How to Tell If Your Phone Has Been Hacked: 7 Signs (2026)

If you want to know how to tell if your phone has been hacked, look for patterns rather than a single symptom. A phone that is genuinely compromised usually shows several at once: apps you never installed, a green or orange dot near the camera when nobody is using it, unknown calls in your log, and data usage that runs away from your normal pattern. The check below takes about twenty minutes and uses only settings your phone already has, so nothing has to be bought or installed to start.

Most people who think they were hacked turn out to have a worn battery or a buggy app update, and I have seen both on the same phone in the same week. That is worth knowing because the rush to wipe everything often destroys the evidence you will need later. Work through the steps in order, note what you find, and only then decide how much cleanup you need.

Table of Contents

What You Need

Gather this before you start, and the whole check goes faster:

  • The phone itself, charged above 50% so a factory reset, if it comes to that, does not die halfway through.
  • A second, clean device. Ideally your laptop or another phone you are confident is not compromised. Password changes and account reviews must happen there, not on the phone you suspect.
  • Access to your email password. Your email is the master key. If an attacker can reset it, they can reset everything else that uses your email address.
  • Your carrier account login and the account PIN, plus the passcode or number listed in Settings under About or SIM status.
  • Two-factor authentication codes for your main accounts, from wherever you store them.
  • A USB or cloud backup option for photos, contacts, and files, in case you need to wipe the device later.

If the phone is the only device you have, do steps one through four first, then use your carrier’s website from a public library or work computer rather than a shared one. Café and hotel computers carry their own problems.

How to Tell If Your Phone Has Been Hacked: Step-by-Step

How to Tell If Your Phone Has Been Hacked: Step-by-Step

The seven checks below run from the most visible evidence to the least. If you find something at step one, you can often stop worrying about step six.

1. Check for unfamiliar apps, accounts, and device activity

On Android, open the Play Store, tap your profile picture, and choose Manage apps, then sort by recently installed or by last updated. Anything you do not remember installing deserves a look, especially an app with no reviews, a generic name, or permissions it has no business needing. Two Android screens matter more than the rest: Settings > Apps > Special app access > Device administration apps lists anything holding device control, and Accessibility lists services that can read everything on screen and tap on your behalf. Stalkerware lives in that second list far more often than anywhere else.

On iPhone, open Settings > General > VPN & Device Management. If it says No Profiles, nothing has installed a configuration profile, which is good. Any name you do not recognise, especially one labelled as a device management profile or corporate access, is a reason to stop and investigate. Profiles are how some monitoring tools get onto an iPhone without the App Store.

Then check the codes people search for, with realistic expectations. They are diagnostic, not proof.

  • *#06# shows the IMEI on most Android phones and some feature phones. On iPhone the IMEI sits in Settings > General > About. An IMEI you do not recognise means a second device may be registered on your account.
  • *#21#, *#61# and *#62# check unconditional and conditional call forwarding. If they return nothing, or a confirmation, forwarding is off. These codes do not prove a phone is tapped and cannot see a listening device that never touches your call settings.
  • *#*#4636#*#* opens an engineering menu on many Android phones with network information. On iPhone, *#*#1234#*#* opens Field Test Mode, which shows signal strength and cell details. Samsung service menus usually sit behind *#*#1234#*#*.

People who went through a SIM swap describe the same first clue: service that suddenly drops to No Service, sometimes for a few hours, with no outage on the carrier’s side. If that happened and you did not lose or break the SIM, contact your carrier immediately and ask whether your line has been ported out.

2. Look for unusual messages, calls, or browser activity

Open your call log and read it in full, not just the recent tab. Calls you placed but do not remember, incoming calls from numbers you do not recognise, or a burst of one-minute voicemail calls are all worth noting. Then read your sent messages: phishing often produces a message you replied to and forgot, which is the actual route in, not a mysterious failure.

In the browser, check history and downloads for sites you never visited. Pop-ups that appear with no site open, redirects from a search to an unfamiliar store, and a new home page you did not set usually point to adware or a rogue extension. On iPhone, look under Settings > Safari > Extensions and confirm you recognise each one.

