Am I Hacked? What Actually Counts as Evidence

Am i hacked? Why a hot battery and pop-ups prove nothing, which signs really matter, how to check your phone and accounts, and what to do first if it is real.

A dark reflective panel lying flat on a surface, catching a single soft band of warm light, with nothing discernible on the surface itself

Am i hacked, typed into a search box at eleven at night, is one of the most honest questions on the internet. Something felt off. The battery ran hot, the data allowance vanished faster than usual, an advert appeared where none should be. Within seconds the web offers a list of twelve signs your phone has been hacked, and at the bottom of that list sits a security suite with a discount code.

This piece runs the other way round. It first clears out the observations that almost always have a dull explanation, then names the ones that genuinely count, and shows how to reach a defensible answer in about twenty minutes. The last section is an order of operations for the real thing, because when it has actually happened, sequence decides how much damage follows.

Most symptoms are not symptoms

Start with the uncomfortable part. The standard checklist consists largely of things a three-year-old phone does anyway. That does not rule out an intrusion. It means none of these observations, taken alone, carries any weight.

The battery gets hot and dies early. Lithium cells lose capacity with every charge cycle. Apple rates eighty percent after around five hundred charges as normal, and in practice many phones sit just above seventy percent after two or three years. That alone is enough to break a full day of use. Add background app refresh, location services and an operating system that demands more with each release. Heat comes from charging, from navigation and from a summer afternoon on the dashboard.

Mobile data disappears. Autoplaying video in social apps is by far the largest consumer, followed by cloud backups that slipped onto the mobile network when the Wi-Fi dropped. Monitoring software mostly ships text logs and compressed packets, which barely register next to one autoplayed clip.

The device has become slow. Storage below ten percent free, a dozen apps resident in memory, an OS built for newer silicon.

Pop-ups appear. Usually the browser or a free app with an aggressive ad network, and quite often a web push notification somebody permitted long ago, which can be switched off again under site settings.

Many small warm points of light on a dark background, most of them blurred and fading, while a single brighter patch of light burns on steadily
Twelve warning lights, eleven of them noise. The skill lies in spotting the twelfth.

None of this is reassurance for its own sake. It is the precondition for noticing the real signal at all, because anyone who reads every warm phone case as an attack has stopped paying attention by the third false alarm. The security industry calls that alert fatigue, and it is the most reliable ally an attacker has.

The dial code myth

One piece of advice refuses to die: type *#21# into the phone app and you will see whether you are being monitored. Tabloids reprint it every few months and it loops endlessly on short-video platforms.

The code does do something, just not that. It is an MMI command that asks the mobile network about the status of call forwarding, meaning whether calls are being diverted to another number. That is a network feature, not a phone feature. *#62# queries forwarding when unreachable, which on almost every contract points at your own voicemail platform, so an unfamiliar-looking number appears there by design. That voicemail number is precisely what the viral videos present as proof of a wiretap.

Spyware installed on a handset reads messages, reaches for the microphone and location, and ships all of it to a server. None of that touches call forwarding in the carrier network, which is why no MMI code can reveal it. The codes are genuinely useful for checking whether someone set up a diversion, for instance after a SIM swap. As a hacking test they are worthless.

What actually counts

Reliable indicators share one property: behind each of them sits an action you did not perform. An event with a timestamp, rather than a condition open to interpretation.

Sign-ins that were not you. Google, Apple, Microsoft and every serious mail provider keep a sign-in log with time, device and approximate location. Access from a country you have never visited is a hard finding. Read it carefully though, since a VPN or mobile roaming can shift the reported location.

Messages in your sent folder that you did not write. The classic marker of a compromised account, because attackers like to use mailboxes for further distribution. Equally telling: mail that vanishes from the inbox, because a newly created filter rule sends provider security warnings straight to the bin.

Two-factor codes without a login attempt. If a verification SMS arrives while you are doing nothing at all, someone is trying your password at that exact moment. The password is burnt regardless of whether the attempt succeeded.

Changed recovery details. An unfamiliar phone number or secondary address on the account, a new forwarding rule, an extra app password. This is how an intruder makes themselves permanent, and it does more long-term harm than the break-in itself.

Apps you never installed, especially ones with plausible system-sounding names. Alongside them: devices listed on your account that are not yours, and a linked desktop session in WhatsApp you do not recognise.

Money moving. Small test charges, an app store purchase, an order shipped to an address you have never seen. Where funds move, the diagnosis is usually made.

Am i hacked: a five-step check

The following takes twenty minutes and ideally a second device. Work through it in order and delete nothing along the way.

A row of heavy dark toggle switches receding into darkness, with a single one of them caught in warm light
Five switches worth checking. The order is not decorative.

One: test the address against known breaches. Enter your email address at haveibeenpwned.com and you get the list of published data breaches it appears in. The service is run by an Australian security researcher, costs nothing, and is treated as a reference across the industry. For the accompanying password check your password is never transmitted: the browser hashes it, sends only the first five characters of that hash, and the comparison happens locally. The technique is called k-anonymity, and it is the reason the site can be used with a clear conscience.

