Need Help iPhone 15 Hacked

Hi. I received a replacement iPhone 15 from my carrier. It was refurbished.

It sounds very staticky at times. Once, it sounded like a fax machine.

Someone is currently trying to hack into my Proton Mail Account. I can see them being denied access repeatedly because I have lock protection on it.

The Proton’s email application logs, show that they are using saved passwords. It also shows entries related to KCF Network. I searched what I found online and it comes up that it is related to Apple.

I have location services disabled. I do not share messages, pictures, etc. My iPhone analytics reads location services disabled, opt in third party “true”. It also reads that automatic sharing is enabled for messages, pictures and Safari. I also notice 3-4 device Ids in analytics on the same day, basically at the same time.

Does anyone know if multiple device ids are normal? I do not connect my phone to any devices. Does anyone know why automatic sharing would be in analytics if I don’t have it showing that way in the phone?


iPhone 15, iOS 17

Posted on Jun 26, 2024 10:39 AM

Reply

Similar questions

6 replies

Jun 27, 2024 12:38 PM in response to iPhone15Hacked

You will never learn anything useful from the analytics. They are only intended for use by Apple engineers. They take special training and software to interpret. Without that training, things that are innocuous can seem scary.


What you can do is run a Saftey Check. See here:


Use Safety Check on iPhone to stop sharing and secure your account - Apple Support


Personal Safety User Guide - Apple Support



Jun 26, 2024 10:57 PM in response to iPhone15Hacked

If you feel an unauthorized person/app is remotely using, controlling or monitoring your device, then that is possible only if you have done one or more of the following Don'ts...


  1. Don't hand over an iPhone to kids or to a stranger without Enabling Guided Access
  2. Don't share Apple IDs
  3. Don't Jailbreak
  4. Don't share sensitive information pertaining to your device
  5. Don't give in to Phishing
  6. Don't plug in your device in Airports and Public places through third-party cables and trust the device. Beware of Juice Jacking. (Especially in India)
  7. Don't leave your iPhone unlocked and unattended in public places like offices, schools, malls, etc.


If one of the above is true then quickly change the Apple ID Password and Return iPhone settings to their defaults.



Keep the iPhone updated to the latest iOS always and never Jailbreak. That's it.


iOS / iPadOS devices cannot be hacked or infected with Virus / Malware / Spyware *** unless you have intentionally downloaded spurious software or unauthorized apps directly from the internet and installed them on your device or/and have Jailbroken


It (Hacking) also depends on how careful you are in sharing sensitive and valuable information pertaining to your iPhone such as Passcode, Password, etc with your friends and family members.


Be judicious when sharing the device's sensitive and valuable information with friends and family members.



**The primary reason for this is Sandboxing. All third-party apps are “sandboxed”, so they are restricted from accessing files stored by other apps or from making changes to the device. Sandboxing is designed to prevent apps from gathering or modifying information stored by other apps.


Security of runtime process in iOS and iPadOS - Apple Support



The sandbox on an iPhone is a security feature that creates a restricted environment for each app to run in isolation from other apps and the operating system. It is a core component of iOS's security architecture and plays a crucial role in making iPhones more secure.



If you doubt the authenticity of the information provided earlier, you have two alternatives:

  1. Report the hacking incident to local law enforcement authorities and actively pursue the case.
  2. Accept the credibility of the information; it is impervious to hacking. Just as some individuals hold unconventional beliefs, such as a flat Earth or moon landing denial, one has the freedom to believe in anything. The choice ultimately rests with you in this open and free world.


Jun 27, 2024 12:03 PM in response to SravanKrA

I’m not sure what could have happened to the device, but I’m almost 100% sure that nobody had physical access to it during my ownership.


when I first got the device, I remember seeing something that read ATT/Apple Bootstrap in analytics. ATT is not my carrier.


Maybe this refurbished device is defective or was compromised prior to my receiving it.


