I shouldn’t comment much but yes. I think these are variables that could be useful to this problem that people are having. Especially given the IOT components at home and given corporate governance being weakened by WFH networks. I’ve been concerned about my own privacy issues lately not from my small business given the current problems, let’s just say. Possibly a lot of cross play here.

May 17, 2024 7:56 PM in response to AgentDragonfly

Me too! All of the above. And they use Xcode & DT tools to make “user” & bundle versions of my apps to manipulate the settings that I can change. Use a lot of open source software. I believe that somehow they’re using my biometrics because sometimes my face scans only when I open up settings altogether. Which I’m sure they’re using somewhere else. Whenever I use screen time settings for and need more time, it always asked me twice. Like there is two screens. I find that it’s being mirrored to a PC and doing all kinds of things and has known about this since, November September 2022 and can’t get any help. Scary. The police said I called out over 10 times because they were coming. My home also only advised me to make a IC3 complaint. Which I made one back in 2022 and took screenshots of it. It made another in 2023 and that pages are different. Every site I visit is different than it should be, be acceptable. We spend on these devices and for their service just for people to steal them and have more access than we do.


also, if you have T-Mobile and it says in cellular settings that your plan is whitelist and regular usage. That means it’s only tallying and adding up the usage that is not streaming. So that is an in accurate amount of data it shows used. I went from 182 GB which I never used anywhere close the month before it turned to white and regular and then it went back to normal around 50.

May 27, 2024 5:07 AM in response to AgentDragonfly

Also, whenever I reach my screen time limit and I choose to remind me in 1, 15, or all day, I have to give the permission twice. Like I’m giving 2 screen’s permission.


My Reminders App is out of date apparently and not giving me the option upgrade it like apple support online suggests. Using the out of date apps means out of date security updates and features. I got the following error: The creator of this list has upgraded these reminders.Learn more here Upgrading the Reminders app in iOS 13 or later - Apple Support


Asking here bc it’s too early to get the call center & they representatives don’t know anymore than the same info I can look up on here. It looks outdated as well.

Jul 25, 2023 6:49 AM in response to T3ddy19

T3ddy19 wrote:

It does not remove it from your iphone. A subpoena tells you who/what/when/where. Based on state, you might be able to get a subpoena from the sheriffs dept, or DIY, I don’t recall saying court? It’s not taking someone to court. You could get a restraining order (and request removal). The details would show who installed it.

All of that is pointless if you don't know who installed...whatever it is you think was installed.


I was also not aware Siri could do such things, I tried it myself with no results, but the search showed in history? And, Siri does provide web searches, since it was done, yes it can if you have the skill.

No, you can't.


what helpful info have you provided on how to remove the MDM?

Start here:


Install or remove configuration profiles on iPhone - Apple Support


Or, do this:


Restore your iPhone, iPad, or iPod to factory settings - Apple Support


I thought you requested help, as others have.

I most certainly don't need the type of help you do.

Aug 6, 2023 6:07 AM in response to Community User

Same same Same here. EXCEPT: I am NOT an employee yet constantly have indicators or error messages for my administrator! The suspect had been already into my devices to track and monitor me ( for 0 reason other than he was reflecting). 3 years. Right down to the printer. Police called me delusional but I’m not giving up.

my question is this.. what do you do when your Apple accounts been taken over and the device it’s linked to remotely reset to iTunes by itself overnight.

have I really lost all my pics of my babes growing up and personal information? The account is still active but I can’t get the 2FA. The login info has been changed about three times. Twice to emails and numbers I had never seen or used. Now when I try to recover it it back to the original login but can’t get the 2FA pin to change password. When I call support they can’t give me info as the account isn’t in my name?! 😢

Right now 2FA is the devil when phones been cloned or SIMSWAPED or hacked via your internet provider router, that had a reset secure password. Infected phone infected the router and the printer I’m thinking. Still no police will investigate my evidence , which is very incriminating for this horrible person who’s made me part of their business to stalk me after leaving the marriage. How do I get support through apple business when I’m technically not associated with a school or business account?? I’ve been trying everything but I do t know the domain name. And apple support sees me as a regular customer. Help!

