Guides

iPhone Photo Security Checklist: How to Stop Your iCloud Photos From Being Hacked

Mehmet Ali Kısacık · Developer of Secure Folder · July 21, 2026 · 8 min read

A hacker in a black hoodie using a tablet displaying a skull, surrounded by chalk symbols and 'Hacker Attack' text.
Photo by Lucas Andrade on Pexels

Key takeaways

  • Two-factor authentication requires both your password and a six-digit code on any new device sign-in, and it's on by default for every Apple ID created on iOS 13.4 or later.
  • A recovery key is a 28-character code that replaces Apple's standard account-recovery process; Apple explicitly warns against storing it in the Passwords app, iCloud Photos, Notes, or iCloud Drive since you'd be locked out of those too.
  • Advanced Data Protection extends end-to-end encryption to iCloud Backup and iCloud Photos, but it requires a recovery key or recovery contact first, and it removes Apple's ability to help you recover the account if you lose access.
  • Apple will never ask for your password, passcode, or two-factor code by email, phone call, or text, so links in "verify your Apple ID" messages should never be tapped.
  • Account security (2FA, a strong password, a recovery key, Advanced Data Protection) protects your whole synced library from remote attackers, but it doesn't stop someone with physical access to an unlocked phone from browsing everything in it.
  • Moving your most sensitive photos into an on-device vault like Secure Folder removes them from iCloud sync entirely, so an account compromise has nothing in the vault to expose.

Most "iCloud hacking" isn't hacking at all in the movie sense. The 2014 leak of celebrities' private photos, still the event most people picture when they worry about this, happened because attackers guessed passwords and reset security questions through targeted phishing and brute-force attempts on individual accounts, not because Apple's servers were broken into. That means the fix is mostly in your hands: a few account settings close almost every realistic path an attacker has.

1. Turn on two-factor authentication

Here's a checklist you can work through in about fifteen minutes, followed by the one thing account security can't do for you.

If two-factor authentication (2FA) is on, signing in to your Apple Account from a new device requires both your password and a six-digit code sent to a trusted device or phone number. Apple states this is designed so that no one else can access your account, even if they know your password. On an iPhone, it's under Settings > [your name] > Sign-In & Security > Two-Factor Authentication.

If your Apple ID was created on iOS 13.4 or later (or the equivalent macOS/iPadOS version), 2FA is already on by default and can't be turned off. Older accounts should check and enable it manually.

2. Use a strong, unique password, not a recycled one

A password you've reused on another site is only as safe as that other site's worst data breach. Apple's own guidance for a strong Apple Account password is the standard advice: long, unique, and not reused anywhere else, ideally generated and stored by a password manager rather than memorized. The 2014 leak involved attackers testing passwords and answers to security questions gathered from other breaches and phishing pages, which is exactly what a unique password and 2FA together defeat.

3. Set up a recovery key (and store it somewhere that isn't your Photos app)

A recovery key is a 28-character code you can generate for your Apple Account that replaces the usual account-recovery process with something only you hold. Apple explicitly warns not to store the recovery key in the Passwords app, iCloud Photos, Notes, or iCloud Drive, since if you're ever locked out you won't be able to open those apps to retrieve it. Write it down, or keep a printed copy somewhere physical and secure. Losing it while it's your only recovery method can lock you out permanently, so this step is worth doing carefully rather than quickly.

4. Review your trusted devices and sign out anything you don't recognize

Under Sign-In & Security you can see every device currently signed in to your Apple Account. If there's a laptop you sold two years ago or a device you don't recognize, remove it. A forgotten trusted device is a standing way in that has nothing to do with your password strength.

5. Turn on Advanced Data Protection if you want end-to-end encryption on iCloud

By default, Apple holds the encryption keys for most iCloud data, which lets Apple help you recover your account and lets services like iCloud.com work. Advanced Data Protection is an optional setting that extends end-to-end encryption to more iCloud data categories, including iCloud Backup and iCloud Photos. With it on, Apple states it does not hold the keys to that data, meaning Apple cannot read it and cannot use it to help you recover your account if you lose access. Because of that trade-off, Apple requires you to set up a recovery key or recovery contact before it lets you turn this on, and it also disables iCloud.com web access to your data unless you approve it from a trusted device each time. It's a meaningful upgrade for anyone who wants their photo library protected even in the event of a server-side breach, but it comes with real responsibility: there's no "forgot password" safety net if you lose both your devices and your recovery key.

