Sarai Hannah Ajai PUBLIC REDACTED VERSION CONSOLIDATED APPLE SCREEN TIME PASSCODE, APPLE ACCOUNT, TELECOMMUNICATIONS, AND DEVICE-SECURITY INCIDENT REPORT

 


PUBLIC REDACTED VERSION

CONSOLIDATED APPLE SCREEN TIME PASSCODE, APPLE ACCOUNT, TELECOMMUNICATIONS, AND DEVICE-SECURITY INCIDENT REPORT




Reporting Individual / Complainant: Sarai Hannah Ajai
Primary Incident Date: October 8, 2026
Primary Device: Apple iPhone 17
Relevant Systems: Apple Screen Time; Apple Account/iCloud; Apple authentication and account recovery; cellular telecommunications service; personally controlled mobile network equipment
Residential Unit: [REDACTED]
Report Preparation Date: October 8, 2026


PUBLIC-REDACTION NOTICE

This version has been prepared specifically for public posting.

The following information has been intentionally withheld, generalized, or replaced with redaction markers for privacy, account security, telecommunications security, residential security, and evidentiary integrity:

  • residential apartment-unit number;
  • precise residential address;
  • Screen Time passcodes;
  • current Screen Time passcode;
  • Apple Account password;
  • Apple Account email address;
  • cellular telephone number;
  • telecommunications-provider account information;
  • carrier-specific account identifiers;
  • SIM/eSIM identifiers;
  • IMEI;
  • ICCID;
  • EID;
  • device serial numbers;
  • MAC addresses;
  • IP addresses;
  • hotspot passwords;
  • Wi-Fi credentials;
  • authentication codes;
  • account-recovery credentials;
  • trusted-device identifiers;
  • and other information that could facilitate unauthorized access to personal devices, accounts, or telecommunications services.

The complete unredacted report and original exhibits should remain preserved separately for authorized attorneys, law-enforcement agencies, courts, regulators, Apple, telecommunications providers, qualified forensic professionals, or other authorized recipients when appropriate.


I. PURPOSE OF THIS INCIDENT REPORT

I, Sarai Hannah Ajai (“the Complainant”), prepare this report to document another Screen Time passcode and account-security incident affecting my personally owned Apple iPhone 17 on October 8, 2026.

This incident concerns:

  1. my intentional change of the Apple iPhone 17 Screen Time passcode at approximately 11:16 AM;
  2. the Apple Screen Time interface subsequently displaying “Passcode used today at 11:16 AM”;
  3. my intentional change of my Apple Account/iCloud credential at approximately 11:41 AM;
  4. my subsequent discovery at approximately 1:37 PM that the Screen Time passcode I understood to be valid was rejected by the iPhone;
  5. the iPhone displaying “Incorrect passcode”;
  6. my use of Apple’s Screen Time Passcode Recovery process at approximately 1:40 PM;
  7. my authentication through the Apple Account associated with Screen Time recovery;
  8. my establishment of another Screen Time passcode;
  9. a separate observation concerning personally controlled mobile network equipment at approximately 2:04 PM;
  10. my concern regarding recurring Screen Time passcode irregularities;
  11. my concern that unauthorized Apple Account, device, telecommunications, or network activity may be affecting my personally controlled systems; and
  12. my request for preservation of Apple, telecommunications-provider, authentication, device, and network records capable of establishing what occurred.

This report distinguishes among:

  • information directly displayed by my iPhone;
  • actions I personally performed;
  • credentials I personally established;
  • screenshots and photographs I preserved;
  • events I personally observed;
  • concerns requiring investigation;
  • and conclusions that cannot presently be established without independent technical evidence.

I do not intend this report to attribute the incident to a particular person or technical mechanism unless supported by reliable provider-side, forensic, or other objective evidence.


II. DEVICE OWNERSHIP AND AUTHORIZATION

I personally own and control the Apple iPhone 17 associated with this incident.

