You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

MDM on personal iPhone - Businesses, unauthorized developer activity HELP!

I am a personal 'User' I have cycled through many hours and days with support. No one knows what is going on. Most likely because I am never able to speak with someone that understands the Enterprise platform. I feel this is happening via my carrier- but Fraud sent me to Tech support. Tech support told me my phone is hacked and to file a police report.

In combination I suspect that MDM is a gateway for an external developer to access my phone via various methods: webkit, Xcode, Apple Store Connect, SDK

I am about 99.99% sure I know why, but that is something that I will not disclose because most likely all of my activity is monitored; despite the very strict privacy settings I try to maintain.


Symptoms:

  1. My apps will sometimes tell me they did not come from the App Store (Maps, FindMyiPhone, etc..)
  2. When I make an attempt to chat with Apple support I receive a message to Use Messages to Connect with Business. When I have my iPhone in LOCKDOWN mode I receive a message that I cannot use Messages for Business when my device is locked down.
  3. I only have one device. However, I am sharing across devices- many times or I have the option to. The choice is not grayed out.
  4. I am unable to perform an Emergency Reset because I am usually sharing something - Notes, Home, Health, Books....
  5. I do not use iCloud Drive due to multiple security concerns. Almost every time that I double check those settings apps show that they are using iCloud Drive. (Game Center, Health or Fitness, Notes, Books, Apple Support, Wallet) While clicking to turn OFF syncing I have had a battle with it changing right back before my eyes. (I have screen recordings)
  6. Game Center will come on even though I have strict Screen Time settings.
  7. I am generally either sharing, or my phone is gathering data from Health; even though that privacy option is supposed to keep that from happening.
  8. Sometimes I am unable to even sign out of my phone due to 'restrictions'.
  9. I have 'Share with Family' sometimes

*Those are only a few symptoms. That is minus the horror I see from the extraction of information I backed up into Kali Linux

As I have mentioned I have spent many many many hours with Support. One Senior Director did spend time Googling the services that show up in my Analytics. I have even uploaded screen shots and documents, but I never heard back.

I REALLY REALLY need help here.

I will add attachments. They won't be nearly the amount I have. I am begging!!!



iPhone 13, iOS 16

Posted on Apr 2, 2023 2:32 PM

Reply
Question marked as Top-ranking reply

Posted on Apr 3, 2023 6:45 AM

Sadly, there doesn't seem to be any help and the ones that will respond, will tell you you are either crazy or you can't be hacked unless you have your device to someone.


For what it is worth I have been dealing with this and here is what I have learned; you need to delete your old apple id's and confirm that they are deleted. You may not be logged in to any (neither was I) but it has something programmed into the IOKIT boot so you cannot reset the NVRAM properly, leaving find my process to look as if the activation lock is on.


Make appointments for each apple product to have a firmware/software update through DFU mode and make sure it is DFU because a factory restore will not remove the cache that is lingering in the files. This should all be done at the same time otherwise it will talk to the other device and reestablish itself.


The factor reset you are doing doesn't work because it does not empty the trash and it seemingly blocks any terminal command to do so as well.


Before you boot up your computer(s) & phone(s) delete and confirm you have deleted all of your previous apple id's. Write down the code it provided to delete the id because chances are you will have to call to

confirm its deletion.


If you have a google ID, check to see if you are enrolled in any trial based workspace or fire base programs. Workspace allows device control as well.


I have changed our TV's and printers but it still seems to latch on to any printer so now we do not print. Debilitating to say the least.


I believe that there are enough of us out there to confirm that this problem exists but apple will not respond until they have fixed it. I know it sucks. Two factor everything and I wouldn't suggest any external usb or thunderbolt security keys.


I also would not suggest any products other than apple. That will only make your situation worse.. even the keyboards because it will load a generic driver onto your device. Only use apple wires as well. I am definitely not an apple advocate, only sharing what I have come to accept and learn.


You may have to go line by line in settings on your iPhone to turn off everything that you do not use and if there is an arrow on it, click to make sure there is not an opportunity to bypass your defaults. The Mac computer is the same and there are probably about 100 Plists that will try to alter your default settings so do not take anything for granted until you have clicked through it all. Plists are just preference and apple will tell you that it does not mean that they are being used. That is absolutely correct but the Plists I have seen start with NVRAM and a fmm (find my

mac activation) which is huge problem.


for whatever reason it uses nfc and mdm BUT mdm does get removed later on during the process. It keeps respawning. So it isn't necessarily MDM as much as it is trying to be so I presume that there is some detail in the MDM program that helps it get what it needs.


The shared cache you are seeing is at best guess, all of the info it has collected on you and will keep looping together. This is just a guess but I have been watching it on mine as well. I could 100 percent be wrong but I believe the cache is what keeps this process communicating between devices.


There are enough of us out there with this problem. I am sure that we have a common thread but I have no idea what it could be. I just know that no one is going to help me or my family and I am just going to have to do my best to keep my kids safe.


I could bring a new computer into this house and within ten minutes watch it try to harvest my old apple ids, while Bluetooth sniffing and try to connect to something nonstop. Eventually, it gets back in and the new id becomes corrupt, I delete it and start again hoping the last apple update resolved this issue. Two years later and I am headed back to the Apple Store today to pick up a couple of devices.


I wish someone had better news for the both of us but this is the best advice I can give you.

Similar questions

160 replies

Nov 8, 2023 9:56 PM in response to JMurphyCO

Hello…did you ever find a solution? I have gone through an iPhone15 (direct from Apple, an IPhone 12. (wiped and reset), a Samsung AOS, a Motorola Pure G, 3 carriers, a windows 10 PC, they have hacked 5 Gmail accounts (also my Apple IDs) and (2) other emails. If that wasn’t bad enough they are spoofing me. They are answering my calls pretending to be me and intercepting outgoing calls and pretending to be tech support for my carrier. I am being served web pages in French. Web pages with errors. I’m also always showing up in New York as my location. They are constantly in my iCloud account doing things like disconnecting my eSim, leaving creepy photos of me. I basically can’t live my life because I’m always trying to get unhacked. My theory that ties all these things together is a Stingray or Dirtbox. They also hacked my ADT panel. I found a known WiFi network that I have never signed into. I never sign into WiFi. Then on my other iPhone I found the same network and D-link. They are constantly using my devices, doing things like downloading music. My PC is terrifying. I think I may have figured out how they exploited it.


Any advice? I can’t trust anything.

Nov 8, 2023 10:10 PM in response to Park3rr

I posted to someone earlier. I 100% think it’s a Stingray or Dirtbox. I don’t even have the energy to go through everything they have destroyed. They have completely stolen my identity and have done things like set up accounts using my name and number. I’m being hacked, spoofed, phished and doxxed. I actually think my Pc is the source of hacked passwords. Did you ever get anywhere with this?

Nov 9, 2023 5:35 PM in response to EllieDolanStl

I guess my last post was deleted. I feel like I have found “my people. I’m compiling all my issues for everyone; FBI, FCC, FTC, local law enforcement. Sorry for all the posts but I feel so much better knowing that I am not alone. See earlier post for how many devices and carriers I have been through. I’m not entirely sure what exploit everyone is taking about but literally can’t function on any of my devices. I realize the implications of what is happening and how companies are going to try to cover this up but I feel obligated to go public. This is the craziest thing I have ever seen. I could definitely use some more explanations of what everyone thinks is going on (in plain English). My last post was asking about everyone’s location. Im asking because I am almost 100% positive that a Stingray or Dirtbox is being used since I am also being spoofed, combined with the this exploits that take over so quickly. I mean I’m spending all my time fighting this. It’s so unbelievable I keep thinking it’s a joke or test or something other than a stalker (which I definitely have). Can someone please reach out to me to explain what they think the exploit is in as plain language as you can. My PC I swear was being used as a mini server. I watched all these people log in an out one night. They used my name and number to set up fake accounts. Seriously, I cant make a call, they pick up, I can’t send an email, they have the password to all of my accounts, I got through to the FCC but only because it was a form. I would like reality back. I want to know who I am taking to is who they say they are. I don’t want to have to guess if someone emailed me and it got deleted. Help!!!

Nov 17, 2023 6:48 AM in response to AgentDragonfly

Omg I’ve been going through this for 5 years there is so many of us with the exact problems, every phone laptop MacBook router cctv gaming console

multiple ids sims esims Carriers internet providers

im not sure if a combination of stingray and Iot or separate

but have now found iot core version os on my home version pc just to get the mdm privilege so looks like I’ll be searching for a clean device to dfu my 14 pro for a few days peace.


I’ve only replied to add a me too in hopes someone figures it out,

or at least 1 more to add backup for a support call to lose 2 hrs of your life you won’t get back

I’ve lost more than a day over the 5 years and the last 1 was to go to the police, who directed me to a cyber tech for concrete proof ($800/hr was the best quote I got)


Feb 26, 2024 11:22 AM in response to achoo274

I apologise for my spelling mistakes I didn’t have time to do spellcheck I’ve got that blue recording microphone that’s supposed to be dictation. I’m pretty sure it’s a whisper product made by chat gpt. I saw a little symbol on it earlier year last year. I saw the same symbol over at the chat GPT site. The bast-rds keylogger. I don’t bother calling Apple anymore. Sometimes it but most the time it’s not.

Do you know that they mimic logging into my bank? Spoofed and made it look like a bank.

My friend that had this happened to her she says it’s not a bank it’s not a bank usually she doubts me , So I don’t believe anything anymore.


This just isn’t right. I feel pretty alone. The people in town here that this happened to have lost contact with them because my phone got stolen from the bottom level huge group.


I don’t think people understand the fact that it takes six times longer to do anything but that you’re doing something it undoes other things.


2023 I was supposed to go to school, while dealing with my health crisis.


there is no Apple Store here, I have no second device, I have got it cyber cleaned. I had to pay to get it cybercleaned. I’ve changed my Sim card I’ve begged my cell phone provider to help, I’m said to them ; do not think it’s weird that I have 78 GB used of my data and I have the toggle off?

This is theft. Worse. I’ve been saying what this is for over here and I was never talking about any of the stuff before.

This was zero day. I did nothing. I thought I had but I since spoke to the party I thought was the culprit because they have been cloned/ overlays relentlessly.

Even when the advertise doesn’t see.



But they’re all through the Wi-Fi. I got locked out of my phone, I couldn’t call anybody.

I have a landline now I’ll see how long this lasts.


I reported it.


Feb 26, 2024 1:57 PM in response to celliott147

Nothing. But on my Mac air I’ve run the commands (lmsk??? sfltool dumpbtm ps xawww | grep.. ?? I forget) and found MDM (force time and date etc) and there are install logs for random stuff, a little above my head, in the system info, so two cheers for Settings.app. It gets worse since I’ve tried to hire outside help because they always muddle things up with their own stuff instead of just looking into the machine. (I’m suspicious of them now sad:( since I have experienced so many DDOS attacks…)


btw what happens when you got to activity monitor and look for controlCenter>Wifi>network or whatever. Do you have 3, maybe 4 processes running like ControlCenter>WiFi, and (CC>WiFi) and ((WiFi)) and (((WiFi))) & ((((CC>network>wifi)))) etc ?

Feb 28, 2024 10:54 PM in response to T3ddy19

WOW, I've been dealing with this exact same issue for about 3 months now. Every single day has been an emotional rollercoaster and my life has been completely torn apart from this issue. I live in fear because I know that I am being watched and tracked through my devices, and the worst part is that no one believes me. I have had my iPad and iPhone13 disabled by RAT trojans. I got the new iPhone15 and within 10 minutes of leaving the store my device was under attack, little did I know, my bluetooth in my car and my AppleID were the problem....that was before I really started digging and doing my research. When I try to explain what is going on people look at me like I'm talking gibberish, I've been at the point where I have questioned my own sanity, but I've seen the changes happen on the screen!!! Ive contacted every agency out there. I can't even be identified for a credit report with my social security # HELP!!!!!

Mar 1, 2024 3:09 PM in response to katiebeth_19

Hi Katie,


it sounds like your already on the right path with blue tooth and your apple id. If you buy a new phone, dont use any of the old apple ids you have had, be careful of email and sms attacks and most of all, make sure no settings can be changed while your phone is locked / unattended. and of course wifi too, if you haven't check out apple developer programs, basically all they need is your apple ID and device numbers and access to your phone when they have the password. Your in it for the long haul, but don't fret - you'll get there!


J.

Mar 22, 2024 12:26 AM in response to AgentDragonfly

Just wanted to say you’re not alone in this. It’s easy to get paranoid and start to question yourself. It’s good to have doubts. It shows you’re not crazy. But follow your intuition. Try and show grace and compassion to those whose responses are short or dismissive or sometimes downright cruel. It’s intentional. This type of stuff has happened before and now in the age of the internet it’s reached new levels. Get rid of your iPhone. I’m doing the same. I miss land lines and flip phones and dial up computer..

Mar 23, 2024 11:28 AM in response to gravityfed

i've had same issue senior support hangs up on me een sealing with this for 5 years now had 5 brand new iphones quit working an ipad as well support sets up a call from senior advisor i explain issue and soon as i do they hang up on me currently out over 10,000 dollars in brand new personal iphones .hired a private investigator team and all information they have collected goes all the way back to a developer from apple hacking me and trying to blackmail me for 1500 dollars for some reason they tracked the call back to austin texas and next week they are flying there to confront the developer who did this wish me luck this is a major fraud and cyber theft issue and will hopefully end up throwing developer in prison and refunding all my money i've been ripped off for for last 5 years but we will see next week just wish the developer would of came forward on there own and turned themselves in but we will see come next week have documented everything since day one 5 years ago

Mar 23, 2024 11:31 AM in response to T3ddy19

my emergency reset won't work says try again matter several times over last two weeks phone is shareing g info on its own i change settings go to bed wake up phone changes back all by itself it's cyber theft on the highiest level 5 iphones an ipad all quit working within 1/3 month us after purchase and apple senior support hangs up on me after i exsplain what's going on

Mar 25, 2024 9:02 AM in response to Funnyguy52

Funnyguy52 wrote:

i've had same issue senior support hangs up on me een sealing with this for 5 years now had 5 brand new iphones quit working an ipad as well support sets up a call from senior advisor i explain issue and soon as i do they hang up on me currently out over 10,000 dollars in brand new personal iphones .hired a private investigator team and all information they have collected goes all the way back to a developer from apple hacking me and trying to blackmail me for 1500 dollars for some reason they tracked the call back to austin texas and next week they are flying there to confront the developer who did this wish me luck this is a major fraud and cyber theft issue and will hopefully end up throwing developer in prison and refunding all my money i've been ripped off for for last 5 years but we will see next week just wish the developer would of came forward on there own and turned themselves in but we will see come next week have documented everything since day one 5 years ago

There appears to be something wrong with your keyboard. The period key only seems to have worked once and there are no capitals at the beginning of sentences. This makes your post very hard to understand.

May 27, 2024 4:50 AM in response to T3ddy19

I, too, have been dealing with this since 2022- that I know of!! SAME THING as everyone else. One thing I haven’t seen mentioned yet (haven’t been through all posts yet) was Virtual Ethernet Connection. Also when I did a whatsmyip search, I was told I was Enterprise Hosting. Someone tried to tell me it’s bc Apple is the enterprise 🙄. Also, a lot of it doesn’t necessarily go to MDM, I’ve found more to point me towards a Educational/School Managed Device, def some with Microsoft excel, edge, I could go on for days when it comes to PC. I’m sure there are many more but here’s a few I hadn’t seen mentioned.


Oh! There’s something with SOS mode. I’ve been locked out devices and they were stuck on SOS mode- when they still at cellular service.


It’s awful. I could write a book with all of the negative consequences to this but the biggest for me going through something so devastating and not having the support of loved ones. Bc if they don’t understand it, it can’t be real. Especially bc they consider themselves to be so much better. Their ego gets in the way. Makes you feel very isolated and alone Wish this would allow me to post my personal info bc I would love to talk to you all outside of the community. Compare notes and offer support.

MDM on personal iPhone - Businesses, unauthorized developer activity HELP!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.