facebook-pixel

How to Know if Your Phone Is Hacked: 10 Warning Signs

L
Lunyb Security Team
··11 min read

Your phone holds your email, banking apps, photos, two-factor authentication codes, and conversations with nearly everyone you know. That makes it the single most valuable target an attacker can hit. The problem? Modern phone compromises are quiet. There's rarely a dramatic popup saying "you've been hacked." Instead, there are subtle clues — a battery that drains faster than it should, odd text messages you didn't send, apps you don't remember installing.

This guide walks through the 10 clearest warning signs that your phone is hacked, how to confirm whether something is actually wrong, and the concrete steps to take back control. It applies to both iPhone and Android, and it's written so you can act on it today — no technical background required.

What Does It Mean When a Phone Is "Hacked"?

A hacked phone is a device where an unauthorized person has gained access to your data, accounts, or the operating system itself — usually through malware, a malicious app, phishing, a compromised account, or physical access. The attacker's goal is almost always money, identity theft, surveillance, or using your device as a stepping stone to someone else.

Phone compromises generally fall into four buckets:

  1. Malware or spyware installed on the device (stalkerware, banking trojans, remote access tools).
  2. Account takeover — your Apple ID, Google account, or iCloud is compromised, giving the attacker remote visibility without touching your phone.
  3. SIM swap attacks, where someone transfers your number to their SIM to intercept calls and texts.
  4. Network-level attacks, like rogue Wi-Fi hotspots or malicious profiles that reroute your traffic.

Knowing which category you're dealing with changes how you respond, so the signs below are grouped by what they typically indicate.

10 Warning Signs Your Phone Has Been Hacked

1. Battery Drains Dramatically Faster Than Usual

Spyware and crypto-mining malware run constantly in the background, using the CPU, GPS, microphone, or network radio. If your battery life suddenly drops by 30–50% over a few days without any new apps or heavy use, that's a red flag. Check Settings > Battery (iOS) or Settings > Battery > Battery usage (Android) to see which apps are consuming the most power. An unfamiliar app at the top of the list — or "System" using a suspicious amount — deserves a closer look.

2. Your Phone Runs Hot When Idle

A warm phone during a long video call or gaming session is normal. A phone that's hot in your pocket while locked and doing nothing is not. Persistent heat is a classic symptom of hidden background processes — often spyware recording audio, uploading files, or mining cryptocurrency.

3. Unusual Spikes in Mobile Data Usage

Malware has to send stolen data somewhere, and that costs bandwidth. If your monthly data usage suddenly jumps without a change in your habits, investigate which app is responsible. On iPhone, go to Settings > Mobile Data and scroll through the per-app list. On Android, open Settings > Network & internet > SIMs > App data usage. Look for apps you don't recognize or system services using gigabytes you can't explain.

4. Apps You Never Installed Appear on Your Home Screen

Unknown icons, duplicate apps (two WhatsApps, two Chromes), or apps with slightly misspelled names are strong indicators that something was sideloaded. On Android especially, trojan droppers install additional payloads after the initial infection. Don't just hide these apps — uninstall them, and if they can't be uninstalled, they may have been granted device-admin privileges that need to be revoked first.

5. Pop-ups, Redirects, and Browser Changes

If your browser suddenly opens to a different homepage, your searches get hijacked to an unfamiliar engine, or you see pop-ups even when no browser is open, you likely have adware or a malicious configuration profile. iPhone users should check Settings > General > VPN & Device Management for profiles you didn't install. Android users should check installed browsers and recent app permissions.

6. Outgoing Texts or Calls You Didn't Make

Check your call log and messages app for calls, SMS, or messages (including in WhatsApp, Signal, or Messenger) that you didn't send. SMS trojans frequently send premium-rate texts or spread themselves to your contacts. If friends tell you they received a strange link from your number, treat that as a confirmed compromise and act immediately.

7. Suspicious Account Activity and Login Alerts

Login notifications from unfamiliar locations, password reset emails you didn't request, or 2FA prompts appearing on your lock screen out of nowhere all suggest someone is actively trying to use your credentials. If a hacker has your phone, they often have — or are trying to get — your email too. Review Google Account > Security > Your devices or Apple ID > Devices and sign out anything you don't recognize.