I also personally control the associated:

  • Apple Account/iCloud account;
  • Screen Time configuration;
  • Screen Time passcode;
  • Apple Account password;
  • device passcode;
  • cellular telephone service;
  • authentication credentials;
  • account-recovery settings;
  • one-time verification codes;
  • trusted-device settings;
  • trusted telephone numbers;
  • and other personal account-security controls.

I have not knowingly authorized neighboring residents, property-management personnel, family members, acquaintances, or unrelated third parties to:

  • change my Screen Time passcode;
  • reset Screen Time;
  • access my Apple Account;
  • use or obtain my Apple Account password;
  • change trusted devices;
  • change trusted telephone numbers;
  • access my Apple iPhone 17;
  • enroll an additional device using my credentials;
  • administer my iPhone remotely;
  • change cellular-account settings;
  • provision an additional SIM or eSIM;
  • access authentication codes;
  • alter account-recovery settings;
  • or otherwise exercise administrative authority over my personally owned device or accounts.

III. PRIOR SCREEN TIME PASSCODE

Before the October 8 incident, my Apple iPhone 17 Screen Time configuration was protected by a four-digit Screen Time passcode.

For this public report, that credential is:

[REDACTED PRIOR SCREEN TIME PASSCODE]

I understood that credential to be valid before intentionally changing it on October 8, 2026.


IV. APPROXIMATELY 11:16 AM — INTENTIONAL SCREEN TIME PASSCODE CHANGE

On October 8, 2026, at approximately 11:16 AM, I intentionally changed the Screen Time passcode on my Apple iPhone 17 from the prior credential to a newly selected credential.

For this public version:

Prior Screen Time Passcode: [REDACTED]
New Screen Time Passcode: [REDACTED]

I personally selected the new credential.

After completing the process, I understood the newly established passcode to be the valid Screen Time credential for my Apple iPhone 17.

I did not knowingly authorize any other person to change that Screen Time passcode after I established it.


V. EXHIBIT A1 — SCREEN TIME PASSCODE ACTIVITY AT 11:16 AM

I preserved a screenshot identified as:

Exhibit A1 | Apple Screen Time — Manage Screen Time — “Passcode used today at 11:16 AM” — October 8, 2026

The screenshot visibly displays:

Manage Screen Time

and:

Passcode used today at 11:16 AM

The screenshot also visibly displays Screen Time controls including:

  • Allowed Contacts;
  • Always Allowed;
  • Screen Time Schedule;
  • Time Allowances;
  • Content & Privacy Restrictions;
  • Communication Safety;
  • and Manage Screen Time.

Evidentiary significance

Exhibit A1 supports that:

  • Screen Time was configured on the Apple iPhone 17;
  • Screen Time passcode protection was active;
  • Apple displayed passcode activity for that day;
  • and the visible time associated with that activity was approximately 11:16 AM.

The screenshot does not independently establish:

  • the numerical value of the passcode used;
  • whether the displayed 11:16 AM event itself represents a passcode change rather than another authenticated Screen Time action;
  • whether another Apple device synchronized Screen Time configuration;
  • whether the passcode changed later;
  • or whether unauthorized access occurred.

My statement that I intentionally changed the Screen Time passcode is based upon my personal action and contemporaneous recollection.


VI. APPROXIMATELY 11:41 AM — APPLE ACCOUNT/ICLOUD CREDENTIAL CHANGE

At approximately 11:41 AM on October 8, 2026, I intentionally changed the credential associated with my Apple Account/iCloud account.

This occurred approximately 25 minutes after the Screen Time activity documented at approximately 11:16 AM.

I personally performed the Apple Account credential change.

I did not knowingly disclose the newly established credential to:

  • neighboring residents;
  • property-management personnel;
  • family members;
  • acquaintances;
  • or unrelated third parties.

I did not knowingly authorize another person to access, administer, or use my Apple Account following the credential change.