A hit means your address leaked somewhere. It becomes a problem the moment you reused that password elsewhere, since automated credential stuffing is exactly what attackers do with those lists.

Two: the active sessions on your main accounts. Every large provider shows, under security, which devices are signed in and when they last checked in. On a Google account that is the same security area that matters when you look into your profile more broadly, which we covered in what Google knows about you. Remove anything you cannot place, and while you are there, review mailbox forwarding and filter rules.

Three: the app list and the permissions. Sort installed apps by install date, which exposes recent arrivals far better than scanning a grid of icons. Then check which apps may reach location, microphone and camera. Both systems now record which app used a sensor last, and iOS shows a coloured dot in the status bar while a sensor is live.

Four: the two settings pages nobody ever opens. On iOS, Settings, General, VPN and Device Management holds the configuration profiles. Profiles normally come from an employer or a VPN app. One you did not install yourself is a serious finding, since a profile can reroute traffic and enforce settings. On Android the equivalents are device admin apps, notification access and above all accessibility services. Those exist for people with impairments and allow an app to read screen content and observe input, which is why stalkerware takes that route almost every time.

Five: battery and data use per app. Both platforms keep statistics on which app consumed how much energy and traffic. The interesting entry is not the leader but the outlier: an app you never open that has been busy in the background for weeks.

If it is real: order of operations

Once the check produces a genuine finding, one rule governs everything. The possibly compromised device is useless for the rescue operation, because a password change watched by a bystander is not a password change.

A heavy dark door with a metal handle, a narrow vertical strip of warm light standing along its edge
Close the door first, tidy up afterwards.

1. Get a second device. A laptop, a trusted person’s phone, a freshly reset tablet. Everything below happens there.

2. Change the email password first. The mailbox is the master key, because password resets for nearly every other service arrive in it. Then work outward: bank, cloud storage, Apple or Google account, social networks, each with its own long password. A password manager removes the memorising, and reuse of one password across services is the single mistake that makes most breach chains possible.

3. End all sessions. Almost every service offers a sign out everywhere button. Use it, otherwise an already open session survives your new password untouched.

4. Turn on two-factor. Prefer an authenticator app over SMS, since SIM swapping defeats the SMS route. Store the recovery codes somewhere that is not the affected device.

5. Audit the recovery details. Secondary address, phone number, forwarding, filters, connected apps. Anything you did not set up goes. This step is the one most often skipped, and it is the door attackers walk back through.

6. Clean the device. Install the system update, remove unknown apps, revoke suspicious permissions and profiles, reboot.

7. Reset if doubt remains. A factory reset is the only measure that reliably removes anything living close to the system. On an iPhone the path is Settings, General, Transfer or Reset iPhone, Erase All Content and Settings. On Android it sits, depending on the maker, under Settings, System, Reset, Factory data reset. Before you trigger it, make sure you know the credentials of your Apple ID or Google account, otherwise the activation lock will shut you out of your own device once the reset is done.

What matters is what comes next: set the device up as new and reinstall your apps one by one instead of restoring a backup. A backup made shortly before or during the compromise would carry the problem straight back in, and the whole effort was for nothing. Photos and documents you can pull back separately from the cloud or by hand, while the apps themselves come fresh from the store. (If you want the opposite, wiping a device so that nothing is left before you sell or hand it on, that is its own subject, taken apart in our piece on deleting data permanently.)

8. Report where it matters. Your bank and the police if money moved, the provider for a hijacked account, and the relevant data protection authority if business data was involved.

The case that changes the rules

Everything so far assumed an attacker somewhere on the network who does not know you. There is a second case, and it accounts for most genuine monitoring software found on phones in practice. It is installed by people with physical access: partners, ex-partners, relatives. The programs are sold openly as parental controls or anti-theft tools and run invisibly once configured.

Two identical old metal keys lying side by side on a dark surface, one clearly visible in a band of warm light, the second almost entirely swallowed by shadow
There is a second key. It belongs to someone standing close.

Technically, the same places apply: accessibility services and device admins on Android, configuration profiles and the Apple Account device list on iOS. Apple added a dedicated Safety Check in iOS 16 that gathers every sharing arrangement with other people in one screen and can stop all of it in a single action. It carries a quick exit button in the top corner, a detail that says a good deal about who the feature was built for. On Android, Play Protect flags a share of these tools, and the Coalition Against Stalkerware, a joint effort of security vendors and victim support organisations, maintains guidance and contacts.

Also consider the quieter route: no software is needed when somebody knows your account password. Shared family accounts, a known iCloud password or an active location share deliver the same picture without anything being installed at all.