8. Settings Change on Their Own

If you find that Bluetooth, location services, or microphone permissions are turned on when you're sure you disabled them, or you discover new accessibility services enabled on Android (a common requirement for stalkerware), someone or something is modifying your device remotely. Accessibility abuse is one of the most dangerous categories because it lets an app read your screen and simulate taps.

9. The Phone Behaves Erratically — Crashes, Freezes, or Reboots

Occasional glitches happen. But repeated unexplained reboots, apps crashing right after launch, or the screen flickering and responding to inputs you didn't make can indicate either malware or an active remote session. Random reboots in particular are sometimes triggered when malware updates itself or when competing malicious processes collide.

10. Your Phone Service Suddenly Goes Dead

If you lose signal completely while others around you have service, and restarting doesn't fix it, you may be the victim of a SIM swap attack. The attacker has convinced your carrier to port your number to their SIM. Within minutes they'll start resetting passwords on your bank, email, and crypto accounts. Call your carrier from another phone immediately.

How to Confirm Whether Your Phone Is Actually Hacked

One symptom alone doesn't prove compromise — batteries age, apps have bugs, carriers have outages. Confirmation comes from combining signs and running checks.

Checks for iPhone Users

  1. Open Settings > General > VPN & Device Management. Any configuration profile you didn't knowingly install should be removed.
  2. Review Settings > Privacy & Security. Check which apps have access to the microphone, camera, location, and photos.
  3. Go to Settings > [Your Name] and review the list of devices signed into your Apple ID. Sign out anything unknown.
  4. Check for jailbreak indicators. Apps like Cydia or Sileo shouldn't exist on a stock iPhone. Their presence means the device has been jailbroken — intentionally or not.
  5. Make sure iOS is on the latest version via Settings > General > Software Update.

Checks for Android Users

  1. Open Settings > Apps and sort by "recently installed." Scrutinize anything unfamiliar.
  2. Go to Settings > Accessibility and review which apps have accessibility services enabled. Only apps you intentionally granted this to (like a legitimate password manager or screen reader) should appear.
  3. Check Settings > Security > Device admin apps. Nothing here should be a surprise.
  4. Run Google Play Protect: open the Play Store, tap your profile, then Play Protect > Scan.
  5. Install a reputable mobile security scanner from a major vendor (Malwarebytes, Bitdefender, ESET) and run a full scan.

What to Do Immediately if Your Phone Is Hacked

If multiple signs line up and your checks confirm something is wrong, speed matters. Here's the response order that limits damage most effectively:

  1. Disconnect from the internet. Turn on airplane mode. This stops data exfiltration and cuts off any remote session in progress.
  2. Change passwords from a different, trusted device — not the compromised phone. Start with email, then banking, then everything else. Prioritize accounts protected only by SMS 2FA.
  3. Revoke sessions and devices in your Google and Apple accounts, plus services like Facebook, Instagram, Microsoft, and your bank.
  4. Call your mobile carrier and request a port-out PIN or SIM lock to prevent SIM swapping.
  5. Uninstall suspicious apps. On Android, you may need to boot into safe mode to remove stubborn malware. Revoke device-admin and accessibility permissions first.
  6. Update the operating system to the latest version to patch any exploited vulnerabilities.
  7. Enable app-based 2FA (authenticator apps or hardware keys) instead of SMS wherever possible.
  8. If you're not sure the device is clean, factory reset. Back up photos and documents, but not apps or system settings. Set the phone up as new rather than restoring from a backup made while infected.

iPhone vs. Android: Which Signs Matter Most?

The warning signs overlap, but the likelihood and typical attack vectors differ between platforms. Here's a quick side-by-side.

