Sold my phone with my personal data ☹️

More in Tips
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- We will croc you
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian…
- VMkatz: a hidden threat to virtual infrastructure 🫣
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely…
- A look inside ESE
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need…
- ::%16777216 — so what exactly are you?
::%16777216 — so what exactly are you? It is known that during attacks, adversaries can use…
Sold a phone with my personal data ☹️
When purchasing donor devices on platforms for selling personal items, a negative trend is emerging: many people rarely worry about the security of their data. This is especially true for selling faulty devices and old phones that are no longer in use.
The most common reasons given for selling are:
➖ damage to the charging and data transfer port;
➖ damage to the screen and device matrix;
➖ complete discharge or malfunction of the battery;
➖ problems loading the device’s operating system.
With certain repair skills, an attacker can easily restore access to all information on the device.
Password protection is also not a panacea: using various mobile device vulnerabilities and certain tools, it is possible to extract data bypassing the lock. How this can be done on iOS devices was previously written about here.
During conversations, many sellers themselves provide not only the passwords for accessing the phone but also for the account linked to the device. Such kindness often plays into the attacker’s hands: having obtained the account password, they can download the contents of cloud backups and remotely lock all your devices linked to the account.
Personal data that can be obtained from such devices:
1️⃣ SMS messages.
In addition to correspondence between subscribers, they may contain information about registration on third-party resources, user account data, and partial payment card numbers.
2️⃣ Device call log.
Based on this data, an attacker can establish the seller’s social circle.
3️⃣ Photos, video recordings, and voice recorder recordings.
This information can be used by attackers to generate deepfakes and blackmail the owner. Photos of passports, bank cards, and other documents with personal data can be used directly for criminal purposes.
4️⃣ Messenger correspondence.
Information you share with other people, your video messages, and voice messages — all of this adds to the portrait of your personality and can be used to create deepfakes.
5️⃣ Contact list of the subscriber.
Allows targeted dissemination of information among your acquaintances.
6️⃣ User accounts, passwords for accessing online services.
Despite periodic data leaks and the need to use individual passwords for different resources, many still use one password to log into all sites. Two-factor authentication provides additional protection against unauthorized access, but if an attacker obtains a valid access token for a site whose validity period has not yet expired, 2FA will not help. If the access password does not work and the token is not valid, the attacker can check passwords against various data leaks.
7️⃣ Device location at a specific point in time.
With geolocation enabled, it is possible to find out a person’s place of residence and places they frequently visit.
Thoughtless sale of technology can have serious consequences if the device falls into the hands of an attacker.
When selling, adhere to the following security measures:
1️⃣ If the device is fully functional: log out of your accounts, perform a factory reset of the device. For iPhone and iPad, use Apple’s instructions for preparing the device for sale.
2️⃣ If the device has technical damage and there is no way to perform a factory reset: sell the device for parts, without the board containing the memory chip.
3️⃣ If the device has already been sold:
➖ enable 2FA for all accounts;
➖ close active sessions associated with the sold device;
➖ change passwords on services that were accessed from this device;
➖ come up with and share a code word with close contacts to verify the authenticity of requests made in your name for money transfers or other assistance.
About 30 phones were purchased to write this post, so these are not isolated cases 🙂
#mobile #ios #android #tip
@ptescalator
More in Tips
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- We will croc you
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian…
- VMkatz: a hidden threat to virtual infrastructure 🫣
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely…
- A look inside ESE
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need…
- ::%16777216 — so what exactly are you?
::%16777216 — so what exactly are you? It is known that during attacks, adversaries can use…






