iPhone security concerns after clicking link during scam call

I recently fell for an AI investment scam.

When I realised it, I cancelled the payment card, and have blocked all further contact with them. No money has been lost.

Part  of the scam was a 55 minute phone call during which I was invited to click a link to view my account operating.


My question is this - during my ‘visit’ to my account could my phone have been hacked? 

  • Could something have been installed on my phone?
  • Could data, address book, contact list have been sucked out of my phone?
  • Could access be gained to read my emails?
  • Could the contents of files in the Files app have been accessed?
  • If I took my phone into an Apple shop could they check the phone for malware?

I have spoken to Vodafone, my phone service provider, they looked at the phone and said all appeared clean.

I’ve also used as many of the *# codes as I can find to check on Call Forwarding etc.


I’d appreciate any answers to my questions

Best regards

Jim

Posted on Aug 14, 2026 11:42 PM

Reply
Question marked as Top-ranking reply

Posted on Aug 15, 2026 2:56 AM

As a first step, simply perform a forced restart of your iPhone - as this will ensure that any potential memory resident exploit, that might attempt to exfiltrate data, is purged from the device:

Force restart iPhone - Apple Support


Providing that your iPhone has been kept up-to-date with system software updates, you should not be overly concerned for your iPhone being directly compromised by malware. Due to the sandboxed system architecture of iOS, unless jailbroken, your iPhone is not susceptible to traditional malware infection per-se. However, as with all computer systems, there are still vulnerabilities and exploits to which you remain vulnerable.


For older devices, no longer benefiting from regular security updates, the risk of an unpatched vulnerability being exploited increases. Regardless of the installed version of iOS, there are useful mitigations that can be used to significantly reduce your exposure to risk.


If necessary, change any account passwords (including your Apple Account/AppleID Password) that you suspect may have been compromised. If you have cause to believe that your Apple Account has been compromised, follow the advice outlined here:

If you think your Apple ID has been compromised - Apple Support


If you remain concerned that the iPhone itself may have been compromised, for your peace of mind, you might consider consider restoring your iPhone to factory settings. Before doing so ensure that you have a backup of your data and files - and then

How to back up your iPhone, iPad, and iPod touch - Apple Support

Restore your iPhone, iPad, or iPod to factory settings - Apple Support


After restoring to factory settings, you can restore your backup to your iPad:

Restore your iPhone, iPad, or iPod touch from a backup - Apple Support



Threat Mitigation


Other than malicious websites that will attempt to capture information that you willingly enter, the majority of threats to which you will be invariably exposed will surface via web pages or embedded links within email or other messaging platforms. Browser-based attacks can be largely and successfully mitigated by installing a good Content and Ad-blocking product. One of the most respected within the Apple App Store - designed for iPad, iPhone and Mac - is 1Blocker for Safari.

https://apps.apple.com/gb/app/1blocker-for-safari/id1365531024


1Blocker is highly configurable - and crucially does not rely upon an external proxy-service of dubious provenance, All defensive processing by 1Blocker takes place on your device - and contrary to expectations, Safari will run faster and more efficiently.


Unwanted content is not simply filtered after download, but instead undesirable embedded content is blocked from download. The 1Blocker product has also introduced its “Firewall” functions - that are explicitly designed to block “trackers”. Being implemented at the network-layer, this additional protection works across all installed Apps. Recent updates to 1Blocker has introduced additional network extensions, extending protection to other Apps.


A further to improve protection from exploits is to use a security focussed DNS Service in preference to automatic DNS settings. This can either be set on a per-device basis in Settings, or can be set-up on your home Router - and in so doing extends the benefit of this specific protection to other devices on your local network. I suggest using one of the following DNS services - for which IPv4 and IPv6 server addresses are listed:


Quad9 (recommended)


9.9.9.9

149.112.112.112

2620:fe::fe

2620:fe::9



OpenDNS


208.67.222.222

208.67.220.220

2620:119:35::35

2620:119:53::53



Cloudflare


1.1.1.1

1.0.0.1

2606:4700:4700::1111

2606:4700:4700::1001



Security focused DNS providers intentionally "sink hole" known bad or malicious websites and resources - this providing an additional layer of protection beyond that provided by your device and its Operating System. These DNS services will, when used alongside 1Blocker or other reputable Content Blocker, provide defence in depth.


Due to the character limit for posting here, I'll continue describing Threat Mitigation in a second reply...


13 replies
Question marked as Top-ranking reply

Aug 15, 2026 2:56 AM in response to SixtiesSailor

As a first step, simply perform a forced restart of your iPhone - as this will ensure that any potential memory resident exploit, that might attempt to exfiltrate data, is purged from the device:

Force restart iPhone - Apple Support


Providing that your iPhone has been kept up-to-date with system software updates, you should not be overly concerned for your iPhone being directly compromised by malware. Due to the sandboxed system architecture of iOS, unless jailbroken, your iPhone is not susceptible to traditional malware infection per-se. However, as with all computer systems, there are still vulnerabilities and exploits to which you remain vulnerable.


For older devices, no longer benefiting from regular security updates, the risk of an unpatched vulnerability being exploited increases. Regardless of the installed version of iOS, there are useful mitigations that can be used to significantly reduce your exposure to risk.


If necessary, change any account passwords (including your Apple Account/AppleID Password) that you suspect may have been compromised. If you have cause to believe that your Apple Account has been compromised, follow the advice outlined here:

If you think your Apple ID has been compromised - Apple Support


If you remain concerned that the iPhone itself may have been compromised, for your peace of mind, you might consider consider restoring your iPhone to factory settings. Before doing so ensure that you have a backup of your data and files - and then

How to back up your iPhone, iPad, and iPod touch - Apple Support

Restore your iPhone, iPad, or iPod to factory settings - Apple Support


After restoring to factory settings, you can restore your backup to your iPad:

Restore your iPhone, iPad, or iPod touch from a backup - Apple Support



Threat Mitigation


Other than malicious websites that will attempt to capture information that you willingly enter, the majority of threats to which you will be invariably exposed will surface via web pages or embedded links within email or other messaging platforms. Browser-based attacks can be largely and successfully mitigated by installing a good Content and Ad-blocking product. One of the most respected within the Apple App Store - designed for iPad, iPhone and Mac - is 1Blocker for Safari.

https://apps.apple.com/gb/app/1blocker-for-safari/id1365531024


1Blocker is highly configurable - and crucially does not rely upon an external proxy-service of dubious provenance, All defensive processing by 1Blocker takes place on your device - and contrary to expectations, Safari will run faster and more efficiently.


Unwanted content is not simply filtered after download, but instead undesirable embedded content is blocked from download. The 1Blocker product has also introduced its “Firewall” functions - that are explicitly designed to block “trackers”. Being implemented at the network-layer, this additional protection works across all installed Apps. Recent updates to 1Blocker has introduced additional network extensions, extending protection to other Apps.


A further to improve protection from exploits is to use a security focussed DNS Service in preference to automatic DNS settings. This can either be set on a per-device basis in Settings, or can be set-up on your home Router - and in so doing extends the benefit of this specific protection to other devices on your local network. I suggest using one of the following DNS services - for which IPv4 and IPv6 server addresses are listed:


Quad9 (recommended)


9.9.9.9

149.112.112.112

2620:fe::fe

2620:fe::9



OpenDNS


208.67.222.222

208.67.220.220

2620:119:35::35

2620:119:53::53



Cloudflare


1.1.1.1

1.0.0.1

2606:4700:4700::1111

2606:4700:4700::1001



Security focused DNS providers intentionally "sink hole" known bad or malicious websites and resources - this providing an additional layer of protection beyond that provided by your device and its Operating System. These DNS services will, when used alongside 1Blocker or other reputable Content Blocker, provide defence in depth.


Due to the character limit for posting here, I'll continue describing Threat Mitigation in a second reply...


Aug 14, 2026 11:50 PM in response to SixtiesSailor

Mere clicking on a link received during a call, message, or text conversation does not automatically make an iPhone vulnerable. In most cases, simply opening a link will only take you to a webpage. A device generally becomes at risk when a user is tricked into sharing sensitive information such as Apple ID passwords, banking details, verification codes, passcodes, or installing an unknown profile, app, or configuration.


iPhones have strong built-in security protections, including app sandboxing, code signing, hardware-based encryption, and regular security updates. These measures make common viruses, malware, and spyware infections extremely difficult compared with many other platforms.


However, no device connected to the internet can be described as completely impossible to attack. Sophisticated attacks, security vulnerabilities, or targeted spyware campaigns can exist, especially when a device is outdated or when a user is deceived into giving access. Keeping iOS updated, using a strong Apple ID password, enabling two-factor authentication, and avoiding suspicious links or requests for personal information are the best ways to maintain security.


In normal usage, an updated iPhone is one of the most secure consumer smartphones available, and a simple accidental click on a link does not mean the device has been hacked or infected.


Aug 15, 2026 2:03 AM in response to SixtiesSailor

Thanks a lot, Jim!


For your future reference, please see below.


If you feel an unauthorized person/app is remotely using, controlling or monitoring your device, then that is possible only if you have done one or more of the following Don'ts...


