Saturday, June 27, 2026

Trying to figure out if Mac is being hacked [closed]

I’ve been the target of a harassment and doxxing campaign so I’m spending a lot of time securing my devices and my families devices.

I noticed that my systems files creation date had been change to the 16th of August as if they’d been recreated. No update was done, and unless they’re lying Apple support told me that this is not normal system behavior.

I noticed that since this Friday the 15th, there has been an attempt to login as private in opendirectory:

How do I figure out what thing, file, process or call is causing that?

opendirectoryd: (PlistFile) [com.apple.opendirectoryd:auth] Authentication failed for <private> (#): ODErrorCredentialsInvalid

… that started regularly since Friday the 15th, which coincides with when I looked at the history of logging there’s a weird discrepancy:
Fri 15 is right when those opendirectoryd queries started

Additional details:

  • Firewall is activated
  • Router is not port forwarding – although I couldn’t get them to confirm UPnP is disabled
  • I’m using LittleSnitch for filtering

My goal is to really figure out what is making those attempts whether it’s a genuine login/touchid for some or system process or other files/plist/process etc., …

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles