Techguru45 wrote:
I noticed the local storage was almost full after 3 months of minimal use - discovered the cause was that business Apple accounts aren't compatible with iCloud hence why the local storage was being utilized instead.
This seems reasonable enough, but is this a work computer or personal computer? Is it managed by your employer? If you have any type of access to the kinds of sensitive materials that you hinted, for either government or industry work of this sort, the entire computer has to be completely separate from personal items. The type of mixing of personal and work IDs and files and accounts is strictly forbidden. Did you really do this?
I switched to using my personal iCloud to address the above - however for some reason the cache continues to load no matter how many times I erase and run a clean install of Tahoe.
So above comments. Also, your clean install has to follow this What to do before you sell, give away, trade in, or recycle your Mac - Apple Support otherwise it will retain vestiges of the old system.
In addition to my Mac randomly crashing, I started noticing regardless of which browser I used, my Mac would redirect me to other countries when trying to access Google.com.
There are innocuous reasons this can happen, it has happened to me after or during travel.
I discovered the remote scripting and shortcuts under the "sharing" section and bizarre behavior such as apps randomly launching (Apple Music, podcasts).
Also not that unusual. Sometimes my Mac launches Music for reasons unknown to me when I connect a dock and external monitor.
found out recently a lot of the caches are hidden intentionally by Apple.
Not sure how this is relevant to "hacking."
I do have access to sensitive and confidential files for my industry in tech and partnerships under NDA and within 24 hours of getting access to those files I received multiple phishing calls and emails from people claiming they were apple support - I reported it to Apple and they confirmed it indeed was phishing attempts.
A number of the things you described above would never be tolerated for an employee with access to those types of files. Phishing is not that hard to mitigate, one has to be careful not to fall for it. But it is very common.
In addition to the above, the ldap and Active Directory seem to have additional entries that look unfamiliar
I don't see this as proof of hacking.
"hackers found a way to make my son the admin of my computer as a workaround to hack into my machine and make me a standard user"
Wait. Your son has an account on your work computer? That is a huge no-no for any government or industry computer with "sensitive files." I am even surprised you are even allowed to do things like that on a computer with such "sensitive" data.
Don't be insulted: but if you gave your son an account on this computer, that is also used for all kinds of sensitive and NDA work, how do you know that your son did not do some of these things himself?
Bottom line: with an internal SSD, if you followed follow this What to do before you sell, give away, trade in, or recycle your Mac - Apple Support and then created a TOTALLY NEW Apple ID with 2-factor and used FileVault to encrypt the drive to use going forward, I do not see how any vestige of past anything would be present on this computer. All settings would have to be recreated from scratch. With strong passwords, 2-factor, and no remote access or sharing of any sort, I don't see how any hacker could get in. Your home network might be a vulnerability but any type of secure work done remotely (off site) for virtually any government or industrial entity comes with a very robust VPN professionally configured by the employer for high security.