Hello
I have been a victim of Device compromise and takeover, through various cyber attack methods, over the last 8 months, Changes devices, Sims, passwords, Attackers mange to get back into the device, through maybe Email or other forms,
I am run a self-employed business , I receivr fake emails of companies that I have interacted with
The issue begins by I think is key logging, and malware, I have Bitendefender installed , they seem to by pass it, I have secured sim by registration and pass code with carrier, installed Cloudflare one and warp set up private DNS
Process is gradual with the end being
I can't change the network setting,
Cloude flare VPN is showing always on connected but error message from samsung that the VPN is off can not connect,
Antivirus setting are rest and can't be changed as there is no internet,
I change sim still no network connection or WiFi, to connect,
What Ithink is the issue and if anyone can advise, the process is initially through malware, (it by passes antivirus) then moves on to Adding extensions to installed apps., all my AI models have had Multi turn manipulation, emails (I have proton mail accounts) to Claude and anthtopic support I never receive I think theyay have access to emails,
Always 2 emails that are send from chat GPT I never receive the first TOP code it's always the second. I think maybe that's how they gain access to the AI, I have Auath app set. 2FA now. Claude, anthtopic don't support 2FA .
On the browser. When on. Logging on it seems there is a redirection to a similar site is Open AI goes to chat gpt,
There a second page Reload, .
I understand most of it is high experience Social engineering, some advice on any experience on what options to try
The ultimate climax is network compromise. I initialy the device becomes very slow. It feels like a DDOS attack, traffic is heavy on the phone. Then the warp connection is showing connected but not showing connection on the 1.1.1.1 help page
As explainied at the beginning of the thread all Network connection is lost
Can't change or access the setting due no internet
I would appreciate some experienced and expert advice from any one.
My phone is a Samsung A16 Android 16
Thanks
Important first point
The symptoms you describe do not, by themselves, prove a keylogger, malware infection, device takeover, or a DDoS attack. VPN failures, damaged network settings, phishing, account-session theft, carrier problems, DNS issues, and ordinary Android configuration problems can produce similar symptoms.
Because you operate a business, treat this as a possible account-security incident without assuming that every symptom has the same cause.
1. Stop using the phone for sensitive activity
Until it has been checked or reset:
- Do not use the phone to change business, email, banking, or AI-account passwords.
- Do not approve unexpected authenticator prompts.
- Do not open links in suspicious messages.
- Do not install “cleaners,” remote-support tools, certificate profiles, or APK files received by email or messaging.
- Use a different, trusted device for account recovery.
If you do not have a trusted device, use a newly reset computer or a device belonging to someone you trust, and access accounts by manually typing the official address rather than following email links.
2. Secure accounts from a trusted device
Start with the email accounts, because email access can allow attackers to reset many other accounts.
For each important account:
- Change the password to a unique password that has never been used elsewhere.
- Review and revoke active sessions, remembered devices, app passwords, OAuth connections, and recovery methods.
- Check email forwarding rules, filters, blocked addresses, automatic replies, and mailbox delegation.
- Confirm that the recovery email address and telephone number are yours.
- Use an authenticator application or, preferably, a hardware security key where supported.
- Save new recovery codes offline.
- Rotate business, cloud, and AI service API keys if you have used them.
For Proton Mail, inspect account sessions, authentication methods, recovery settings, forwarding or filtering rules, and mailbox activity. For ChatGPT, Claude, Anthropic, and other services, use their official account-security pages and revoke sessions or connected applications where that option exists.
A missing verification email does not necessarily indicate interception. It can result from filtering, delivery delay, an incorrect account address, rate limiting, or a phishing page collecting the first code. Always check the actual destination address in the browser address bar before entering a code. Never enter a code into a page reached through an unexpected email.
3. Check whether the phone is actually compromised
On the Samsung device, review:
- Settings > Apps: remove unfamiliar applications, especially those installed recently.
- Settings > Accessibility > Installed apps: disable anything you do not recognize.
- Settings > Security and privacy > More security settings > Device admin apps: remove unknown administrators.
- Settings > Security and privacy > Install unknown apps: disable permission for browsers, file managers, and messaging applications unless genuinely required.
- Settings > Connections > More connection settings > VPN: remove unknown VPN profiles and temporarily disconnect Cloudflare WARP.
- Settings > Connections > Wi-Fi: remove unfamiliar saved networks.
- Settings > Notifications and Settings: review applications with notification access, display-over-other-apps permission, and unrestricted battery usage.
- Browser settings: remove unknown extensions, site notifications, search engines, and saved passwords.
The exact menu names can vary by Samsung and Android version. Android settings do not require an internet connection, so loss of internet access should not normally prevent you from opening or changing local network settings.
Booting into Android Safe Mode is a useful low-risk test because third-party applications are disabled. If mobile data or Wi-Fi works normally in Safe Mode, a third-party application or VPN configuration becomes more likely. Safe Mode is not proof of malware, however.
4. Repair the network configuration
Before performing a factory reset, try these standard steps:
- Restart the phone and confirm that Airplane mode is disabled.
- Temporarily remove or disable Cloudflare WARP and any other VPN.
- Use Settings > General management > Reset > Reset Wi-Fi and Bluetooth settings, or the equivalent “Reset network settings” option.
- Check the carrier APN settings and ask the carrier to confirm the correct APN.
- Test the SIM in another known-working phone, and test another SIM in this phone if possible.
- Test a different Wi-Fi network rather than only the home network.
- Set date and time automatically.
Resetting network settings removes saved Wi-Fi networks, Bluetooth pairings, VPN settings, and some mobile-network configuration. It does not normally erase personal files.
The Cloudflare 1.1.1.1 help page is not a complete test of internet access. WARP can report a tunnel state while DNS, routing, captive-portal authentication, or the underlying carrier connection is failing.
5. If the problem continues, perform a clean reset
If there is no reliable explanation after the checks above, a factory reset is reasonable:
- Back up only essential photos, documents, contacts, and business records.
- Do not restore all applications, system settings, VPN profiles, or browser data automatically.
- Record important two-factor recovery codes before resetting.
- Perform the factory reset through Samsung’s official Settings or recovery procedure.
- Install all Android and Samsung updates before installing other applications.
- Install applications only from Google Play or the official Samsung store.
- Restore data selectively and manually.
- Change important passwords again after the reset if the old device was used during recovery.
If the phone still loses connectivity or settings remain abnormal immediately after a clean reset and updates, contact Samsung support or an authorized service centre. Ask the carrier to check the SIM, account provisioning, call/data restrictions, and any unauthorized SIM replacement or eSIM activity.
6. Preserve evidence and protect the business
Do not delete everything before recording useful information. Save:
- Screenshots of suspicious messages, URLs, application names, VPN errors, and account-security alerts.
- Dates and times of lost connectivity and unusual account activity.
- Carrier notifications and SIM-change information.
- Email headers for suspicious messages, not only screenshots.
- Relevant business transaction and login records.
Contact banks, payment processors, domain registrars, hosting providers, and important business services through their official contact details. Tell them that account compromise is suspected and request session revocation, transaction review, and additional verification. If customer or regulated data may have been accessed, obtain professional incident-response or legal advice promptly.
Do not conclude that every AI conversation or browser redirect proves device compromise. Verify the domain shown in the address bar, inspect account sessions and email rules, and submit suspicious files or URLs to reputable services such as VirusTotal without uploading confidential business documents.
The safest path is to secure email and business accounts from a trusted device, disable the VPN and reset network settings, then perform a clean factory reset if the abnormal behavior remains.