Third-party security apps such as Norton 360 cannot completely scan an iPhone’s entire file system because of Apple’s sandboxing architecture. This means a Norton scan of an iPhone is not equivalent to a full forensic examination of the device and cannot, by itself, rule out every form of compromise or unauthorized access. A clean Norton scan also does not establish that spyware is present.
If you believe your device or personal accounts may have been compromised by a known individual, there are several steps you can take directly through iOS to review access and strengthen your security.
1. Review Access with Apple Safety Check
Apple provides a built-in privacy feature called Safety Check, specifically designed for situations where someone’s personal safety or privacy may be at risk from another individual.
- Go to Settings > Privacy & Security > Safety Check.
- Use Emergency Reset if appropriate to quickly review and stop sharing information with people and apps.
- Follow the prompts to review people and apps that have access to your information, devices connected to your Apple Account, and other security settings.
- Consider changing your device passcode and Apple Account password if you believe someone else may know them.
2. Consider Lockdown Mode
If you believe you may be the target of highly sophisticated, targeted spyware, Apple provides Lockdown Mode, its most stringent security setting. It substantially restricts certain apps, websites, communications, and other features to reduce potential attack surfaces.
- Go to Settings > Privacy & Security > Lockdown Mode.
- Review Apple’s information about the feature and enable it if appropriate.
Lockdown Mode is a protective measure; enabling it does not establish that spyware is present.
3. Check for Unrecognized Configuration Profiles or Device Management
Check whether the iPhone has any configuration profiles or device-management enrollment that you do not recognize.
- Go to Settings > General > VPN & Device Management.
- Review any listed profiles or Mobile Device Management (MDM) entries.
- If you find something you do not recognize, investigate it before removing it. Some profiles and management enrollments are legitimate, and if you are involved in legal proceedings, preserving the state of the device may be important.
4. Secure Your Apple, Email, and Financial Accounts
Because you report that a photograph of your bank account was recently taken, I would also treat your important accounts as potentially exposed until you can establish otherwise.
Using a device or telephone that the suspected individual cannot access:
- Change your Apple Account password.
- Review the devices signed into your Apple Account and remove anything you do not recognize.
- Change passwords for important email, banking, and other financial accounts.
- Enable or review multi-factor authentication where available.
- Contact your bank or financial institution and explain the situation so they can advise you about protecting the account.
5. Consider a Factory Reset Only After Considering Evidence Preservation
If the suspicious behavior continues and you remain concerned that the iPhone itself has been compromised, completely erasing the device and setting it up as new can be an appropriate final step.
Go to Settings > General > Transfer or Reset iPhone > Erase All Content and Settings.
If you take this route, consider setting the iPhone up as a new device rather than immediately restoring everything from a backup, particularly if you are concerned that settings, apps, or account access associated with the suspected compromise could be carried forward.
However, there is an important exception in your situation: you state that the suspected individual is a defendant. If this situation is connected with legal proceedings, do not rush to erase the phone. A reset could destroy information that might be relevant to a forensic investigation. Consider consulting your attorney or an appropriate digital-forensics professional before taking that step.
Finally, keep in mind that the reported behavior does not, by itself, establish that spyware is installed. A Norton scan that finds nothing does not prove the phone is clean, but neither does unusual behavior prove that spyware is present. The steps above are intended to help determine whether there is an identifiable access, account, configuration, or device-security issue and to reduce further exposure while that is being investigated.