The actual Apple Account password is:

[REDACTED — CONFIDENTIAL ACCOUNT CREDENTIAL]

It should not appear in any public exhibit, blog post, public complaint, or other publicly accessible record.


VII. SIGNIFICANCE OF THE 11:41 AM APPLE ACCOUNT CREDENTIAL CHANGE

The timing of the Apple Account credential change establishes the following sequence:

11:16 AM — Screen Time credential activity/change

followed by:

11:41 AM — Apple Account/iCloud credential change

followed by:

1:37 PM — Screen Time passcode rejection

followed by:

1:40 PM — Screen Time Passcode Recovery

Approximately one hour and fifty-six minutes elapsed between the Apple Account credential change at 11:41 AM and the Screen Time passcode rejection at approximately 1:37 PM.

This chronology makes preservation of Apple Account security records during that period particularly important.

The chronology does not independently establish that another person obtained the newly established Apple Account credential.


VIII. MY LOCATION AND COMMUNICATION ACTIVITY DURING THE RELEVANT PERIOD

During the period surrounding the October 8 incident, I report that:

  • I remained inside my residence;
  • I did not knowingly share my Apple Account credential with neighboring residents;
  • I did not knowingly share that credential with property-management personnel;
  • I did not knowingly share it with family members;
  • I did not knowingly authorize another person to use my Apple Account;
  • I did not knowingly authorize another device to administer Screen Time;
  • and I report that I did not make telephone calls or send text messages to another person during the relevant period I describe.

These statements form part of my personal chronology.

They do not independently determine whether remote account activity occurred.


IX. APPROXIMATELY 1:37 PM — SCREEN TIME PASSCODE REJECTION

At approximately 1:37 PM on October 8, 2026, I attempted to use the Screen Time passcode that I understood to be valid.

For this public report, that credential is:

[REDACTED]

The Apple iPhone 17 did not accept the credential.

Instead, the device displayed:

“Incorrect passcode”

I preserved that interface as Exhibit A2.


X. EXHIBIT A2 — “INCORRECT PASSCODE”

Public Exhibit Title:

Exhibit A2 | Apple Screen Time Interface Displaying “Incorrect Passcode” — Approximately 1:37 PM, October 8, 2026

The screenshot visibly displays:

Enter Screen Time Passcode

and:

Enter the Screen Time passcode to change this setting

followed by:

Incorrect passcode

Evidentiary significance

Exhibit A2 establishes that a Screen Time credential entered at approximately 1:37 PM was rejected by the iPhone.

The screenshot does not independently establish:

  • the four digits entered;
  • whether the Screen Time credential had actually changed;
  • who changed it, if a change occurred;
  • whether another Apple device synchronized a configuration;
  • whether an iOS software condition affected Screen Time;
  • whether another individual accessed the Apple Account;
  • whether someone possessed the Apple Account password;
  • or whether unauthorized remote administration occurred.

My statement regarding the credential entered is based upon my personal recollection and the credential I had intentionally established earlier that morning.


XI. DISCREPANCY BETWEEN EXPECTED PASSCODE AND DEVICE STATE

I considered the approximately 1:37 PM Screen Time passcode rejection abnormal because I understood the credential established earlier that morning to be valid.

The event therefore presents a discrepancy between:

  1. the Screen Time credential I understood to be valid; and
  2. the credential state accepted by the iPhone at approximately 1:37 PM.

That discrepancy requires investigation.

It should not automatically be characterized as proof that another person changed the credential.

Potential technical areas requiring review include:

  • Screen Time synchronization;
  • Apple Account synchronization;
  • another device signed into the Apple Account;
  • Screen Time recovery activity;
  • Family Sharing configuration;
  • password or account-recovery activity;
  • configuration-profile activity;
  • mobile-device-management enrollment;
  • backup or restoration activity;
  • iOS software behavior;
  • Apple Account session activity;
  • unauthorized Apple Account access;
  • or another technical cause.

XII. APPROXIMATELY 1:40 PM — SCREEN TIME PASSCODE RECOVERY

At approximately 1:40 PM, because the Screen Time passcode I understood to be valid had been rejected, I entered Apple’s Screen Time Passcode Recovery process.

The Apple iPhone 17 displayed:

Screen Time Passcode Recovery

and:

Enter the Apple Account you provided to reset the Screen Time passcode.

The interface displayed the Apple Account email address associated with the Screen Time recovery process and provided a password field.

For public purposes, the Apple Account identifier is:

[REDACTED APPLE ACCOUNT EMAIL ADDRESS]

I preserved the original screen as Exhibit B1.


XIII. EXHIBIT B1 — SCREEN TIME PASSCODE RECOVERY

Public Exhibit Title:

Exhibit B1 | Redacted Apple Screen Time Passcode Recovery Interface — Approximately 1:40 PM, October 8, 2026

The screenshot visibly establishes that:

  • Apple’s Screen Time Passcode Recovery workflow was active;
  • an Apple Account was associated with the recovery process;
  • Apple requested authentication through that account;
  • and the recovery interface was displayed at approximately 1:40 PM.

The Apple Account email address visible in the original exhibit must be fully obscured in the public derivative copy.

No Apple Account password should be displayed.


XIV. SIGNIFICANCE OF THE RECOVERY PROCESS AFTER THE 11:41 AM PASSWORD CHANGE

The sequence raises an account-security question because I had intentionally changed my Apple Account/iCloud credential at approximately 11:41 AM, and less than two hours later I entered Apple’s Screen Time Passcode Recovery process after the Screen Time credential I understood to be valid was rejected.

I am concerned about whether unauthorized Apple Account or device activity occurred during that interval.

However, important evidentiary distinctions must be preserved:

The fact that I personally entered my Apple Account credentials during the recovery process does not establish that another person knew those credentials.

Likewise:

The Screen Time passcode rejection does not independently establish that another person changed the Screen Time passcode.

These issues require Apple account-security and device records.


XV. REQUEST FOR APPLE ACCOUNT PASSWORD-CHANGE VERIFICATION

I request preservation and confirmation of records concerning the Apple Account credential change that I performed at approximately 11:41 AM on October 8, 2026.

Where available, relevant information should establish:

  1. the exact timestamp of the password change;
  2. the Apple device from which the change originated;
  3. the account session involved;
  4. the originating IP address where retained and legally available;
  5. whether multi-factor authentication was used;
  6. which trusted device approved the activity;
  7. whether a recovery workflow was involved;
  8. whether other Apple Account sessions remained active after the password change;
  9. whether another device authenticated following the change;
  10. whether new trusted devices were added;
  11. whether trusted telephone numbers changed;
  12. and whether any Screen Time recovery activity occurred before my approximately 1:40 PM recovery.

XVI. ESTABLISHMENT OF ANOTHER SCREEN TIME PASSCODE

Following the Screen Time Passcode Recovery process, I established another Screen Time passcode.

For this public version, the credential is:

[REDACTED CURRENT SCREEN TIME PASSCODE]

The current credential should not be reproduced in:

  • public blogs;
  • publicly accessible screenshots;
  • public court attachments;
  • social-media posts;
  • publicly posted complaints;
  • or other publicly distributed materials.

XVII. APPROXIMATELY 2:04 PM — PERSONAL MOBILE NETWORK DEVICE OBSERVATION

At approximately 2:04 PM, I examined personally controlled mobile network equipment.

I preserved a photograph identified as Exhibit C1.

The original image shows manufacturer/device information.

For this public report, carrier-specific and device-specific information is generalized as:

[REDACTED PERSONAL MOBILE HOTSPOT / NETWORK DEVICE]

I also report that I observed what I understood to be an unexpected connected-device count associated with this equipment.


XVIII. EXHIBIT C1 — MOBILE NETWORK DEVICE INFORMATION

Public Exhibit Title:

Exhibit C1 | Redacted Personal Mobile Network Device Information Screen — Approximately 2:04 PM, October 8, 2026

The photograph establishes:

  • physical possession of the network device;
  • that a device-information interface was displayed;
  • and certain hardware/software information in the original image.

