MOBILE SECURITY FIRST AID

Stop. Breathe. Follow these steps.

Before you do anything — do not factory reset, uninstall apps, or make any sudden changes. Hasty actions can permanently destroy the evidence needed to understand what happened. These steps are first aid, not a full diagnosis. If you are unsure about any step, contact us before proceeding.

1

Leave the phone behind

Assume your phone's microphone and camera are live right now — even with the screen off.

DON'T Discuss your situation, plans, or fears near the device.
DON'T Use it to search for spyware help or cybersecurity support.
DO Physically leave it in another room, a drawer, or a vehicle before talking.
2

Find a secure line before going further

Do not use the suspected device to search for help, contact support, or communicate about this situation. You need a separate, clean channel before taking any next steps.

DO Use a completely separate device — a trusted colleague's phone, a library computer, or a cash-purchased burner phone.
DO If you have access to a landline or a trusted person's phone, use that to reach out for support now.
DON'T Use your regular email, phone number, or accounts on the new device — those may already be monitored.
3

Isolate the device — preserve what's on it

Elite spyware often lives only in the device's active memory. The evidence needed to identify your attacker, understand the infection vector, and protect others in your community exists right now — and can be permanently lost if the device is turned off, reset, or tampered with.

Keep it on. Cut it off.

Physically remove the SIM card (use a paperclip — Airplane Mode alone is not reliable). Manually toggle Wi-Fi and Bluetooth off. Ensure the phone does not get switched off - connect to a power source if needed

Preserving the device in this state gives our forensic team the best chance of identifying who targeted you, how they got in, and whether others are at risk. Your cooperation directly helps protect the broader community.

Do not insert the removed SIM into any other phone. The number itself is tracked and can trigger re-infection on a new device.

If you are in immediate physical danger: leave the phone where it is and call 911 (or your local emergency number). Your safety comes first. Do not stop to power it off or retrieve it.
Not sure what to do with your device? Contact us first — we can help you decide before you take any action.
4

Revoke all cloud sessions from a clean device

The spyware has likely cloned your login tokens. Even with the phone off, attackers may still have access to your Google, email, and banking accounts.

DO Get a separate, trusted computer — a library terminal, a colleague's laptop, or a cash-purchased burner phone.
DO Log into your Google account, primary email, and password manager from that clean device. Change all passwords.
DO Find the "Sign out of all other sessions" or "Revoke authorized devices" option in each account's security settings. Use it.
DO Move 2FA off SMS and onto an authenticator app on your new clean device only.
DON'T Type new passwords or receive SMS verification codes on the suspected device.
5

Do not contact standard IT support

Commercial antivirus tools and standard corporate IT cannot detect elite mercenary spyware. A clean result from them is not a clean device — it's a false negative.

DON'T Take the device to a retail tech shop or run consumer antivirus.
DON'T Factory reset the device. This permanently destroys the forensic evidence we need.
DO Treat the device as hazardous material. Keep it isolated until a specialist can triage it.

Done with these steps?

Contact our specialized forensic team.

Use a clean device and a fresh communication line — not your regular email or phone number — to reach us. We provide discrete, specialist-grade incident response for high-risk individuals and organizations.

Get Help Now