Check your messaging apps separately, because linked devices are easy to miss. In WhatsApp, open the menu, tap Linked devices, and log out anything you did not pair. Instagram has Similar accounts activity, Messenger has Active sessions, and Google has your security page. Each of those screens lists what is currently signed into your account, and an unfamiliar entry there is a stronger signal than a suspicious text.

3. Inspect battery, data, storage, and performance changes

Battery drain alone means almost nothing, because a three-year-old battery behaves exactly like malware. What makes it meaningful is the pattern underneath it. On Android, Settings > Apps > See all apps > three dots > Sort by Battery usage shows which app consumes the most. If one app you never chose sits at the top while your usual apps sit low, that is a real signal.

On iPhone, Settings > Battery > Battery Usage & Levels shows the same breakdown by app and, on recent versions, by what ran in the background.

Apply the same method to mobile data. Settings > Data Saver > Data usage on Android and Settings > Cellular > Cellular Data on iPhone break usage down per app. Check whether an unfamiliar app or a browser you are not using is responsible. Background data is where a remote access trojan sends everything it collects, so this one line matters more than the rest.

Overheating follows the same logic. A phone warm while charging, or hot right after a long video call, is normal. A phone that runs hot while sitting idle on a table is not. Storage that drops sharply overnight, files you cannot open, or photos replaced by encrypted gibberish all point to ransomware, which is rarer than people assume but worth recognising immediately.

4. Review privacy settings, permissions, and location access

Modern phones display a coloured indicator whenever the camera or microphone is active. On recent iPhones the dot sits in the top right of the status bar, on Android it appears in the upper corner too. A dot that lights up with no app in the foreground is one of the clearest signs of monitoring, so treat it as meaningful rather than decoration.

Walk through permissions and ask whether each app needs what it has. A weather app with microphone access, a flashlight with contacts permission, a wallpaper tool with location access. You do not need to remove everything; you need to remove what makes no sense.

On Android, also review Settings > Apps > Special app access > Installed apps > Install unknown apps. If an app can install other apps, someone can add malware quietly. On iPhone, check Settings > Privacy & Security > Location Services and turn on Share My Location or Find My so you can see where the device has been. Abusive partner monitoring is a real pattern in forums, and it rarely shows up as anything more obvious than a battery that empties faster than it used to and a partner knowing details nobody said out loud.

5. Check important accounts and change exposed passwords

Start with email, always. Nobody else can help you decide whether your phone is compromised if your mail account belongs to an attacker. On a clean device, open your provider’s account security page, review active sessions and forwarding rules, and change the password to something long and unique. Add an authenticator app or hardware key, and remove any recovery method you do not recognise.

Then work down the list: online banking, PayPal and any payment app, social accounts, cloud storage where your photos live. Change each password from the clean device and sign out every session. If a password was reused anywhere, change it there too.

Watch for two-factor codes you never asked for. An unsolicited code arriving after you changed a password is normal and harmless. One arriving while you are logged out means someone is attempting to take the account, and you should change the password and report it to the provider.

6. Run a reputable mobile security scan

Run the built-in tools first. On Android, Play Protect scans on install and can be run manually from the Play Store. On iPhone, Settings > Privacy & Security > App Management > Safety Check does something similar and flags configuration profiles, which matters on iPhone because third-party apps cannot install them.

If the built-in tools come back clean and behaviour is still wrong, a free reputable scanner catches more. Malwarebytes Free is the name that comes up most often in support communities for a reason. Run it, read what it names, then remove the offending app, revoke its permissions, and change any password it may have captured.

Skip anything you found through a pop-up, a full-screen ad, or a search result promising to clean your phone for you. That is the most common route to the problem in the first place. On Google Play, a useful rough signal is a recent review count, though it is not a guarantee. Community advice consistently favours built-in tools and well-known free scanners over paid suites, largely because paid suites push upsells.

7. Back up, remove access, and monitor the phone

If you found something real, work in this order. Photograph whatever suspicious you saw before deleting it: app names, profile names, forwarding status. Then back up photos, contacts, and documents to cloud storage or a computer. Skip backing up unknown apps and anything you did not put there yourself.