Overview: symptom, likely cause, evidential value

ObservationMost likely causeEvidential value
Hot battery, poor runtimecell ageing, background servicesvery low
High data usageautoplay video, cloud backup off Wi-Filow
Pop-ups and advertsweb push notifications, free applow
Device feels slowfull storage, older modelvery low
Unknown app installedsomeone had the unlocked devicehigh
2FA code without a loginsomeone has your passwordvery high
Unknown device on accountactive accessvery high
Recovery address changedattacker securing their accessvery high
Unknown configuration profile (iOS)deliberately installedvery high
Unknown accessibility service (Android)typical of stalkerwarevery high

Prevention is dull and free

The measures that help most are boring ones. A unique long password per service out of a password manager stops the chain reaction after a breach. Two-factor authentication renders a stolen password mostly useless. System updates close the holes that automated attacks rely on, and a six-digit lock screen prevents the two minutes of access that installing stalkerware requires.

Add one habit that rarely gets mentioned: once a quarter, review the device list and connected apps on your three most important accounts. It takes five minutes and turns up sessions nobody remembers granting. For the wider picture of what sits about you in the open regardless of any intrusion, our article on what metadata reveals about you covers the ground.

What remains

The honest answer to the question in the title is usually no, and your phone is simply three years old. That answer sells no security suite, which is why it appears so rarely.

What makes a device suspect is not its condition but an event you did not cause: a sign-in at an hour you were asleep, a verification code for a login nobody attempted, an app that is simply there. Once one of those applies, the reassuring part is over, and the sequence above takes over: second device first, then the mailbox, then everything else. Twenty minutes well spent, even when the result is that nothing was wrong.

Frequently asked questions

My phone has been hacked, what should I do first?
Pick up a second device before you touch anything else. Change the password of your email account first, because password resets for everything else run through that mailbox, then work through banking, cloud storage and social accounts. Switch on two-factor authentication, sign out every active session and check the recovery address and forwarding rules of your mailbox. Only then deal with the phone itself: install the system update, remove apps you do not recognise, review permissions. If a solid suspicion remains, a factory reset is the only clean cut.
How do I know if my email has been hacked?
Start at haveibeenpwned.com, enter your address and see which published breaches it appears in. A hit only tells you the address leaked somewhere, not that anyone is in your mailbox right now. For that, open your provider security settings and look at active sessions, the sign-in history, and any forwarding rules or filters. A quiet forward to an unfamiliar address, or a filter that deletes provider warnings on arrival, is the clearest sign there is.
Is my phone being monitored?
Almost certainly not. Software that genuinely monitors a phone nearly always requires someone to have held the unlocked device for a few minutes, which narrows the field of suspects considerably. The dial codes circulating on social media prove nothing either way. More useful is a look at the installed app list, at device admin apps and accessibility services on Android, and at configuration profiles on iOS. If nothing unfamiliar sits in those places and the system is up to date, monitoring by app is unlikely.
What do I do if my iPhone is hacked?
The path is shorter than on Android, because conventional spyware barely runs on an iPhone without a jailbreak. Open Settings, General, VPN and Device Management and check whether a configuration profile is installed that you did not add yourself, then review the device list under your Apple Account. In practice the account matters more than the handset: anyone who knows your Apple credentials can see photos, backups and location without installing a thing. Change that password, verify two-factor, remove unknown devices, update iOS.
What are real signs of a hacked phone?
Only signs backed by an event you did not trigger. Sign-ins from countries you have never visited, messages in your sent folder you never wrote, two-factor codes arriving when you are not logging in anywhere, a recovery address that changed by itself, apps nobody admits to installing. A warm battery, a sluggish device or adverts in the browser belong in a different category entirely, because there is nearly always a boring explanation for those.
Can someone hack you through WhatsApp?
An attack triggered purely by receiving a message is rare and, in practice, aimed at people pursued by state-level actors. The everyday version looks different: someone talks you into forwarding the registration code sent by SMS and takes over your account, or links WhatsApp Web while holding your unlocked phone. Two-step verification with your own PIN blocks the first, and a regular look at the linked devices list catches the second.
How do I detect a spy app on Android?
Such apps hide themselves, but they need permissions you can see. Open Settings, Accessibility and check which services are switched on, because stalkerware abuses that interface almost without exception to read screen content. Then review device admin apps, notification access and the full app list including system apps, where you will find bland cover names like Sync Service or Device Health. Google Play Protect flags a portion of these tools, and security apps from ESET, Bitdefender or Kaspersky score well against stalkerware in lab tests.
How can I check my phone for spyware?
Four checks cover most of it. Battery and data usage per app, where software that transmits in the background stands out. The app list sorted by install date, which exposes latecomers faster than scanning icons. Permissions for location, microphone and camera, together with the record of which app used them last. And finally configuration profiles on iOS or device admins and accessibility services on Android. Keep the operating system current and reboot afterwards, since some spyware does not survive a restart.

This article may contain affiliate links. If you buy through one of them, we may receive a commission at no extra cost to you. It never changes our assessment, and we do not recommend anything we would not use ourselves.

← All articles