Your phone is running hot in your hand, the battery is draining at an alarming speed, or an aggressive pop-up suddenly flashes across your screen claiming your system is infected. In that moment, it’s completely natural for your heart to start pounding.
Everyday technical hiccups, like a rogue background app, a poor signal, or a warm battery, can look and feel suspiciously like a high-tech breach when you don't know the technical difference between a device glitch, a stolen password, and actual spyware.
Security app developers and predatory ads exploit this exact confusion. They rely on fear-mongering to convince you that standard phone behavior is a crisis, driving you to download expensive $40 "cleaner" apps that often do more harm than good.
The truth? A warm phone and a quick-draining battery are almost never proof of a security breach on their own. In this guide, we’ll strip away the panic and explain how to tell if you’ve actually been targeted, what is really happening behind the scenes, and how to fix it using free tools already built into your phone.
The 12 Signs Your Phone Has Been Hacked, Ranked by Severity
Not all security warnings carry the same weight. Lumping a simple pop-up ad in with a stolen two-factor authentication code creates unnecessary panic and makes real threats harder to spot.
To help you prioritize, here's every major symptom ranked by actual risk.
| Symptom | Tier | What It Likely Means |
|---|---|---|
| Two-factor authentication (2FA) code or password-reset email you didn't request | 1 | Act now: Account compromise attempt |
| Texts or calls in your outgoing log you didn't send | 1 | Act now: Phone or account being used without your permission |
| "No SIM" or sudden service drop | 1 | Act now: Possible SIM swap |
| Verified security alert from Apple or Google | 1 | Act now: real alerts don't cry wolf |
| Unrecognized device signed into your account | 1 | Act now: Active account breach in progress |
| Apps you don't remember installing | 2 | Investigate today: Possible malware or physical tampering |
| Settings that changed on their own | 2 | Investigate today: Configuration tampering or stalkerware |
| Camera or mic light on with no cause | 2 | Investigate today: Check which app is using the sensor |
| Data spike from an app you don't recognize | 2 | Investigate today: Possible background data exfiltration |
| Unexplained charges on your bill | 2 | Investigate today: Possible premium SMS malware |
| Battery drain or heat, alone | 3 | Usually innocent |
| Slow performance or a flood of pop-ups | 3 | Usually innocent, or run-of-the-mill adware |
Tier 1: Smoking Guns
These symptoms are high-probability evidence that your security has been actively compromised. They aren't standard glitches or vague performance hiccups; they are clear, verifiable actions taking place on your phone or account without your consent.
If you spot any of these, an active breach is likely in progress, so you should skip straight to the recovery steps at the bottom of this guide immediately.
- Two-factor codes or password-reset emails you didn't request: Someone likely has your password or is actively trying to bypass your security. Check signed-in devices immediately and change your password from a known trusted device.
- Texts or calls in your outgoing log that you didn't make: Your device or account is actively being used without your authorization. Malware may be sending premium-rate messages, or the account itself is compromised.
- Unexplained "No SIM" error or sudden loss of service: Losing mobile connectivity unexpectedly often points to a SIM swap attack, where an attacker convinces your carrier to transfer your number to a SIM card in their possession. Contact your carrier immediately.
- A verified security alert from Apple, Google, or Play Protect: Official operating system alerts are high-priority notifications. Note: Always verify alerts inside system settings or the official app, as browser pop-ups frequently fake these notices.
- An unrecognized device signed into your account: An unauthorized user is inside your account, capable of accessing emails, personal data, or password reset tools. Address this right away.
Tier 2: Strong Signals
While these signs aren't absolute proof of a targeted hack, they strongly suggest that something on your device is misconfigured, unauthorized, or operating silently in the background. They usually point to lower-level threats like rogue applications, aggressive adware, or stalkerware installed by someone with physical access to your phone.
These are genuine red flags worth investigating today using the built-in inspection tools below.
- Apps you don't remember installing: Unrecognized apps can be leftover bloatware or software installed by someone who had physical access to your unlocked phone. Compare install dates against times the phone was out of your sight.
- Settings that changed on their own: Unexpected VPN profiles, unexpected device admin privileges, or automatic call-forwarding rules indicate configuration tampering or stalkerware.
- Camera or microphone indicator light turning on unexpectedly: Built-in sensor lights warn you when hardware is active. While not absolute proof of surveillance, you should immediately check which application has active sensor permissions.
- Sudden data spikes from unknown applications: While background updates cause occasional usage spikes, a high-volume data transmission from an app you don't recognize suggests background data exfiltration.
- Unexplained charges on your phone bill: Malware historically monetizes access via hidden premium SMS charges. Recurring small charges are a particularly strong signal.
Tier 3: Weak Signals
Tier 3 symptoms are the single biggest driver of false alarms and unnecessary panic. Because phones are complex devices that process a ton of data, standard OS updates, hardware heat, and aging batteries constantly cause performance drops that feel like security issues.
On their own, these symptoms are almost always harmless system behavior. You should only take them seriously if they show up in clusters alongside Tier 1 or Tier 2 signs.
- Battery draining fast or phone running hot: High power consumption and heat are standard side effects of recent system updates, intensive tasks, or battery degradation. On their own, they rarely indicate a hack.
- Sluggish performance, crashes, or sudden pop-ups: System slowdowns occur naturally as hardware ages. Pop-up floods are typically caused by aggressive web advertising networks rather than targeted spyware.
First, Rule Out the Innocent Explanations
Most security guides only focus on worst-case scenarios, but knowing when you don't need to worry is just as important. Scare tactics often drive people to download sketchy $40 "scanner" apps that do nothing, when the real culprit is usually just normal device behavior.

Before you assume the worst about Tier 3 symptoms, run through these common, non-security explanations:
- Post-update sluggishness and heat: If your phone runs hot or loses battery quickly right after a software update, it’s usually just reindexing files and rebuilding caches. It typically settles back down within a day or two. Similarly, heat while fast-charging or gaming is basic physics, not a security breach.
- Pre-installed carrier bloatware: Finding four or five unexpected apps on a new phone usually points to a preinstalled carrier bundle, not an unauthorized break-in.
- Scareware pop-ups: If a browser window flashes an urgent alert saying "Your phone is infected, tap here to fix it," the pop-up itself is the actual attack. Close the tab immediately, don't tap anything inside it, and never install whatever software it offers.
- Testing for bad apps (Android): If you're on Android, restarting into Safe Mode temporarily disables third-party applications. If your performance issues disappear in Safe Mode, you’re dealing with a poorly coded or rogue app, not a deep system hack.
- Fake system alerts: Always verify security notifications by going directly into your device's Settings, the official application, or your account page yourself. Never tap on links embedded inside unexpected messages or web pages.
What "Hacked" Actually Means: Your Device, Your Accounts, or Your SIM
The picture in your head is probably a stranger tapping around inside your phone. The far more common reality: someone's logged into your Google or Apple account from a laptop on another continent, while your phone sits in your pocket behaving perfectly.
To figure out what's going on, it helps to understand that "getting hacked" actually breaks down into three distinct layers.
Layer 1: Your Device
This layer involves malware, spyware, or stalkerware physically running on your phone, causing issues like unknown apps, unauthorized settings changes, unexpected camera or mic activity, or hidden background data usage.
While this is the scenario people worry about most, it’s rarely the most common. Still, device-level threats are very real: Zimperium's 2026 Banking Heist Report tracked 34 active banking malware families targeting 1,243 financial apps across 90 countries, with Android malware-driven financial transactions increasing 67% year over year.

Layer 2: Your Accounts
Here, an attacker gets hold of your password, usually because it leaked in a data breach elsewhere and was reused, and logs directly into your Apple, Google, or social media accounts. Your phone will look completely fine and show no signs of malware, except perhaps a single sign-in notification or an unexpected 2FA code.