Remove the app, then remove its traces. On Android, revoke device administrator and accessibility access first, because the app cannot be uninstalled until you do. On iPhone, delete the profile under Settings > General > VPN & Device Management before deleting the app. Then revoke permissions, clear the browser’s saved passwords, and change every password that app could have seen.

A factory reset is the last resort, not the first. It removes local evidence, so document first, and understand that it does nothing about a compromised email account, which is where re-entry usually comes from. After the reset, restore only what you trust.

Finally, ask your carrier to lock the line with a port-out protection PIN, and confirm your account passcode is set. It takes one call, it is free, and it is the single most effective defence against a SIM swap. Then keep watching: sign-in alerts, transaction notifications, and credit reports for a few months. Reports of post-compromise abuse cluster around identity theft and financial fraud appearing weeks after the phone itself was fixed.

Common Mistakes

Treating battery drain as proof. A tired battery is the most common false alarm there is. Check the per-app breakdown before you worry; the number matters, not the feeling.

Wiping the phone before you document anything. Once you reset, the app, the profile, and the timestamps are gone. Take pictures first.

Installing a cleaner or antivirus app from a pop-up. That pop-up is often the bait. You would be installing the problem you are trying to remove.

Changing passwords on the phone you suspect. A keylogger or remote access tool can capture the new one as you type it. Switch devices first.

Reading too much into *#62#. It only reports whether call forwarding is configured. It says nothing about listening devices, and no USSD code confirms a phone is tapped.

Securing everything except email. Password resets for most accounts travel through your inbox. If email is not clean, nothing else holds.

Skipping the carrier. Port-out protection is unknown to most people and costs one phone call. Ask for it while everything is quiet.

Frequently Asked Questions

What are the most common signs that a phone has been hacked?

The most common signs appear together: apps you did not install, unknown calls or messages, a camera or microphone indicator that lights up on its own, battery and mobile data use that spikes suddenly, pop-ups and redirects in the browser, and two-factor codes you never requested. Any one of these alone can be innocent. Several at once, especially an unfamiliar app plus unexplained data use, is the pattern worth acting on.

Can someone hack my phone just by sending a text message?

A text message by itself cannot take over a phone. It can, however, lead to a convincing phishing link that tricks you into entering your password or installing an app yourself, which is how most compromises actually start. Ignore unexpected texts with links, especially ones claiming to be a bank, a delivery company, or your employer. Delete them and never open the link.

How can I check whether my iPhone or Android phone has suspicious apps?

On Android, open the Play Store, tap your profile icon, choose Manage apps, sort by recently installed, and also review Device administration apps and Accessibility under Special app access. On iPhone, open Settings then General then VPN u0026amp; Device Management; anything there you did not install is not normal. Run Play Protect or Safety Check next, then a reputable free scanner if you want a second opinion.

Should I factory reset my phone if I think it has been hacked?

Not as your first move. A reset destroys the evidence and the malicious app, but it leaves your email account open, and that is usually how the same attacker gets back in. Photograph what you found, back up your photos and contacts, remove the app and revoke its permissions, and secure your email from a different device. Reset afterwards if the behaviour continues.

Why is my phone using mobile data when I am not using it?

Check the per-app breakdown first, because background sync, photo uploads, and streaming apps are the usual explanations. On Android open Settings then Apps then See all apps and sort by data usage; on iPhone open Settings then Cellular. If the usage comes from an app you do not recognise, or from your browser while it is closed, that is a meaningful sign rather than noise.

What should I do first if my bank account is connected to a hacked phone?

Contact your bank through its official app or website and the number on the back of your card, and ask them to review recent transactions and flag the account. Do not act on any call or text that asks for your banking details. Then change your email password from a clean device, because bank password resets run through your inbox. Finally, check for unauthorised payments and keep the receipts.

Start with three things, in this order. Move off any network you do not trust, change your email password from a different device and turn on two-factor authentication, then read your app list and permissions looking for something that does not belong. That covers the large majority of cases. If you are dealing with monitoring by someone in your household, add a carrier port-out PIN and consider talking to a domestic abuse support service before changing settings they can see.

Leave a Comment

Daily news, sports and entertainment, explained

Read today's explainers