A phone that is hacked usually shows a cluster of symptoms rather than one: battery draining faster than usual, data use jumping, apps or profiles you did not install, and account alerts for logins you did not make. Any one of these on its own is more likely a software bug or a heavy app. Several together, especially after you clicked a link or installed something from outside the app store, is worth acting on. This guide lists the signs in order of how much they mean, shows how to check each one in your phone’s settings, and gives the exact steps to lock things down, from a quick clean-up to a full reset.
Key takeaways
- The strongest signs are things that should not exist: unknown apps, unknown device profiles, forwarding rules in your email, or logins from places you have never been.
- Battery, heat and slow performance are weak signs on their own. Check the battery usage screen to see which app is responsible before assuming the worst.
- Most phone compromises today are not malware on the phone at all. They are stolen passwords, SIM swaps, or someone with physical access who installed a tracking app.
- The fix order is: change the email password from a different device, remove unknown apps and profiles, check account sessions, then factory reset if anything remains unexplained.
- Keeping the phone updated and only installing apps from the official store prevents the large majority of real attacks.
The signs, ranked by how much they mean
Strong signs
- Apps you did not install. Especially ones with generic names such as “System Service” or “Sync”. On Android, check Settings, then Apps, then See all apps, and sort by recently installed. On iPhone, check the App Library and Settings, then General, then iPhone Storage.
- A device management profile or administrator app you did not add. iPhone: Settings, then General, then VPN and Device Management. Android: Settings, then Security, then Device admin apps. Stalkerware and some malware hide here.
- Login alerts or new-device emails you did not trigger. Google, Apple and Microsoft all send these. Do not dismiss them.
- Email rules you did not create. Attackers add forwarding or filters so they can read your mail and hide password reset messages. Check the rules and forwarding settings in your email account’s web interface.
- Loss of mobile service while others are fine. Your number may have been moved to another SIM. Our article on SIM swapping explains this attack and the carrier settings that block it.
- Messages sent from your accounts that you did not write. Friends receiving odd links from you is a clear signal.
Moderate signs
- Data use that jumped with no change in habit. Check the per-app breakdown under mobile data settings. Malware that uploads your data shows up here.
- Pop-ups outside the browser or a browser homepage that changed on its own.
- Settings that changed: an unknown VPN, a new default browser or keyboard, accessibility services enabled for an app you do not recognise.
- Two-factor codes arriving that you did not request. Someone has your password and is trying the second step.
Weak signs (check, but do not panic)
- Battery draining faster. Check the battery screen; a misbehaving legitimate app is the usual cause.
- Phone running warm. Video, games, navigation and poor signal all do this.
- Slower performance. Old phones, full storage and OS updates cause this far more often than malware.
- Odd noises on calls. Almost always a network problem, not a wiretap.

How phones actually get compromised
Knowing the route helps you pick the right fix.
| Route | How it happens | What it looks like | Main fix |
|---|---|---|---|
| Stolen password | Phishing page, data breach reuse | Logins from elsewhere, 2FA prompts, changed settings in accounts | Change passwords, enable 2FA, sign out all sessions |
| SIM swap | Attacker convinces carrier to move your number | Sudden no service, then password resets by SMS | Call carrier, set a port-out PIN, move 2FA off SMS |
| Sideloaded app | App installed from a link or unofficial store | Unknown app, ads, data use, permissions abuse | Uninstall, revoke permissions, reset if unsure |
| Stalkerware | Someone with physical access installs a tracking app | Hidden app, admin or accessibility rights, location sharing | Remove app and profile, reset, change lock code |
| Malicious profile or MDM | You accepted a configuration profile from a link | Profile in settings, VPN you did not add, certificates | Delete profile, reset network settings |
| Exploit with no user action | Rare, targeted, uses unpatched flaws | Often no visible signs | Update immediately, enable Lockdown Mode on iPhone if you are a likely target |
The first two rows account for most real-world cases. Actual malware on a phone that only installs apps from Apple’s App Store or Google Play is uncommon. The US Cybersecurity and Infrastructure Security Agency’s Secure Our World guidance covers the same basics for the general public.