For public posting, I recommend redacting or obscuring:

  • carrier branding if desired;
  • exact model identifier;
  • firmware/version information;
  • serial number;
  • IMEI;
  • MAC address;
  • IP address;
  • SSID;
  • passwords;
  • and other identifiers.

The supplied photograph does not independently display a numerical connected-device count.

Therefore, the public report should not describe Exhibit C1 as proving that two devices were connected.


XIX. REPORTED CONNECTED-DEVICE CONCERN

I personally report that at approximately 2:04 PM, I observed information associated with my mobile network equipment indicating two connected devices, while I expected only one personally authorized device to be connected.

I did not knowingly authorize another device to connect.

Because Exhibit C1 itself does not visibly establish the connected-device count, this observation should be corroborated, where possible, through:

  • a separate connected-device screenshot;
  • administration-interface records;
  • DHCP information;
  • client logs;
  • or other device records.

If two clients were present, investigators should determine:

  • MAC address of each client;
  • client hostname;
  • connection time;
  • disconnect time;
  • DHCP assignment;
  • authentication status;
  • device type;
  • and whether the second connection corresponded to another device I personally own.

XX. CONTINUING SCREEN TIME SECURITY CONCERN

I consider the October 8 event significant because it follows other Screen Time passcode irregularities that I have previously documented.

The recurring nature of these incidents makes preservation of Apple Account and Screen Time records important.

Repeated unexpected Screen Time credential rejection may justify review of:

  • Apple Account access history;
  • Apple Account sessions;
  • trusted devices;
  • trusted telephone numbers;
  • Screen Time synchronization;
  • password-change history;
  • Screen Time recovery events;
  • device-management configuration;
  • Family Sharing configuration;
  • and authorized devices.

Repeated events do not independently establish their cause or identify a responsible person.


XXI. CONCERN REGARDING POSSIBLE UNAUTHORIZED ACCESS

I remain concerned that unknown individuals may be attempting to access or influence my Apple devices, accounts, telecommunications services, or network equipment.

I have not authorized such access.

However, the October 8 screenshots do not identify:

  • a neighboring resident;
  • property-management employee;
  • family member;
  • telecommunications employee;
  • computer user;
  • or any other particular person

as responsible for the Screen Time incident.

Any attribution should therefore be based upon objective technical evidence.


XXII. REQUEST FOR APPLE ACCOUNT AND DEVICE SECURITY RECORDS

I request preservation and review of Apple security records for approximately:

10:30 AM through 3:00 PM on October 8, 2026, with a broader period where available.

Relevant records may include:

  • Apple Account sign-in history;
  • successful authentication events;
  • failed authentication attempts;
  • password-change records;
  • trusted-device changes;
  • trusted-number changes;
  • Screen Time recovery events;
  • new-device registrations;
  • account-recovery activity;
  • security notifications;
  • iCloud synchronization;
  • Screen Time synchronization;
  • Family Sharing activity;
  • device additions;
  • device deauthorizations;
  • account sessions;
  • password-reset activity;
  • and related security events.

XXIII. REQUEST FOR TELECOMMUNICATIONS-PROVIDER RECORDS

I request preservation and review of telecommunications-provider records associated with my personal cellular line during the relevant period.

Relevant records may include:

  • SIM history;
  • eSIM provisioning history;
  • ICCID records;
  • IMEI associations;
  • EID information;
  • line-activation history;
  • device-registration information;
  • SIM changes;
  • eSIM downloads;
  • port-out requests;
  • telephone-number transfer requests;
  • carrier-account access;
  • account-PIN changes;
  • customer-service modifications;
  • trusted-device activity;
  • call-forwarding settings;
  • IMS registration;
  • Wi-Fi Calling registration;
  • line-sharing services;
  • connected-device services;
  • and concurrent registrations involving the cellular line.