Reused passwords from old breaches are the culprit behind the majority of real-world "I got hacked" stories, yet it’s the layer people think to check last. It’s also why we actively search hacker forums for leaked credential dumps and disable any exposed Windscribe accounts we find.
Layer 3: Your SIM and Network
In this scenario, an attacker targets your carrier or network connection rather than the phone itself. A SIM swap transfers your entire phone number and all incoming 2FA texts to a SIM card in the attacker's hands, while unauthorized call-forwarding quietly reroutes your incoming calls.
The telltale sign here isn't a slow phone. It’s your device suddenly losing cell service or displaying a "No SIM" error out of nowhere.
How to Check if Your Phone Is Hacked (Free, Built-In Tools)
You don't need to buy a $40 app store "scanner" for any of this. Everything you need is already built into your phone. You just need to know where to look.
On iPhone (verified on iOS 26)
- Run Safety Check: Go to Settings > Privacy & Security > Safety Check to review who has access to your location, photos, and personal information. (Note: Use the Quick Exit button if you need to close this screen instantly for safety.)
- Review App Privacy Report: Go to Settings > Privacy & Security > App Privacy Report to see which apps have accessed your camera, microphone, or location—and how frequently.
- Audit Profiles & VPNs: Check Settings > General > VPN & Device Management. Remove any configuration profile or VPN you didn't manually set up yourself, as unauthorized profiles are a major security threat.
- Inspect Battery Drain: Go to Settings > Battery and review app usage. Look for unfamiliar apps consuming high battery power in the background, which spyware requires to transmit data.
- Check for Apple Threat Notifications: If Apple suspects your device was targeted by mercenary spyware, they will display a notification banner at the top of your Apple ID page, alongside an official email and iMessage.
- Consider Lockdown Mode: Found in Settings > Privacy & Security > Lockdown Mode, this option strips away advanced system features targeted by high-level exploits. It reduces convenience, but offers maximum security for high-risk individuals.
On Android (verified on Android 15/16)
- Run a Google Play Protect Scan: Go to Settings > Security & Privacy > App security > Google Play Protect > Scan (or open Play Store > Profile Icon > Play Protect). If an app is flagged, uninstall it and run the scan again.
- Check the Privacy Dashboard: Navigate to Settings > Security & Privacy > Privacy Dashboard to see exact timestamps of when apps accessed your camera, microphone, or location. Unrecognized apps in this log are a key warning sign.
- Audit Device Admin Apps: Go to Settings > Security & Privacy > More security & privacy > Device admin apps (or search for "Device admin apps"). Remove administrative privileges for any unfamiliar apps. (Note: Consult IT first if your phone is provided by work or school.)
- Disable "Install Unknown Apps": Search for "Install unknown apps" in Settings and revoke permission for all browsers and file managers. This prevents unauthorized sideloaded apps from installing outside the Google Play Store.
- Inspect Data & Battery Usage: Check Settings > Battery and Settings > Network & internet > Data usage for unfamiliar apps consuming unusually high volumes of background data or power.
Your Accounts
Account compromise happens on Google or Apple servers, not on your handset, meaning your phone can look completely normal while someone else reads your data. Perform these checks in order:
- Change Your Password First: Go to your Google Security Checkup or Apple ID settings and update your password from a trusted device.
- Revoke Unrecognized Devices: Review your active device list and sign out of any session you don't recognize. (Always change your password before doing this, or the attacker can simply log right back in.)
- Update Recovery Details: Verify that your account recovery email address and backup phone number haven't been altered.
- Upgrade Security Controls: Turn on app-based two-factor authentication (2FA) rather than SMS-based 2FA.
- Check Email Forwarding Rules: Open your email settings and confirm no unexpected auto-forwarding rules were created. Quietly forwarding your incoming mail is one of the oldest tricks attackers use to maintain access after a password change.