  1. Don't hand over an iPhone to kids or to a stranger without Enabling Guided Access
  2. Don't share Apple IDs
  3. Don't Jailbreak
  4. Don't share sensitive information pertaining to your device
  5. Don't give in to Phishing
  6. Don't plug in your device in Airports and Public places through third-party cables and trust the device. Beware of Juice Jacking. (Especially in India)
  7. Don't leave your iPhone unlocked and unattended in public places like offices, schools, malls, etc.


If one of the above is true then quickly change the Apple ID Password and Return iPhone settings to their defaults.


If a person has ever had your passcode, they could’ve installed something quietly — so the full erase and setting up as new is the safest option. How to factory reset your iPhone, iPad, or iPod touch



Aug 15, 2026 3:14 AM in response to SixtiesSailor

Corollary...


One last item to check. If during your interaction you were prompted to install any remote-access Apps - or clicked any links that may have linked to the Apple App Store - ensure that any such Apps have been identified and deleted from your iPhone.


Scammers often employ installation of legitimate remote access Apps (e.g. Team Viewer Remote Control) to gain persistence on a victims device. If any such Apps were installed during the interaction, it is essential that these are identified and manually deleted from your device.

Aug 15, 2026 2:58 AM in response to SixtiesSailor

Part 2 - Threat Mitigation Continued


There are advanced techniques to further “harden” iOS/iPadOS (such as using DoH, DoT and DNSSEC); while fully and effectively supported by iOS, Apple doesn’t expose this capability via device settings - but there are easy ways to access this functionality. Aside from installing a device-profile from a external device-management system, a really easy way to set and manage DoH/DoT settings is to use a third-party utility App - DNSecure:

https://apps.apple.com/app/dnsecure/id1533413232


This App does exactly what is needed to effectively configure DoH/DoT - and is free to download and install. As an added benefit, this App provides a simple method to change your iPhone's DNS server setting. Many DNS providers are already preconfigured - including Quad9 and Cloudflare that I have already listed above.


Apple has also introduced its Private Relay service for its iCloud+ subscribers - in part employing ODoH (a variant of DoH) as an element of this new functionality. More details of this feature can be found here:

About iCloud Private Relay - Apple Support


In summary, there are many mitigations that you can use to better secure your iPad from malware and other potential threats. A good content blocker, combined with secure DNS and other protections offered by iPadOS can reduce your exposure to malicious links, content and threat actors.


I hope you find this information and insight to be helpful.


Aug 15, 2026 4:00 AM in response to SixtiesSailor

You're very welcome.


Some scammers are becoming increasingly skilled at deception. Even the best of us can be fooled into doing something that we shouldn't. The key take-away, that you yourself have demonstrated, is awareness of the threat - and the ability to recognise (even in retrospect) that something untoward has happened. With the benefit of immediate hindsight, you have opportunity to mitigate immediate consequences.


If you have potentially allowed access to financial or credit card information, don't forget to inform your bank and/or credit card issuer(s). For your own protection, your bank may place a marker on your account to protect against potential fraud - while your credit card issuer may re-issue credit cards with new card numbers.

Aug 15, 2026 4:09 AM in response to SixtiesSailor

Re: “… I thought I was above scamming, but my experience has woken me up …”


We all unfortunately occasionally experience these “wake ups” and find ourselves asking “What was I thinking?”


While there’s nothing really “new” in this article, it’s probably worth a few minutes to re-read as a refresher:


Recognize and avoid social engineering schemes including phishing messages, phony support calls, and other scams - Apple Support






Aug 15, 2026 4:59 AM in response to SixtiesSailor

SixtiesSailor wrote:
LotusPilot,
Thanks for the banking advice.
I cancelled the card used to pay, and visited my branch to check all was well.
The bank employee then marked my account as being a vulnerable old man 🤡🤡


Again, you are very welcome.


While the less technologically adept user is an obvious target, of itself, age is not a determining factor.


Nobody (and I really do mean nobody) is beyond the increasingly sophisticated manipulation and deception techniques used by some of the more adept threat actors. Even Information Security Professionals have been known to be successfully manipulated - prior to triggering the "shields up" response when the threat is recognised either during or immediately after the interaction.


Where compromise is suspected, informing your bank and credit card issuer is key to protecting your finances. Even if money is not directly stolen from you, or fraudulent transactions made, your accounts can be used by threat actors to move money to or between other accounts without your knowledge - such activity only becoming apparent when you receive subsequent account statements.

Aug 15, 2026 6:19 AM in response to LotusPilot

Re: “… your accounts can be used by threat actors to move money to or between other accounts without your knowledge … “


Brian Krebs once published a very good piece on this very point.


i.e. That the highest value was placed on gaining access to — and maintaining that access — an already-established account; and that any gains realized from the target’s own financial info was almost more of an incidental bonus.

iPhone security concerns after clicking link during scam call

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.