These records may help determine whether unauthorized telecommunications-account activity occurred.


XXIV. SCREEN TIME PASSCODE REJECTION DOES NOT ITSELF ESTABLISH CELLULAR CLONING

For technical accuracy, Apple Screen Time is primarily an Apple/iOS account and device-control function.

Therefore:

A rejected Screen Time passcode does not independently establish that a cellular telephone number was cloned, mirrored, split, duplicated, or provisioned through another carrier.

Likewise:

Apple’s Screen Time Passcode Recovery interface does not establish that another individual possessed the Apple Account password.

The telecommunications issue becomes materially connected if independent evidence establishes:

  • unauthorized eSIM provisioning;
  • duplicate device registration;
  • unauthorized Apple Account recovery;
  • suspicious trusted-number changes;
  • unauthorized Apple Account sessions;
  • concurrent carrier registration;
  • or another attributable account-security event.

XXV. REQUEST FOR MOBILE NETWORK EQUIPMENT RECORDS

Where technically available, I request preservation of records associated with my personal mobile network equipment, including:

  • connected-client history;
  • client MAC addresses;
  • device names;
  • DHCP assignments;
  • connection timestamps;
  • wireless-authentication records;
  • administrative-login records;
  • configuration changes;
  • firmware records;
  • restart history;
  • hotspot-password changes;
  • and device-management logs.

If an additional client was connected without my authorization, those records may help identify that client.


XXVI. DEVICE-LEVEL FORENSIC REVIEW

A technical review of the Apple iPhone 17 should examine:

  • Apple Account device list;
  • Screen Time configuration;
  • Screen Time recovery settings;
  • Family Sharing configuration;
  • installed configuration profiles;
  • mobile-device-management enrollment;
  • VPN profiles;
  • installed certificates;
  • trusted devices;
  • trusted telephone numbers;
  • Messages Send & Receive settings;
  • FaceTime identities;
  • Wi-Fi Calling configuration;
  • cellular plans;
  • eSIM entries;
  • Bluetooth pairings;
  • accessibility settings;
  • remote-control functionality;
  • and applications capable of device or account administration.

Where possible, existing settings should be documented before changes are made.


XXVII. EXPRESS STATEMENT OF NON-CONSENT

I have not knowingly authorized any unrelated person to:

  • change my Screen Time passcode;
  • reset Screen Time;
  • access my Apple Account;
  • obtain or use my Apple Account password;
  • modify trusted devices;
  • modify trusted telephone numbers;
  • intercept verification codes;
  • register an additional Apple device;
  • access my telecommunications-provider account;
  • provision another SIM or eSIM;
  • transfer my cellular number;
  • duplicate my cellular service;
  • connect an unauthorized device to my network equipment;
  • administer my Apple iPhone 17 remotely;
  • change account-recovery settings;
  • or impersonate me.

Possession of one of my credentials would not itself establish my consent.


XXVIII. PUBLIC EXHIBIT INDEX

ExhibitPublic DescriptionEvidentiary Purpose
A1Apple Screen Time settings displaying “Passcode used today at 11:16 AM”Documents application-visible Screen Time activity
A2Apple Screen Time interface displaying “Incorrect passcode” at approximately 1:37 PMDocuments Screen Time credential rejection
B1Redacted Apple Screen Time Passcode Recovery interface at approximately 1:40 PMDocuments entry into Apple’s recovery workflow
C1Redacted personal mobile-network-device photographDocuments physical device and visible device-information interface
D1 — Not Publicly Posted Unless RedactedApple Account authentication recordsMay establish account-session activity
D2 — Not Publicly Posted Unless RedactedApple password-change recordsMay confirm the approximately 11:41 AM credential change
D3 — Not Publicly Posted Unless RedactedApple trusted-device historyMay identify device/account changes
D4 — Not Publicly Posted Unless RedactedApple Screen Time recovery recordsMay establish recovery activity
E1 — Not Publicly PostedTelecommunications-provider SIM/eSIM historyMay identify provisioning activity
E2 — Not Publicly PostedDevice-to-line association recordsMay establish telecommunications device relationships
F1 — Not Publicly Posted Without ReviewMobile network connected-client recordsMay identify an unexpected network client

