Removing a fake administrator account from your Mac
A malware infection that creates a new administrator account on macOS can give an attacker broad control over files, settings, installed applications and security tools. The account may use an ordinary-looking name, appear after installing free software, or be connected to pop-ups claiming that your Mac needs an urgent update.
Act promptly, but avoid deleting the account before collecting basic evidence. A suspicious login can be part of a wider infection involving remote-access software, a browser hijacker, adware, stolen passwords or a configuration profile. The steps below are intended for information and education; the site’s security disclaimer explains the limits of online malware guidance.
Signs an unfamiliar account needs attention
Open Apple menu > System Settings > Users & Groups and review every account. On older macOS versions, the same area may be called System Preferences. An account you did not create, especially one marked as an administrator, deserves investigation. Check the account’s full name, login items and whether it appeared around the time suspicious software was installed.
Other warning signs include a changed homepage, unfamiliar browser extensions, repeated password prompts, disabled security settings, unexplained remote-control apps and files being renamed or encrypted. A Mac that runs hot, shows unusual network activity or displays fake Apple, ATO or parcel-delivery alerts may have more than a simple unwanted user profile.
Do not assume every unknown account is malicious. A second user might have been created by a family member, an employer’s IT provider or a legitimate device-management service. Confirm its origin before removal, particularly if the Mac is used for work, university or a small business.
Contain the Mac before changing accounts
Disconnect Wi-Fi and Ethernet if you believe someone is actively controlling the computer. This can interrupt remote access and prevent further downloads, although it will not remove the infection. Avoid signing in to internet banking, myGov, email or cryptocurrency services from the affected Mac. Australians using NBN connections should also check whether other devices on the home network show similar warnings, but do not reset the router until important evidence has been recorded.
From a separate, trusted device, change the password for your Apple Account and your primary email account. Turn on multifactor authentication and contact your bank immediately if banking details, card information or one-time codes may have been exposed. If the Mac is used for payroll, tax work or customer records, notify the relevant business contact and consider reporting a serious cyber incident to the Australian Cyber Security Centre.
Take photos or screenshots of the suspicious account, alerts, installed applications and dates. Save them somewhere offline rather than emailing files from the compromised Mac. Do not open unknown attachments or run a “cleaner” recommended by a pop-up, as fake security utilities often request administrator privileges themselves.
Find the account and related persistence
In Users & Groups, select the unfamiliar account and note whether it is an administrator, standard user or sharing-only account. Do not remove it yet if you need to establish when it was created. Review Login Items and Extensions, and inspect System Settings > General > Device Management or Profiles for an unfamiliar management profile. A profile controlled by an employer or school should not be deleted without authorisation.
Look for unknown applications in the Applications folder and recent downloads. Pay attention to remote desktop tools, cracked software, browser add-ons and installers obtained from file-sharing pages. Adware can arrive through bundled freeware, so this adware removal guide may help explain how an unwanted installation chain began.
| Finding |
What it may indicate |
Safer response |
| Unknown administrator account |
Malware, unauthorised access or an unapproved user |
Record details, then verify its origin |
| Unfamiliar management profile |
Employer, school or attacker control |
Ask the organisation before removing it |
| Remote-access application |
Legitimate support or persistent intrusion |
Check the developer and installation date |
| Repeated browser redirects |
Adware, hijacker or malicious extension |
Remove suspicious extensions and scan |
| Account returns after deletion |
Deeper persistence or profile control |
Use Safe Mode or professional analysis |
Remove the unwanted administrator safely
After recording evidence and confirming the account is not legitimate, sign in with a trusted administrator account. In Users & Groups, select the suspicious user and choose the delete option. macOS may offer to save the home folder as a disk image, leave it unchanged or delete it. Saving the folder can preserve evidence, but it may also retain malicious files; do not open its contents casually.
If the account cannot be deleted, the delete control is unavailable or it returns after a restart, boot into Safe Mode and repeat the review. Safe Mode limits some startup software and can make persistent malware easier to identify. The method differs between Apple silicon and Intel Macs, so use Apple’s current instructions for the model rather than following a random command from a forum.
Run a reputable, updated anti-malware scan after removing the account. Delete unknown login items, browser extensions and applications only when you can identify them confidently. Avoid terminal commands copied without understanding their effect: an incorrect command can remove legitimate system files or lock you out of the Mac.
Protect files and restore control
Treat passwords used on the Mac as potentially exposed. Change them from a clean device, beginning with email and Apple Account credentials, followed by banking, work and social accounts. Review sign-in history, trusted devices, recovery numbers and forwarding rules. If your bank or superannuation provider reports suspicious activity, follow its fraud team’s instructions rather than relying on a local cleanup alone.
Back up important documents to a clean, disconnected drive or trusted cloud account, but scan the files before restoring them. Do not copy applications, unknown scripts or browser profiles from the compromised account. If ransomware, repeated account recreation or serious system tampering is present, erase the Mac and reinstall macOS from Recovery after preserving essential evidence. A clean reinstall is more reliable than repeatedly deleting visible symptoms.
For a work Mac, contact the organisation’s administrator before erasing anything. A management system may recreate approved accounts, and wiping the device could breach company procedures or remove evidence needed for an incident investigation.
Prevent another account takeover
Keep macOS, browsers and security software updated through legitimate settings. Install applications from the Mac App Store or the developer’s verified website, and reject installers that demand unnecessary permissions. “Free” video tools, cracked apps and fake codec updates are common routes for adware and trojans.
Use a standard daily account and reserve an administrator account for controlled installations. Review Users & Groups, Login Items, browser extensions and Device Management every few weeks. A password manager and multifactor authentication reduce the damage caused by reused credentials.
Practical habits are especially useful on shared home networks and public Wi-Fi at cafés, libraries and airport lounges. Be sceptical of urgent messages claiming to be from the ATO, Australia Post, a bank or Apple, and type official addresses manually rather than following pop-up links.
- Keep a recent backup that is disconnected when not in use.
- Check administrator accounts and management profiles regularly.
- Install software only from trusted, verifiable sources.
- Use unique passwords with multifactor authentication.
- Record suspicious alerts before deleting accounts or files.