I was EXTREMELY careful with this device. I have it on lockdown mode. I only have a handful of needed applications and rarely connect to WiFi. I have location services disabled.


Up until a few days ago, my analytics read location services disabled, opt in 3rd party “true”. It now reads false. It read true for a very, very long time.


As far as the sharing goes, this is from my analytics:


activeiMessageUser":1,"automaticSharingEnabled":2,"musicAutomaticSharing":false,"newsAutomaticSharing":false,"photosAutomaticSharing":true,"podcastsAutomaticSharing":false,"safariAutomaticSharing":true,


Nowhere in the device can you see that these items are being shared.


I can’t copy and paste from my email logs to show the KCF Network entries (research leads me to believe that this is Apple related) in my email account or the statements about using my saved passwords.


This is from my iPhone analytics showing just two of the many device ids:


deviceId":"3d9c6eaa7bed53a105c8db65bbbea383ad523a56","message":{"Count":719,"isSupported":true,"language":"en"},"name":"SafariTrafficDistribution_highersampling","sampling":100.0,"uuid":"132de8ce-535e-49a5-9c7b-ae00ea1949d1_2"}

{"deviceId":"e9c28ee867fca35b585c1b11187b5a691840c469","message":{"Count":7,"daily_total_numOfFetchesPerDay":0},"name":"UT_AISFetch_CountPerDevice","sampling":100.0,"uuid":"13ab465c-27c3-467d-a166-ee005ed5184e_4"}


I think I will take the device to an Apple Store and have them remove and reinstall all of the software and change my passwords, etc.


I’m concerned about how to prevent such a thing from happening again.


Thanks for all of your responses. They were much appreciated:)




Jun 27, 2024 12:07 PM in response to iPhone15Hacked

rolloverReason":"scheduled","servingCarrierName":"Verizon US","startTimestamp":"2024-06-26T00:00:00Z","stateDbType":"sqlite","stateDbVersion":3,"trialExperiments":"2","trialRollouts":"2","version":"2.4"}

{"deviceId":"3d9c6eaa7bed53a105c8db65bbbea383ad523a56","message":{"Count":1,"activeSMSUser":0,"activeTreatments":"100:210304_control,101:210415_control,102:210304_control,103:210304_control,105:210304_control,106:210304_control,107:210304_control,104:210304_control,108:210601_control,109:20419_control","activeiMessageUser":1,"automaticSharingEnabled":2,"musicAutomaticSharing":false,"newsAutomaticSharing":false,"photosAutomaticSharing":true,"podcastsAutomaticSharing":false,"safariAutomaticSharing":true,"tvAutomaticSharing":false},"name":"SocialHighlights_SettingsStatus_v1_boolean","sampling":100.0,"uuid":"


Sorry! It didn’t all appear when I first posted.

Jun 28, 2024 6:47 AM in response to SravanKrA

Question, if you can answer it. I changed the passwords on a couple of my apps. I could see from the application logs that whoever hacked my vpn and is trying to hack into my email was having difficulty accessing the accounts for a bit. I did not save the passwords in my iPhone. I do believe that they got into my vpn again and that they are stuck at the same place they were at prior to me changing my mailbox password. My question is about device ids. Should there be multiple device ids showing in analytics on the same day? I believe that there are approximately four in mine. I’m not sure if this is related to the issues that I am having. Today, I noticed that some of the settings in my iPhone were changed. I’m almost 100% certain that this phone was not compromised by anything that you have listed during the time that I have owned it. Other than what I have previously written, the only other thing that seems odd to me is in analytics, sometimes my primary network interface is cellular and sometimes, it is listed as “other”. It should always read cellular. I’m at a loss as to what happened to my phone. I know analytics aren’t made for the consumer. I guess my only option is to have the Apple Store remove and reload the software. If that doesn’t work, I guess I’ll purchase another phone. I just want to know how I’m supposed to make sure something like this doesn’t happen again.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Need Help iPhone 15 Hacked

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.