XXIX. CONSOLIDATED OCTOBER 8, 2026 TIMELINE

Approximate TimeEvent
Before 11:16 AMPrior Screen Time credential in use
11:16 AMI intentionally change the Screen Time passcode to a new credential
11:16 AMApple Screen Time interface later displays “Passcode used today at 11:16 AM”
11:41 AMI intentionally change the password/credential associated with my Apple Account/iCloud account
1:37 PMScreen Time passcode I understand to be valid is rejected; device displays “Incorrect passcode”
1:40 PMScreen Time Passcode Recovery interface displayed
Shortly thereafterI authenticate through Apple recovery and establish another Screen Time passcode
Approximately 2:04 PMI examine personally controlled mobile network equipment and report concern regarding an unexpected connected-device count

XXX. EVIDENTIARY SIGNIFICANCE OF THE CHRONOLOGY

The chronology establishes a relatively narrow period warranting technical review.

Approximately:

  • 2 hours and 21 minutes elapsed between the 11:16 AM Screen Time activity and the approximately 1:37 PM rejection;
  • 1 hour and 56 minutes elapsed between the 11:41 AM Apple Account credential change and the approximately 1:37 PM Screen Time rejection;
  • and approximately 3 minutes elapsed between the passcode rejection and entry into Apple’s Screen Time recovery workflow.

These time intervals may assist in identifying relevant account, device, or provider records.

They do not independently establish unauthorized access.


XXXI. EVIDENTIARY LIMITATIONS

The presently available exhibits support that:

  • Apple Screen Time was configured;
  • the iPhone displayed “Passcode used today at 11:16 AM”;
  • I report intentionally changing my Apple Account credential at approximately 11:41 AM;
  • a Screen Time credential was subsequently rejected;
  • the iPhone displayed “Incorrect passcode” at approximately 1:37 PM;
  • Apple’s Screen Time Passcode Recovery interface was displayed at approximately 1:40 PM;
  • and Exhibit C1 documents personally controlled network equipment.

The exhibits do not independently establish:

  • that another person changed the Screen Time passcode;
  • who changed it, if a change occurred;
  • that another person knew my new Apple Account password;
  • that neighboring residents accessed my Apple Account;
  • that my cellular telephone number was cloned;
  • that the iPhone was mirrored;
  • that another carrier provisioned my telephone number;
  • that another individual remotely administered the iPhone;
  • that an additional connected network client was unauthorized;
  • or that a criminal or civil offense occurred.

Those issues require independent technical evidence.


XXXII. PRESERVATION OF ORIGINAL EVIDENCE

I intend to preserve original versions of:

  • Exhibit A1;
  • Exhibit A2;
  • Exhibit B1;
  • Exhibit C1;
  • Apple security notices;
  • Apple password-change records;
  • authentication notices;
  • telecommunications-provider records;
  • mobile-network-device records;
  • handwritten records;
  • screenshots;
  • photographs;
  • and related documentation.

Original files should remain unchanged.

Any:

  • redacted;
  • annotated;
  • cropped;
  • resized;
  • highlighted;
  • blurred;
  • or publicly posted

version should be maintained as a separate derivative copy.

Where practical, evidence records should include:

  • original filename;
  • creation timestamp;
  • modification timestamp;
  • file size;
  • image resolution;
  • metadata;
  • and SHA-256 hash.

XXXIII. PUBLIC-REDACTION REQUIREMENTS

Before the exhibits are publicly posted:

Exhibit A1

The screenshot may generally be published after confirming that no:

  • Apple Account identifier;
  • cellular telephone number;
  • device name;
  • private contact information;
  • or other account-identifying information

is visible.

Exhibit A2

The screenshot showing “Incorrect passcode” does not visibly disclose the four-digit credential.

It may generally be used as a public evidentiary copy after confirming that no identifying information appears elsewhere in the image.

Exhibit B1

The original screenshot displays the Apple Account email address.

That information should be completely obscured.

The public copy should display only:

[REDACTED APPLE ACCOUNT EMAIL]

or an opaque redaction bar.

The original image should remain unchanged.

Exhibit C1

Before public posting, obscure any visible:

  • carrier-specific identifiers;
  • exact hardware identifier, if desired;
  • firmware information, if not needed publicly;
  • MAC address;
  • IP address;
  • serial number;
  • IMEI;
  • SSID;
  • QR code;
  • password;
  • device-management identifier;
  • or other information that could assist identification or access to the equipment.

XXXIV. REQUEST FOR INDEPENDENT TECHNICAL ATTRIBUTION

I request that investigators determine, where technically possible:

  1. what Screen Time credential state existed at approximately 11:16 AM;
  2. whether Screen Time configuration changed between 11:16 AM and 1:37 PM;
  3. whether Screen Time recovery activity occurred before 1:37 PM;
  4. whether another Apple device synchronized Screen Time settings;
  5. the exact Apple Account password-change timestamp at approximately 11:41 AM;
  6. which device and account session initiated that Apple Account password change;
  7. whether other Apple Account sessions remained active afterward;
  8. whether another device authenticated following the 11:41 AM credential change;
  9. whether trusted-device information changed;
  10. whether trusted telephone numbers changed;
  11. whether an Apple Account recovery event occurred;
  12. whether telecommunications provisioning changed;
  13. whether another SIM or eSIM became associated with the cellular line;
  14. whether another network client was connected;
  15. the identity of any additional network client;
  16. and whether relevant activity originated from a device or account session that I did not authorize.

XXXV. NO FINAL LEGAL OR TECHNICAL CONCLUSION

The circumstances described in this report warrant additional technical investigation.

I do not assert solely from these screenshots or device behavior that a particular person committed:

  • unauthorized computer access;
  • identity misuse;
  • Apple Account compromise;
  • telecommunications duplication;
  • device cloning;
  • device mirroring;
  • SIM duplication;
  • eSIM duplication;
  • unlawful interception;
  • unauthorized remote administration;
  • or another criminal or civil offense.

Any final technical or legal conclusion should be supported by appropriate Apple, telecommunications-provider, device, network, or forensic evidence.


XXXVI. DECLARATION OF ACCURACY

I, Sarai Hannah Ajai, state that this public-redacted incident report reflects my present recollection, screenshots, photographs, device interfaces, and contemporaneous security actions concerning the October 8, 2026 Screen Time and Apple Account security incident.

I personally report that:

  • I intentionally changed my Screen Time passcode at approximately 11:16 AM;
  • Apple subsequently displayed “Passcode used today at 11:16 AM”;
  • I intentionally changed my Apple Account/iCloud credential at approximately 11:41 AM;
  • at approximately 1:37 PM, the Screen Time credential I understood to be valid was rejected;
  • the iPhone displayed “Incorrect passcode”;
  • at approximately 1:40 PM, I entered Apple’s Screen Time Passcode Recovery process;
  • I authenticated through the recovery workflow;
  • I established another Screen Time passcode;
  • and at approximately 2:04 PM, I examined personally controlled network equipment and documented a separate network-device concern.

Where I describe possible unauthorized Apple Account access, credential compromise, telecommunications duplication, cellular-number cloning, device mirroring, remote administration, or unauthorized network access, those matters are presented as concerns requiring technical investigation, not established findings.

I request preservation of relevant Apple, telecommunications-provider, device, account, authentication, and network records before applicable record-retention periods expire.

Prepared by:
Sarai Hannah Ajai

Primary Incident Date: October 8, 2026
Public-Redacted Report Date: October 8, 2026


      













    

Comments