What to do, step by step
Stage 1: Contain (15 minutes)
- From a different device, such as a laptop, change your main email password. Email is where password resets land, so it comes first.
- In that email account, sign out of all other sessions and delete any forwarding rule or filter you did not create.
- Turn on two-factor authentication if it was off, using an authenticator app. The 2FA setup guide has the menu paths.
- Check the account’s recovery email and phone number. Attackers change these to keep a way back in.
Stage 2: Clean the phone (30 minutes)
- Uninstall every app you do not recognise. If one will not uninstall, remove its device admin or accessibility rights first, then try again.
- Delete unknown configuration profiles (iPhone) or device admin apps (Android).
- On Android, run Google Play Protect from the Play Store menu. Google’s Play Protect support page explains what it scans.
- Review app permissions for location, microphone, camera, SMS and accessibility. Revoke anything that does not make sense.
- Update the operating system and every app.
- Reset network settings to clear rogue VPNs and proxies.
Stage 3: Secure the rest (an hour)
- Change passwords on banking, social and shopping accounts, prioritising any that share the email password. A password manager makes this bearable; our password manager comparison covers the options.
- Sign out of all sessions on each account and review connected apps.
- Call your carrier, confirm no SIM change was requested, and set a port-out PIN.
- Check bank and card statements for the last month.
- Change your phone’s lock code and, if someone close to you may have had access, consider whether they know the new one.
Stage 4: Factory reset if anything is unexplained
If symptoms continue after the steps above, or you found stalkerware, reset the phone. Back up photos and contacts first, but do not restore a full device backup taken while the phone was compromised; set it up as new and reinstall apps from the store. On iPhone: Settings, then General, then Transfer or Reset. On Android: Settings, then System, then Reset options.

Prevention that actually works
- Install apps only from the official store. Sideloading is the main way malware reaches Android phones.
- Install updates within a few days. Most exploits target flaws that were patched months earlier.
- Use a unique password per account and an authenticator app instead of SMS.
- Do not tap links in unexpected texts, even if they look like a delivery notice. Go to the service’s app instead.
- Set a strong lock code and a short auto-lock time. Physical access is how stalkerware gets on.
- Turn on find-my-device so a lost phone can be wiped remotely.
- If you are a journalist, activist or executive who might be targeted, enable Lockdown Mode on iPhone or the equivalent advanced protection on Android, and consider a device from our privacy-focused phones guide.
Common mistakes
- Changing passwords on the compromised phone. If a keylogger is present, the new password is captured too. Use another device.
- Restoring a backup taken after the compromise. It can bring the problem back.
- Installing a “cleaner” app found through a pop-up. That is often the malware.
- Ignoring 2FA prompts you did not trigger. That is an attacker with your password, live.
- Assuming a warm phone means spyware. Check the battery screen first.
Who this is not for
If your only symptom is a slow or hot phone with no unknown apps, no unexpected logins and no strange messages, work through the battery and storage screens before anything else; the answer is almost always an app or a full disk. If you believe you are being targeted by a government or a well-funded group, the steps here are a start but not enough; contact a digital security organisation that helps at-risk people. And if a partner or family member may have installed monitoring software, resetting the phone can alert them; domestic abuse support services can advise on doing it safely.
Frequently asked questions
Can someone hack my phone just by calling me?
No. A call or a text on its own does not install anything. The risk is in links you tap and attachments you open, or in giving codes to a caller.
Can an iPhone get malware?
Rarely, and mostly through targeted exploits or malicious configuration profiles. The more common iPhone problem is a compromised Apple ID, which is an account issue rather than malware.
Does a factory reset remove everything?
It removes apps, profiles and data, and clears almost all malware. It does not fix a stolen password or a SIM swap, which live outside the phone.
Should I install antivirus on my phone?
On Android, Play Protect is built in and covers the common cases; a reputable third-party app adds some phishing protection. On iPhone, apps cannot scan other apps, so “antivirus” there is mainly web filtering.
How do I know if someone is tracking my location?
Check who you share location with in Google Maps, Find My and messaging apps, then look for unknown apps with location permission. Also check for unfamiliar Bluetooth trackers using your phone’s tracker detection feature.