Warning Sign iPhone Android
Unknown apps on home screenRare (App Store only) — treat as seriousCommon via sideloading or trojan droppers
Configuration profiles installedClassic attack vector — check oftenNot applicable in the same way
Accessibility services abusedNot applicablePrimary stalkerware mechanism
Pop-ups and browser hijacksUsually a bad profile or Safari extensionOften adware from third-party stores
Jailbreak / root indicatorsCydia, Sileo, unknown tweaksMagisk, SuperSU, unknown root managers
SIM swap signsIdentical risk on both platformsIdentical risk on both platforms
Battery / heat / data spikesReliable indicatorReliable indicator

How Phones Actually Get Hacked

Understanding the entry points makes prevention far easier. In 2026, the vast majority of consumer phone compromises come from a short list of causes:

  • Phishing links in SMS, email, or DMs. A tap on a convincing link leads to a fake login page or a drive-by malware install.
  • Malicious apps, especially from third-party Android stores or sideloaded APKs.
  • Reused passwords. One breached site gives attackers your email login, which gives them your iCloud or Google account.
  • Public Wi-Fi with no transport encryption, or malicious captive portals that push rogue certificates.
  • Physical access — a few unattended minutes is enough to install stalkerware, especially if your passcode is weak.
  • SIM swapping via social engineering of carrier support staff.

Many of these start with a single tap on a shady short link. Being able to inspect links before clicking is one of the simplest defenses available. When you're the one sharing links, using a reputable shortener like Lunyb that offers transparent destinations and click analytics helps your audience trust what they're clicking — and gives you a clean record of where traffic came from. If you're evaluating shortener options for personal or business use, our 2026 buyer's guide to URL shorteners compares the main choices, and this honest review of Lunyb covers its security and privacy posture in detail.

How to Keep Your Phone from Getting Hacked Again

Prevention is dramatically cheaper than cleanup. A short checklist that genuinely moves the needle:

  1. Install OS and app updates within a week of release. Most mobile exploits target already-patched flaws.
  2. Use a unique, long password for your Apple ID or Google account, stored in a password manager.
  3. Switch 2FA from SMS to an authenticator app or hardware security key wherever supported.
  4. Set a carrier account PIN to block SIM swap attempts.
  5. Install apps only from the official App Store or Play Store. Avoid sideloaded APKs unless you truly know the source.
  6. Review app permissions monthly. Revoke anything that doesn't need microphone, camera, contacts, or location.
  7. Use encrypted DNS (such as the built-in options in iOS and Android) to reduce exposure on untrusted networks.
  8. Be skeptical of unsolicited links — especially from "your bank," "the delivery company," or "the tax office."
  9. Lock your phone with a strong six-digit (or longer) passcode and biometrics, never a four-digit PIN.
  10. Encrypt your backups and store them somewhere other than the device being backed up.

Frequently Asked Questions

Can someone hack my phone just by knowing my number?

In almost all cases, no. Knowing your number lets someone send phishing texts or attempt a SIM swap through your carrier, but it doesn't give them direct access to the device. The dangerous step is when you tap a malicious link or when a carrier agent is tricked into porting your number. Protect yourself with a carrier PIN and app-based 2FA.

Does a factory reset remove hackers from my phone?

A factory reset removes almost all forms of malware and spyware, provided you set the phone up as new afterward instead of restoring a backup made while infected. The exceptions are extremely rare — nation-state-grade implants that persist in firmware. For regular consumer threats, a reset plus a fresh OS install is effectively a clean slate.

Will antivirus apps actually detect phone hacks?

Reputable mobile security apps from vendors like Malwarebytes, Bitdefender, and ESET detect the majority of commodity Android malware and stalkerware. On iPhone, antivirus apps are more limited because iOS sandboxes everything, but they can still spot malicious profiles and phishing sites. They're a useful layer, not a complete solution.

How can I tell if someone is reading my text messages?

Signs include messages that appear already read when you open them, delivery reports for texts you didn't send, replies from contacts referencing conversations you don't remember, and unexpected 2FA codes arriving. On Android, check for apps with SMS permissions you didn't grant. On iPhone, check which devices are signed into your Apple ID and iMessage.

Is public Wi-Fi really dangerous for my phone?

It's less dangerous than it used to be because most apps and sites now use HTTPS by default, but it's not zero risk. Rogue hotspots can push malicious profiles, serve fake login pages, or exploit misconfigured apps. Use encrypted DNS, keep your OS updated, avoid logging into sensitive accounts on unknown networks, and dismiss any prompt asking you to install a certificate or profile.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles