How Can an Offline Phone Be Compromised?

How Is This Even Possible?

Look, make it make sense. I factory reset a phone, and before I even hit the screen to sign in or make an Apple ID, the camera indicator light pops on.

Look, make it make sense. I factory reset a phone, and before I even hit the screen to sign in or make an Apple ID, the camera indicator light pops on.

So I skip signing into Apple completely. I keep it off-grid, make a brand-new Proton Mail account, and write the username and password down by hand on a physical piece of paper. No cloud, no saved credentials, nothing.

How the fuck does a setup like that still get compromised? I’m genuinely losing my mind trying to figure out how this is even possible. Anyone got answers?

reddit.com
u/Choice_Caramel138 — 7 days ago
▲ 1 r/theprivacymachine+1 crossposts

Make it make sense: How the fuck is an off-grid setup getting compromised?

How Is This Even Possible?
Look, make it make sense. I factory reset a phone, and before I even hit the screen to sign in or make an Apple ID, the camera indicator light pops on.

So I skip signing into Apple completely. I keep it off-grid, make a brand-new Proton Mail account, and write the username and password down by hand on a physical piece of paper. No cloud, no saved credentials, nothing.

How the fuck does a setup like that still get compromised? I’m genuinely losing my mind trying to figure out how this is even possible. Anyone got answers?

reddit.com
u/Choice_Caramel138 — 7 days ago

Follow up to session hijacking after factory reset

**I’m starting a new thread here to address some of the replies, questions, and comments from my previous post all at once.**
**It didn't start with a clean slate; it started with a full-blown, real-time persistence loop. I walked out of a five-year bid thinking I was finally getting a fresh start, but the reality waiting for me hit the exact second I got home. The device waiting for me was one I had while living with my ex, who had possession of it for a short period while I was away. When I tried to log into the Apple account associated with it, I was completely locked out—it was like I didn't even exist. I later found out that an account using my initials and birthday as the username, tied to my name and credentials, was turned into a** ***developer*** **account. I don't know the first thing about developing apps. Without realizing what I was walking into, I created accounts on that device when I first got home, and that's where the bleed started.**
**Instead of just trying to reacclimate to the real world and restart the business I had before I left, I walked straight into a nightmare. If you’ve never sat there watching a live session get actively hijacked while you’re in a literal tug-of-war match—revoking cookies, logging back in, watching recovery options magically shift underneath you, and repeating that cycle for hours straight—people think you're making it up. But when your session tokens are compromised and an attacker has persistent hooks or an infostealer lurking in the background, normal security logic goes out the window.**
**Here is what my actual cross-platform nightmare looked like the moment I got home:**
**1. The Session Tug-of-War & Cookie Hijacking: When an attacker has your session cookies or is actively side-jacking your traffic, logging in normally or clearing a basic cache doesn't cut it. Every time I invalidated tokens and locked it down, if the underlying endpoint or environment wasn't completely nuked and rebuilt from scratch, they stepped right back into the stream. That’s why I ended up in a live ping-pong match where recovery options and settings flipped back instantly—I was fighting an adversary who was mirroring my moves in real-time.**
**2. The Google Workspace & Admin Console Ghost-Suspensions: Trying to restart my business meant managing my custom domains and Workspace, only to experience the absolute horror of looking at my own admin console and realizing my Super Admin status or main account had been silently flagged, suspended, or hit with automated restrictions for sending out outbound phishing/spam links that I never touched. Why did this happen? Because once an adversary compromises administrative footholds or manipulates session layers, they abuse your infrastructure to blast junk, triggering automated safety blocks that lock you out of your own house while keeping their backdoors greased. Notifications get toggled off behind the scenes so you are completely blind to the automated hits until the damage is done.**
**3. The Bot-Flagging & Platform Loop (X, Grok API, & Beyond): Moving across platforms like X or dealing with API key revocations added another layer of psychological torture while I was just trying to get back on my feet. I got flagged as a "bot," forced into endless verification loops, or hit with captchas because the compromised ecosystem bleeding out from my primary footprint was throwing red flags everywhere. It created a cascading failure across every service I touched—from domain management to social and AI API keys—making it look to automated system filters like I was the threat actor on your own network.**
**4. The Personal Element & Targeted Harassment: Six months home from a five-year bid, trying to re-acclimate, restart my business, and dealing with lost communication with my ex—who is Hindu and won't speak to me—the human-driven malice took over completely. Even after moving to a brand-new device with a clean, brand-new account, shortly after logging in, my YouTube feed suddenly floods with Bollywood content and location data placing me in India. That is no coincidence, especially knowing she and the guy she's with now had my Wi-Fi password. It goes deeper: I'll be standing in my living room smoking a cigarette—something I rarely do—and a personalized Spotify playlist feature will literally play tracks talking about me standing in the middle of the room smoking, dropping my name, and broadcasting details about what he's doing with her now through remixed songs. On top of that, TikTok videos are actively being remade and reposted to mock me.**
**When you throw in targeted, human-driven psychological warfare exploiting every single digital vulnerability while you're trying to rebuild your life after prison, the stress multiplies by a factor of ten. I wasn't just fighting abstract malware; I was dealing with a malicious loop built to harass me at every turn.**
**The Bottom Line: If you're seeing concrete signs like this—unauthorized session changes, admin consoles acting against you, and constant forced logouts—don't let anyone gaslight you into thinking it's just a "bad password" or a coincidence. It’s a multi-vector persistence and surveillance problem. Until you isolate everything to a 100% verified clean device (out-of-band), wipe every active session globally, lock down your DNS/MX records, and sever every legacy API hook, you're just playing whack-a-mole with someone sitting in your passenger seat.**