6. Be skeptical of "your iCloud storage is full" and "verify your Apple ID" messages

Phishing that mimics Apple's login or storage-warning emails and texts remains one of the most common ways credentials get stolen. Apple will never ask for your password, device passcode, or two-factor authentication code over email, phone call, or text. If a message urges you to sign in immediately through a link, don't tap it. Go to appleid.apple.com directly or check Settings on your device instead.

7. Ask what happens to synced photos when you delete them

iCloud Photos syncs across every signed-in device, including ones you might forget still have access, like an old iPad. Deleting a photo from your iPhone deletes it everywhere it's synced, but only after that sync completes, and it still lives in Recently Deleted for 30 days by default. If you're cleaning house after a security scare, check Recently Deleted too.

Why account security still isn't the whole answer

Every step above raises the bar for someone trying to get into your Apple Account from outside. What it doesn't change is a separate reality: your entire photo library, including anything you'd rather keep fully private, sits in one place that syncs everywhere you're signed in. A strong password and 2FA protect the whole library equally; they don't let you set aside your most sensitive images so a compromised sync, a shared family device, or someone briefly holding an unlocked phone can't casually flip through everything.

That's a different problem from account takeover, and it's the one a dedicated vault app addresses. Secure Folder: Incogni Vault moves the specific photos, videos, and files you choose out of the Photos app entirely and into a separate gallery locked behind its own PIN or Face ID, distinct from your phone's own passcode. Those items stay on your device; Secure Folder doesn't upload vault content to any server, so there's nothing in the vault for an iCloud account compromise to expose in the first place. The trade-off mirrors Advanced Data Protection's: since there's no server-side copy, there's also no cloud recovery if you lose the device and forget your vault PIN, so keeping your own backup of anything irreplaceable still matters. For the same reason, Apple's built-in Hidden album isn't a substitute for this: it's a documented Photos app feature that still syncs through iCloud and unlocks with the same Face ID as the rest of your phone, so it protects against casual browsing but not against the account-level access this checklist is about.

Used together, the two layers cover different threats: account hardening (2FA, a strong password, a recovery key, Advanced Data Protection) protects your synced library from remote attackers, while keeping your most sensitive items in an on-device vault means there's simply nothing there to expose even if an account is ever compromised.

Quick checklist

Here's every step from this checklist in one place:

  • Two-factor authentication: on
  • Password: unique, not reused elsewhere, ideally in a password manager
  • Recovery key: generated and stored offline, not inside iCloud Photos, Notes, or the Passwords app
  • Trusted devices: reviewed, unrecognized ones removed
  • Advanced Data Protection: considered, with a recovery key or recovery contact set up first
  • Suspicious "verify your Apple ID" messages: ignored, verified only at appleid.apple.com
  • Most sensitive photos: optionally moved to a separate, on-device vault

Common questions

Was the 2014 celebrity iCloud photo leak caused by a hack of Apple's servers?

No. It resulted from attackers guessing passwords and abusing security questions through phishing and brute-force attempts on individual accounts, not a break-in to Apple's infrastructure. That's why account-level protections like two-factor authentication close almost every realistic path.

Is two-factor authentication already on for my Apple Account?

If your Apple ID was created on iOS 13.4 or later, yes, it's on by default and can't be turned off. Older accounts should check under Settings → [your name] → Sign-In & Security → Two-Factor Authentication and enable it manually.

Where should I store my Apple Account recovery key?

Anywhere except the Passwords app, iCloud Photos, Notes, or iCloud Drive. Apple explicitly warns against those locations because you'd be locked out of them too if you ever needed the recovery key to regain access.

Does Advanced Data Protection mean Apple can't see my iCloud Photos at all?

Turning it on extends end-to-end encryption to iCloud Photos and iCloud Backup, so Apple states it no longer holds the keys and cannot read that data. The trade-off is that Apple also can't help you recover your account if you lose both your devices and your recovery key.

Does account security like 2FA protect specific private photos, or my whole library?

It protects your whole synced library equally from remote attackers; it doesn't let you set aside particularly sensitive photos. For that, moving specific items into an on-device vault like Secure Folder: Incogni Vault keeps them out of iCloud sync entirely, so an account compromise has nothing in the vault to expose.

Keep your photos yours.

Secure Folder is free on the App Store — everything stays on your iPhone.

Get Secure Folder