The Dial Codes: What They Can and Can't Tell You
If you've seen viral videos claiming secret phone codes can reveal if you're being "tapped" or "hacked," there is an important catch: those codes are real, but they only ever answer one narrow question about carrier call-forwarding.
These USSD codes query your carrier's settings, not your phone's internal software:
- *#21# displays your unconditional call forwarding status. On an uncompromised phone, this should read as disabled or off.
- *#62# shows where your calls are redirected when you are unreachable (such as when your phone is powered off or out of service area). This usually points to your carrier's default voicemail number.
- ##002# cancels all active call forwarding rules in one go. Use this with caution: ##002# is an immediate action rather than a check, and running it will clear out legitimate forwarding features (like custom voicemail) that you actually rely on.
- *#06# displays your phone's IMEI (International Mobile Equipment Identity). This is a unique hardware serial number useful for reporting a lost or stolen phone to your carrier—it has nothing to do with detecting malware or hackers.
The Bottom Line on Dial Codes
None of these codes can detect malware, remove spyware, or reveal a compromised online account. If your phone displays an "invalid code" or "connection problem" error when you dial them, it simply means your mobile carrier doesn't support that specific USSD shortcut, not that you've been breached.
These checks are only useful for detecting remote carrier-level tricks such as call redirection. However, if you suspect someone close to you has had physical access to your device, the threat model and the steps to fix it change completely.
If You Think Someone You Know Is Watching Your Phone
When a stranger hacks your account, they usually want money or data. But when someone you know targets your phone, the motivation is personal control.
This is done using stalkerware: monitoring software installed by someone with temporary physical access to your unlocked phone. Stalkerware developers deliberately hide their apps under innocent-sounding names like "family safety," "employee tracking," or "backup utilities" so they don't look suspicious.
The biggest tell isn't a glitchy phone. Stalkerware operates silently, so your handset will often behave completely normally. Instead, the red flag is behavioral: the person knows exact details they have no reason to know, such as private chat messages, confidential emails, or your real-time physical location.
Critical Safety Warning: Prioritize Physical Safety First
If you’re dealing with an abusive partner or a dangerous situation, removing monitoring software can alert the person that you've discovered it. Abruptly cutting off their access can cause a volatile situation to escalate.
- Consult experts before taking action: Reach out to a support organization or domestic violence hotline from a safe, unmonitored device (such as a friend's phone or a public computer) to make a safe exit plan.
- Use Safety Check’s Quick Exit: If you are using iPhone's Safety Check feature to audit shared access, remember the Quick Exit button in the top corner lets you instantly close the screen if someone walks into the room.
A Note on Nation-State Spyware (Pegasus, etc.)
We must distinguish stalkerware from commercial nation-state spyware like Pegasus or Predator. Advanced spyware of this tier is designed to leave zero symptoms and is used almost exclusively against high-value targets like journalists, government officials, and human rights activists.
If you aren't in a high-risk group, you’re extremely unlikely to encounter nation-state tools. If you’re targeted, systems like Apple's Threat Notifications will alert you directly, and turning on Lockdown Mode is your best built-in defense.
What to Do if Your Phone Is Hacked: 8 Steps in Order
Here's the order of operations for responding to a hacked phone, and the order matters as much as the steps themselves.
- If it's safe to do so, disconnect from Wi-Fi and mobile data. This cuts off any live connection. Skip this step, though, if going dark could tip off someone monitoring the phone in person, since a sudden disconnect can escalate a dangerous situation faster than it helps.
- From a different device, change your Google or Apple password first, then email, then banking. Read this one twice: typing a new password on a still-compromised phone can hand that new password straight back to whoever already has the old one. Skipping this order is the single most common mistake people make.
- Sign out of all sessions and review connected devices in your account settings. Signing out everywhere forces anyone else's session to end immediately, even without your new password.