reddit.com
u/Choice_Caramel138 — 14 days ago

Follow up to session hijacking after factory reset

**I’m starting a new thread here to address some of the replies, questions, and comments from my previous post all at once.**
**It didn't start with a clean slate; it started with a full-blown, real-time persistence loop. I walked out of a five-year bid thinking I was finally getting a fresh start, but the reality waiting for me hit the exact second I got home. The device waiting for me was one I had while living with my ex, who had possession of it for a short period while I was away. When I tried to log into the Apple account associated with it, I was completely locked out—it was like I didn't even exist. I later found out that an account using my initials and birthday as the username, tied to my name and credentials, was turned into a** ***developer*** **account. I don't know the first thing about developing apps. Without realizing what I was walking into, I created accounts on that device when I first got home, and that's where the bleed started.**
**Instead of just trying to reacclimate to the real world and restart the business I had before I left, I walked straight into a nightmare. If you’ve never sat there watching a live session get actively hijacked while you’re in a literal tug-of-war match—revoking cookies, logging back in, watching recovery options magically shift underneath you, and repeating that cycle for hours straight—people think you're making it up. But when your session tokens are compromised and an attacker has persistent hooks or an infostealer lurking in the background, normal security logic goes out the window.**
**Here is what my actual cross-platform nightmare looked like the moment I got home:**
**1. The Session Tug-of-War & Cookie Hijacking: When an attacker has your session cookies or is actively side-jacking your traffic, logging in normally or clearing a basic cache doesn't cut it. Every time I invalidated tokens and locked it down, if the underlying endpoint or environment wasn't completely nuked and rebuilt from scratch, they stepped right back into the stream. That’s why I ended up in a live ping-pong match where recovery options and settings flipped back instantly—I was fighting an adversary who was mirroring my moves in real-time.**
**2. The Google Workspace & Admin Console Ghost-Suspensions: Trying to restart my business meant managing my custom domains and Workspace, only to experience the absolute horror of looking at my own admin console and realizing my Super Admin status or main account had been silently flagged, suspended, or hit with automated restrictions for sending out outbound phishing/spam links that I never touched. Why did this happen? Because once an adversary compromises administrative footholds or manipulates session layers, they abuse your infrastructure to blast junk, triggering automated safety blocks that lock you out of your own house while keeping their backdoors greased. Notifications get toggled off behind the scenes so you are completely blind to the automated hits until the damage is done.**
**3. The Bot-Flagging & Platform Loop (X, Grok API, & Beyond): Moving across platforms like X or dealing with API key revocations added another layer of psychological torture while I was just trying to get back on my feet. I got flagged as a "bot," forced into endless verification loops, or hit with captchas because the compromised ecosystem bleeding out from my primary footprint was throwing red flags everywhere. It created a cascading failure across every service I touched—from domain management to social and AI API keys—making it look to automated system filters like I was the threat actor on your own network.**
**4. The Personal Element & Targeted Harassment: Six months home from a five-year bid, trying to re-acclimate, restart my business, and dealing with lost communication with my ex—who is Hindu and won't speak to me—the human-driven malice took over completely. Even after moving to a brand-new device with a clean, brand-new account, shortly after logging in, my YouTube feed suddenly floods with Bollywood content and location data placing me in India. That is no coincidence, especially knowing she and the guy she's with now had my Wi-Fi password. It goes deeper: I'll be standing in my living room smoking a cigarette—something I rarely do—and a personalized Spotify playlist feature will literally play tracks talking about me standing in the middle of the room smoking, dropping my name, and broadcasting details about what he's doing with her now through remixed songs. On top of that, TikTok videos are actively being remade and reposted to mock me.**
**When you throw in targeted, human-driven psychological warfare exploiting every single digital vulnerability while you're trying to rebuild your life after prison, the stress multiplies by a factor of ten. I wasn't just fighting abstract malware; I was dealing with a malicious loop built to harass me at every turn.**
**The Bottom Line: If you're seeing concrete signs like this—unauthorized session changes, admin consoles acting against you, and constant forced logouts—don't let anyone gaslight you into thinking it's just a "bad password" or a coincidence. It’s a multi-vector persistence and surveillance problem. Until you isolate everything to a 100% verified clean device (out-of-band), wipe every active session globally, lock down your DNS/MX records, and sever every legacy API hook, you're just playing whack-a-mole with someone sitting in your passenger seat.**

reddit.com
u/Choice_Caramel138 — 14 days ago

"You guys want your 'extraordinary evidence'? Here you go. Check the fucking screenshots. I told you I’m not making this shit up.

Let me remind you where I’m at: I just did a five-year bid. I’ve been home exactly six months, busting my ass doing plumbing, changing locks, and turning wrenches just to get a legitimate handyman business off the ground. I don’t have a cybersecurity team. I'm fighting this completely by myself.
You want proof of the root compromise? Look at the images I just uploaded:

  1. The MDM/Enterprise Hijack: Look at the Google emails. I’m getting official notices welcoming me to a 'ChromeOS Enterprise Upgrade trial' with 50 licenses that gives an admin the power to manage devices, block downloads, and wipe my data remotely. I never signed up for any enterprise device management, yet it’s tied to my tenant.
    2.The DNS/DMARC Sabotage: Look at the domain status screenshots. I go in, configure my DNS, MX, and DMARC records to point to my secure Proton servers, and get them completely verified. A few days later? They are deliberately altered, and the DKIM is failing.
    3.The Namecheap Chat: Look at the support logs with Namecheap. I literally had to go rounds with them just for support to tell me they can't even see who specifically edited my host records, but they confirmed my API was disabled.
    As for why I haven't dumped my raw Google Workspace IP logs here for you to 'diagnose'—it's because I am actively being session-hijacked. I am currently locked out of my own admin account trying to verify my identity without a secure email. If I log into my Super Admin console right now from this dirty network to pull those logs, I am just handing them my fresh session cookies and putting myself right back in a live tug-of-war.
    I am fighting a ghost that has hijacked my cloud infrastructure and pushed enterprise-level management to my network. So before you sit there and call this 'shizo shit,' look at the actual evidence. If you have the actual technical knowledge to tell me how to safely pull access logs without triggering a live interception, I'm all ears. But if you’re just here to talk shit while a man fights for his digital life, get the fuck out of the way. For those who are willing to accept what I’m claiming to be true, I’m all but begging for your help at that this point. I can’t spend another 3 months fighting this ghost by myself. I’m all ears
u/Choice_Caramel138 — 17 days ago

Escalation Confirmed: Multi-Platform Root Compromise and Live Cookie Hijacking.

To answer your questions: Yes, I am stopping the factory resets, and yes, this has escalated far beyond a simple device infection into a massive, multi-platform root account compromise. I initially suspected an MDM or webkit token grab by my ex, but based on the concrete evidence I’ve gathered, they have bypassed the device level entirely and established persistence in my cloud and domain infrastructure. This isn't just cross-syncing or stale sessions; this is an active, human-driven compromise.
Here are the concrete examples of unauthorized activity across my root accounts:
Google Workspace & Admin Console Hijacking: The attacker gained elevated administrative privileges on my Google Workspace environment. My primary Super Admin privileges were repeatedly suspended by Google for sending out outbound spam and phishing links. The attacker had manually toggled off my admin notifications in the console so I was completely blind to the automated safety blocks hitting my account.
Domain & DNS Manipulation: The attacker infiltrated my Namecheap registrar and Proton mail accounts)They actively altered my DNS records, specifically updating the MX, TXT/DMARC, and DKIM records to route mail directly through their own controlled servers.
Active Session Cookie Hijacking (The Tug-of-War): I have been in literal, real-time tug-of-war matches with the attacker. I would revoke session cookies and log in, and they would instantly log me back out and shift the account recovery options out from under me. This cycle would repeat for hours at a time, proving they have a live mechanism intercepting my session tokens.
I am currently working from a 100% clean, out-of-band device and have placed administrative holds on my domains to stop them from being transferred out. Because the attacker is actively side-jacking my session traffic, I am looking for the best method to pull the raw login IP logs from Google and Proton without triggering another live interception. If you have advice on the safest way to extract the raw access logs from a hijacked Workspace, I need it.

reddit.com
u/Choice_Caramel138 — 19 days ago

Session hijacking after factory resets

I’m seeing repeated unauthorized activity across multiple accounts, even after:
Signing out all sessions
Changing passwords
Enabling security keys and 2FA
Factory-resetting iOS and Android devices
Setting them up as new without backups
Checking for MDM or management profiles
What could realistically cause this across multiple platforms—stolen session tokens, compromised recovery methods, synced credentials, carrier access, enterprise enrollment, or device malware?
I’m looking for advice on what evidence to preserve, which logs to collect, and what type of cybersecurity specialist I should contact before resetting anything again.

reddit.com
u/Choice_Caramel138 — 22 days ago
▲ 2 r/u_Choice_Caramel138+2 crossposts

Follow up to session hijacking after factory reset

I’m starting a new thread here to address some of the replies, questions, and comments from my previous post all at once.
It didn't start with a clean slate; it started with a full-blown, real-time persistence loop. I walked out of a five-year bid thinking I was finally getting a fresh start, but the reality waiting for me hit the exact second I got home. The device waiting for me was one I had while living with my ex, who had possession of it for a short period while I was away. When I tried to log into the Apple account associated with it, I was completely locked out—it was like I didn't even exist. I later found out that an account using my initials and birthday as the username, tied to my name and credentials, was turned into a developer account. I don't know the first thing about developing apps. Without realizing what I was walking into, I created accounts on that device when I first got home, and that's where the bleed started.
Instead of just trying to reacclimate to the real world and restart the business I had before I left, I walked straight into a nightmare. If you’ve never sat there watching a live session get actively hijacked while you’re in a literal tug-of-war match—revoking cookies, logging back in, watching recovery options magically shift underneath you, and repeating that cycle for hours straight—people think you're making it up. But when your session tokens are compromised and an attacker has persistent hooks or an infostealer lurking in the background, normal security logic goes out the window.
Here is what my actual cross-platform nightmare looked like the moment I got home:
1. The Session Tug-of-War & Cookie Hijacking: When an attacker has your session cookies or is actively side-jacking your traffic, logging in normally or clearing a basic cache doesn't cut it. Every time I invalidated tokens and locked it down, if the underlying endpoint or environment wasn't completely nuked and rebuilt from scratch, they stepped right back into the stream. That’s why I ended up in a live ping-pong match where recovery options and settings flipped back instantly—I was fighting an adversary who was mirroring my moves in real-time.
2. The Google Workspace & Admin Console Ghost-Suspensions: Trying to restart my business meant managing my custom domains and Workspace, only to experience the absolute horror of looking at my own admin console and realizing my Super Admin status or main account had been silently flagged, suspended, or hit with automated restrictions for sending out outbound phishing/spam links that I never touched. Why did this happen? Because once an adversary compromises administrative footholds or manipulates session layers, they abuse your infrastructure to blast junk, triggering automated safety blocks that lock you out of your own house while keeping their backdoors greased. Notifications get toggled off behind the scenes so you are completely blind to the automated hits until the damage is done.
3. The Bot-Flagging & Platform Loop (X, Grok API, & Beyond): Moving across platforms like X or dealing with API key revocations added another layer of psychological torture while I was just trying to get back on my feet. I got flagged as a "bot," forced into endless verification loops, or hit with captchas because the compromised ecosystem bleeding out from my primary footprint was throwing red flags everywhere. It created a cascading failure across every service I touched—from domain management to social and AI API keys—making it look to automated system filters like I was the threat actor on your own network.
4. The Personal Element & Targeted Harassment: Six months home from a five-year bid, trying to re-acclimate, restart my business, and dealing with lost communication with my ex—who is Hindu and won't speak to me—the human-driven malice took over completely. Even after moving to a brand-new device with a clean, brand-new account, shortly after logging in, my YouTube feed suddenly floods with Bollywood content and location data placing me in India. That is no coincidence, especially knowing she and the guy she's with now had my Wi-Fi password. It goes deeper: I'll be standing in my living room smoking a cigarette—something I rarely do—and a personalized Spotify playlist feature will literally play tracks talking about me standing in the middle of the room smoking, dropping my name, and broadcasting details about what he's doing with her now through remixed songs. On top of that, TikTok videos are actively being remade and reposted to mock me.
When you throw in targeted, human-driven psychological warfare exploiting every single digital vulnerability while you're trying to rebuild your life after prison, the stress multiplies by a factor of ten. I wasn't just fighting abstract malware; I was dealing with a malicious loop built to harass me at every turn.
The Bottom Line: If you're seeing concrete signs like this—unauthorized session changes, admin consoles acting against you, and constant forced logouts—don't let anyone gaslight you into thinking it's just a "bad password" or a coincidence. It’s a multi-vector persistence and surveillance problem. Until you isolate everything to a 100% verified clean device (out-of-band), wipe every active session globally, lock down your DNS/MX records, and sever every legacy API hook, you're just playing whack-a-mole with someone sitting in your passenger seat.

reddit.com
u/Choice_Caramel138 — 17 days ago

Session hijacking after factory resets

I’m seeing repeated unauthorized activity across multiple accounts, even after:
Signing out all sessions
Changing passwords
Enabling security keys and 2FA
Factory-resetting iOS and Android devices
Setting them up as new without backups
Checking for MDM or management profiles
What could realistically cause this across multiple platforms—stolen session tokens, compromised recovery methods, synced credentials, carrier access, enterprise enrollment, or device malware?
I’m looking for advice on what evidence to preserve, which logs to collect, and what type of cybersecurity specialist I should contact before resetting anything again.

reddit.com
u/Choice_Caramel138 — 24 days ago