Aug 9, 2023 3:00 PM in response to bct1

Did you have any luck with the sheriffs department? I’m not always 100% correct, but trying to help others and get help. I’ve found a MANAGED Wi-Fi hotspot that resolves to Apple based on IP, it seems to be running most of the time, but in particular when I do anything. I don’t have (or should say I never purchased a hotspot! Since it’s managed, I can’t delete it! Several other things pop up and say “you can’t do this on a managed device”. I read on Apple that the the hotspot is an additional “feature of the MDM. Also, per MDM Apple documentation, some options and things I’ve experienced are hidden headers and footers on Web Sites and email (you can’t see the actual sender of the email). Apparently, the MDM uses “web clips” to filter and prevent seeing this data. Try going to a public computer, sign into your email, then “view source”. Mine was redirected to a created page that appears to use JavaScript. Many features were hidden, like deletes of password resets to Apple and other accounts. Lots of hidden apps are downloaded, remote access, now more, about 4, 2 banking apps, one screen recorder and print screen capture, one complete control of your network and everything on it, many more apps. I was in IT Security for a long time, I’ve never seen anything like this before.


I had someone install an MDM before while I was in the hospital, I found the vender name using a Windows device, it was removed right away. But not this time. The MDM link even includes a “HIDE” option. Since it includes a Wi-Fi hotspot, firewall rules are bypassed. AT&T had an attack a while back where employees were installing “hotspots” on victims. I’ll see if I can find that article, can’t put links on here, but can provide search terms.


based on what I’ve experienced and read, it’s likely someone you know, they only need your PIN and hands on for a few minutes. Once it’s on one device, it can remotely installed to almost everything, all computer types, certain TVs and much more. I’ve attached 3 pics. So what to do? The only thing I can think of is to get a new device and install a similar MDM before you bring it home. I’ve not tried this yet, so I’d try it with something new. It gets on Android as well, so that won’t help. Or, get a subpoena and see if you can get a restraining order. Be careful when asking for data to make sure you get all recent connections to your network, device name, serial number, user name and Apple ID. I really wish Apple would help. I’ve read the Sheriffs Dept can issue a subpoena, but that’s based on state. I’m not 100% certain if it has to come from an attorney? I’d really rather not have to hire an attorney. I have 2 missing Apple devices, I know who had them, but they also use a Mac to go into the iCloud and download and share apps. They also use Family Sharing and Bluetooth. They connect via hotspot, then can connect up to 8 devices using Bluetooth. They also use the clipboard to collect data (under shortcuts and using scripts, mostly JavaScripts but other as well. Even when Wi-Fi shows as off on the first page, it’s still on. Once data is collected, I’ve seen it texted or emailed (using my address!), also under shortcuts and scripts. Anything I’ve tried to cut off Bluetooth or Wi-Fi hotspot works for a little while, then turns back on again. I have a Wi-Fi detector, but just keep it off most of the time due to constant beeping indicating Wi-Fi! The battery runs down quickly, and the cell signal drops from 4 bars to 2 bars. At one point, there were 87 scripts on my phone. I don’t have data on here, no fascinating life, and it keeps escalating. IC3 (gov) is very interested in this topic. I’ve yet to report the suspect, hoping they will stop, but it just gets worse.



Jun 1, 2024 9:50 AM in response to AgentDragonfly

I have the same thing for 3 yrs whether it’s a android or apple and factory reset doesn’t work so tired of ppl saying apple can’t be hacked and we have no business looking at system logs I don’t understand everything but I do know how to copy and paste


3 times I factory reset my phone and there are calls and messages still on phone camera light on when I’m not using my phone settings change cant open camera or certain apps says there are restrictions


[Edited by Moderator]

MDM on personal iPhone - Businesses, unauthorized developer activity HELP!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.