I'm worried about my niece after she ended a friendship group on bad terms. She believes some former friends are not only watching her social media but may have accessed her accounts or devices because their posts sometimes seem to reference very specific things she has done online or offline. They live in the same city but have not used our devices, connected to our network, or been physically near us, as far as we know.
We checked the accounts and found no unfamiliar login sessions or devices. Security scans also have not detected viruses or malware. She has changed her passwords and enabled additional security options, but she remains convinced that the devices may have remote-access malware. Her anxiety is getting worse, and she wants us to spend money repairing or replacing the devices. We would like to know how to verify whether there is a real compromise, secure everything properly, and distinguish technical evidence from possibly coincidental or indirect social-media posts before involving authorities.
3 Answers
A genuine remote-access infection usually leaves more concrete signs than vaguely similar posts: suspicious installed apps, unusual accessibility or device-administrator permissions, unknown browser extensions, unexpected account alerts, battery or data usage changes, or security logs showing access. Run reputable scans, update the operating systems, remove apps that are not needed, and review permissions. If there is still serious concern, back up only important personal files, perform a factory reset, install updates from official sources, and set the devices up again rather than paying someone to make unsupported claims.
Security settings matter, but reducing exposure is useful too. Block or unfollow the people involved, make profiles private, disable location and activity sharing, remove unknown followers and connected applications, and avoid accepting new requests. Keep the phone away during meals and overnight so everyone gets a break from monitoring posts. People can also learn details indirectly through mutual friends, public activity, recommendations, or simple coincidence, so matching posts are not reliable proof of a hack.
Start with the basics: use a trusted, fully updated device to change the email password first, then change the passwords for other important accounts. Make every password unique, enable multi-factor authentication, and check recovery email addresses, phone numbers, active sessions, connected apps, and forwarding rules. A password manager can make this much easier. If there are no unknown sessions, recovery changes, security alerts, or other technical evidence, that makes account access less likely, although it cannot prove anything by itself.
She has already changed the passwords and enabled extra security, but she still thinks the posts are too specific to be coincidences. She is also worried that the devices have remote-access malware.

If her fear continues even after the accounts and devices have been checked, please treat the distress as important in its own right. A mental-health professional can help without dismissing her concerns, while a qualified security technician can independently examine the devices. Document specific posts, dates, account alerts, and technical findings rather than confronting or accusing anyone based only on interpretation.