How to tell if your phone is hacked right now

A hacked phone usually shows one or more of these signs: the battery drains much faster than normal, the phone gets hot without you using it, you see unfamiliar apps you did not install, text messages appear in your sent folder that you did not send, or your data bill spikes suddenly. You might also notice the phone is slower than usual, the screen flickers, or you get logged out of accounts without warning.

The most reliable sign is unexpected data usage. Open your phone's settings and check how much data each app has used in the last month. If an app you barely use has consumed gigabytes, or if your total usage is far higher than your normal pattern, something is running in the background without your knowledge. This is worth investigating even if nothing else seems wrong.

Another concrete sign is apps requesting permissions they should not need. If your camera app is asking for permission to access your contacts, or your flashlight app wants to read your location, that is not normal. Hackers often modify apps to steal information. Check your app permissions in Settings — on Android, go to Settings > Apps > Permissions; on iPhone, go to Settings > Privacy.

Key Takeaways

  • Fast battery drain, unexpected data usage, and unfamiliar apps are the most common signs a phone has been compromised.
  • Check your app permissions in Settings to see if apps are requesting access to your camera, location, or contacts without reason.
  • Restart your phone in Safe Mode to see if the suspicious behavior stops — if it does, a third-party app is likely the cause.
  • Change your passwords from a different device, run a malware scan if your phone has that option, and consider a factory reset if the problem persists.
  • On iPhone, check for jailbreaking signs like Cydia in your home screen; on Android, check if you allowed installation from unknown sources.

Run your phone in Safe Mode to isolate the problem

Safe Mode disables all third-party apps and runs only the system software. If your phone works normally in Safe Mode but shows the suspicious behavior when you restart normally, a downloaded app is the culprit. This narrows down the problem significantly.

To enter Safe Mode on Android, press and hold the power button until the power menu appears, then press and hold "Power off" until a Safe Mode option appears. On iPhone, there is no traditional Safe Mode, but you can restart the phone and immediately press and hold the volume up button until the home screen appears — this disables recently installed apps from running.

Stay in Safe Mode for at least an hour and observe whether the battery still drains fast, the phone still gets hot, or the data usage still climbs. If the problems stop, uninstall recently downloaded apps one at a time and restart normally after each removal. The problem should resolve once you remove the offending app.

Check for jailbreaking or rooting on your device

A jailbroken iPhone (or rooted Android phone) has had its security restrictions removed, which makes it far more vulnerable to hacking. Hackers often jailbreak phones remotely to install malware that runs with full system access.

On iPhone, look for an app called Cydia in your home screen — this is the jailbreak app store and should never be there on a normal phone. If you see it, your phone has been jailbroken. You can also check Settings > General > Profiles & Device Management to see if any suspicious profiles are installed; legitimate profiles are rare and usually come from your employer or school.

On Android, open Settings > Apps and look for apps like Magisk Manager or SuperSU — these are rooting tools. You can also check Settings > Security > Unknown sources. If this toggle is turned on and you did not turn it on yourself, someone else has accessed your phone. A factory reset is the safest response if you find evidence of rooting.

Change your passwords from a different device

If you believe your phone is hacked, do not change your passwords on the hacked phone itself — a hacker with access can intercept the new passwords as you type them. Instead, use a computer, tablet, or a friend's phone to change the passwords for your email, banking, social media, and any other sensitive accounts.

Start with your email password, because email is the master key to all other accounts — if a hacker controls your email, they can reset passwords on everything else. After you change your email password, change your banking passwords, then social media, then any other accounts that matter to you.

While you are changing passwords, check your account recovery options. In Gmail, go to myaccount.google.com and look at Security > Your devices. Remove any devices you do not recognize. On Apple ID, go to appleid.apple.com and check Devices — remove anything unfamiliar. This prevents a hacker from using a stolen device to regain access later.

Run a malware scan or factory reset your phone

If your phone has a built-in malware scanner, use it. On Android, open Google Play Protect by going to the Play Store app, tapping your profile icon, then Play Protect. Tap Scan — this checks all installed apps against Google's database of known malware. The scan takes a few minutes and will flag any suspicious apps.

If the scan finds nothing but the suspicious behavior continues, or if you cannot identify which app is causing the problem, a factory reset is the most reliable solution. This erases everything on your phone and reinstalls the original operating system, removing any malware in the process. Before you reset, back up any photos, contacts, or documents you want to keep by uploading them to cloud storage like Google Drive or iCloud.

To factory reset an Android phone, go to Settings > System > Reset options > Erase all data. On iPhone, go to Settings > General > Transfer or Reset > Erase All Content and Settings. The process takes 15 to 30 minutes. After the reset, do not restore from a backup — instead, set up the phone as new and reinstall only the apps you actually use. This ensures any malware is not restored along with your data.

Prevent future hacking by changing your habits

Most phones are hacked because the owner clicked a malicious link, downloaded an app from an untrusted source, or connected to an unsecured Wi-Fi network. You can reduce your risk significantly by being cautious about what you tap and what you install.

Only download apps from the official app store for your phone — Google Play on Android or the App Store on iPhone. These stores review apps before they are published, though malware occasionally slips through. Avoid downloading apps from third-party websites or links in text messages and emails, even if they look legitimate. If someone texts you a link to "update your banking app," go to the App Store directly instead of tapping the link.

Avoid connecting to public Wi-Fi networks without a VPN, especially for banking or email. Public Wi-Fi is easy to intercept, and a hacker on the same network can see your passwords and messages. If you must use public Wi-Fi, use a VPN app like Proton VPN or Mullvad to encrypt your traffic. Also, keep your phone's operating system updated — go to Settings > System > System update on Android or Settings > General > Software Update on iPhone and install updates as soon as they are available. Updates patch security holes that hackers exploit.

What to do if you find malware but cannot remove it

If a factory reset does not solve the problem, or if you discover malware that keeps returning, your phone may have been compromised at the operating system level — this is rare but possible. At this point, the safest option is to stop using the phone for sensitive activities and consider replacing it.

Before you replace it, contact your bank and any financial institutions where you have accounts. Let them know your phone may have been compromised and ask them to flag your account for suspicious activity. Also notify the credit bureaus — you can place a fraud alert at Equifax, Experian, or TransUnion by calling 1-888-397-3742 (Equifax), 1-888-378-4329 (Experian), or 1-888-909-8872 (TransUnion). A fraud alert makes it harder for someone to open new accounts in your name.

When you get a new phone, use a strong, unique password for your email account and enable two-factor authentication on every account that offers it. Two-factor authentication requires a second form of verification — usually a code sent to your phone or generated by an authenticator app — making it much harder for a hacker to break in even if they have your password.

Frequently Asked Questions

Can someone hack my phone without me downloading anything?

Yes, but it is less common. A hacker can exploit a security flaw in your operating system or in an app you already have installed, without you needing to do anything. This is why keeping your phone updated is important — updates patch these flaws. Connecting to an unsecured Wi-Fi network can also expose you, which is why a VPN helps.

If I restart my phone, will that remove the malware?

A restart will not remove malware permanently, but it may temporarily stop it from running. Malware is designed to restart along with your phone. A restart is a good first step to see if the problem is temporary, but you will need to identify and remove the cause to fix it permanently.

Is my phone hacked if I see ads I did not click on?

Not necessarily — many free apps display ads as part of their business model. However, if ads appear when you are not using any app, or if they appear on the lock screen, that is suspicious. Check your installed apps for anything you do not recognize, and look at your app permissions to see if any app has permission to display notifications.

Should I tell my contacts if my phone is hacked?

If your phone was hacked, a hacker may have sent messages to your contacts pretending to be you. Send a message to your close contacts letting them know your phone was compromised and that they should not click any links or download anything from messages claiming to be from you. You do not need to notify everyone, just people who might be targeted.

Can I get hacked through a text message without clicking anything?

Yes, though it is rare. Some security flaws allow malware to install just by receiving a text message, without you needing to tap anything. This is why keeping your phone updated is critical — these flaws are patched in updates. If you receive a suspicious text, do not reply and do not click any links, even if it looks like it came from a trusted source.