Samsung Support Hallucinated I Was Under Attack By A Sophisticated Threat Actor!
Samsung Support Told Me a Sophisticated Threat Actor Was Spying Through My Camera. The App They Named Does Not Exist.
#OnyxAudit
On 22 June 2026, a Samsung Members support representative (identified in the chat as I.L.) responded to a routine query about my device with a detailed forensic diagnosis. The rep named a specific malicious package, com.android.camerasaver, and stated it was likely using my camera to spy on me, that it was consuming up to 10 percent battery in the background, and that other users who encountered the same package had reported the same symptoms. The rep called it a sophisticated threat actor and told me the pattern pointed strongly toward compromise, not a simple software bug. They gave me a step by step remediation plan and told me to contact my carrier about a possible SIM hijack.
I searched my device. App list, system search, file scan. com.android.camerasaver does not exist and never has.
Why this matters more than a wrong answer
A wrong technical answer is normal. Support reps get things wrong. What happened here is different in kind.
I.L. did not just misdiagnose a device. They referenced a cohort of other users who supposedly hit the same package with matching symptoms. If the package does not exist, there is no cohort. That detail was fabricated to make the diagnosis sound corroborated rather than speculative.
The response also read less like a person typing a live chat reply and more like generated text: headers like "This Points to Malicious Activity" and "What This Means: A Sophisticated Threat," a bulleted "Immediate Steps" section, a lock emoji. I have asked Samsung directly whether this reply was AI assisted, and if so, whether the tool hallucinated the package name, the battery figure, and the other-users claim. That is a fair question for a company support channel to answer.
I asked for the evidence. Samsung admitted there wasn't any.
I went back and asked for exact log entries, timestamps, and process names. I asked whether the package had been directly observed in logs, or inferred from symptom patterns, or pulled from an internal template.
A second representative, NM, replied that Samsung Members support is not equipped to perform forensic analysis of device logs, cannot verify the presence of a specific package, and cannot confirm any service exists on a device. In their own words, there was no verified log level evidence of malicious activity.
Read those two replies back to back. One week apart. The first states a sophisticated threat actor is manipulating my camera. The second admits the department cannot verify packages, logs, or the claim at all.
There is also a smaller contradiction worth flagging on its own. When I submitted an error report and diagnostic logs through the app, I was told not to exit while the logs uploaded. If nobody downstream can actually verify what is in those logs, what was the upload for?
Why I'm not letting this go
I do forensic privacy and security accountability work publicly. I catch this kind of thing for a living, cross check it against primary sources, and refuse to publish a claim I cannot back with a receipt. That is the standard I hold myself to and the standard I'm holding Samsung to here.
But I was not the target audience this response was written for. Imagine a teenager, or someone in a mental health crisis, or anyone without the background to independently verify a claim like this, being told by a major manufacturer's official support channel that a sophisticated actor is using their phone camera to watch them. That is not a minor support failure. That is a company with support staff or support tooling capable of generating unfounded, alarming security claims and delivering them with total confidence to whoever happens to be on the other end of the chat.
Full screenshots, both replies in sequence, are attached below as evidence. I've submitted this formally to Samsung and will update this post as the investigation moves.
Follow the case:
- X: @BaximusCyber85
- Blog: onyxdigital.bearblog.dev
- GitHub: Baximus855.github.io
Regards, Clayton, aka Onyx