Hello Shadic109, I'm sorry you are experience this issue. Bungie.net and the companion app use a player's PSN credentials to sign in. That means that if a person is continuing to sign in to Bungie.net then they have have access to your son's PSN account. You may want to set up two factor authentication. This article has information and links that may help you: https://www.bungie.net/en/Help/Article/12718 Hope that helps.
That’s the point. We set up 2SV Saturday morning. Sunday night a person was able to log on to the iOS companions and remove him from his clan and start transferring items to/from the vault. So I removed the fraudulent linked device. Today, that same fraudulent device was found under the linked devices and once again he was removed from the clan. The clan was cool, but it’s now the 2nd time they’ve had to reinvite him, and at some point they won’t feel it’s worth the effort until this is resolved. So how can a device get linked on the mobile companion when the PS4 has 2SV in place??
You would need to work that out with Sony. Bungie doesn't have any visibility into their login system. All the information is stored and verified by Sony. If they are able to login it is because Sony has verified that the information is valid.