- Remove what you found. Delete unfamiliar apps, profiles, and device admin entries, then run a Play Protect scan again to confirm.
- Call your carrier if anything smells like a SIM swap, and set a carrier PIN while they're on the line.
- If banking apps live on the phone, alert your bank and ask what fraud monitoring they can turn on for your accounts. Watch statements closely for the next few weeks, since fraudulent charges don't always show up right away.
- Factory reset if the signals persist, but restore from a backup made before the trouble started, and reinstall apps one at a time instead of dumping everything back at once. Restoring the wrong backup re-infects a phone you just wiped clean.
- Tell your contacts to ignore any weird messages from you, in case something already went out under your name while the compromise was active. A quick heads-up can stop someone who trusts you from falling for the same scam.
How to Keep Your Phone From Getting Hacked Again
Once you've cleared out an immediate threat, preventing a repeat incident doesn't require buying expensive security suites. Most real-world hacks are prevented by a handful of basic, zero-cost habits:
- Keep your OS and apps updated: Outdated software is one of the most common vectors for automated exploits. Every system patch closes security vulnerabilities that attackers have already discovered.
- Stick to official app stores: Avoid sideloading software or downloading apps from third-party sites. When installing new apps, take five seconds to review the permissions they request instead of tapping "Allow" on autopilot.
- Use unique passwords and a password manager: Account takeover is the single most common attack real people face. Using a password manager is the only practical way to maintain hundreds of complex, non-reused passwords.
- Switch to app-based 2FA: Where possible, move away from SMS-based 2FA and use an authenticator app (or security keys). SMS codes are vulnerable to SIM swaps, while app-based tokens are bound to your physical device.
- Set a carrier PIN today: Call your mobile carrier and set up an account security PIN. This simple step blocks attackers from convincing a support representative to execute a SIM swap.
Realistic Safety: Public Wi-Fi, Phishing, and VPNs
Public Wi-Fi isn't quite the wild west it used to be, but network-level risks still exist. Modern web encryption (HTTPS) has largely tamed classic "coffee shop snooping" on most websites, but unencrypted networks, rogue hotspots, and malicious redirect pages can still trick human users.
Connecting to a VPN encrypts your network traffic, preventing local network operators or untrusted Wi-Fi owners from monitoring or altering your connection.
However, it is important to remember what a VPN can and cannot do: it protects the pipe, not your judgment. A VPN cannot detect malware, remove spyware, fix an infected phone, or stop you from entering your password on a convincing phishing page.
Frequently Asked Questions
What do I dial to see if my phone is hacked?
Nothing that actually tells you that. No code can detect hacking or malware. *#21# and *#62# only show your carrier's call-forwarding status, which catches one narrow attack out of dozens. For everything else, use the checks above.
Can someone hack my phone just by calling or texting me?
Usually, no. A text, not by receiving it, but by tapping its link or attachment. Zero-click exploits exist but are rare, expensive, and aimed at specific targets, not ordinary users.
Can iPhones be hacked?
Yes. They're a harder target than Android on average, but phishing, malicious configuration profiles, a stolen Apple ID password, and the occasional zero-day (an unpatched software flaw) all still apply. Believing "iPhones can't be hacked" is itself a risk factor.
Will a factory reset get rid of a hacker?
It removes virtually all device-level malware, the right move when Layer 1 signs keep coming back. It does nothing for compromised accounts (change passwords) or a swapped SIM (call your carrier), and restoring an infected backup can bring the problem right back.
Can hackers see me through my phone camera?
Possible with spyware, which is why the indicator light exists. But that requires Layer 1, the device itself, to be compromised first. Check your permission dashboard for which apps actually used the camera before assuming the worst.
Will a VPN stop my phone from being hacked?
It protects the network layer: snooping and fake hotspots. It cannot detect or remove malware, or recover a compromised account, no matter what the ad promised. What actually prevents most real hacks is boring: updates, unique passwords, and app-based 2FA.