A phone that suddenly loses battery before lunchtime, overheats while sitting idle or displays an unfamiliar app may be showing signs that something is wrong.

For some users, the warning can be even more direct: an unexpected login code arrives for an account they did not try to access, friends receive messages they never sent, or the phone unexpectedly loses network service.

None of these signs, on their own, proves that a phone has been hacked. Battery drain, for example, can follow a software update, while unfamiliar notifications may have perfectly ordinary explanations.

But when several unusual symptoms appear at the same time, security experts recommend taking the possibility seriously and checking the accounts, applications and connections associated with the device.

Start with your accounts

The first place to investigate may not actually be the phone.

In many cases, what appears to be a compromised device is instead an email, Apple Account or Google account that someone else has accessed.

The Federal Trade Commission has noted that when another person appears to know unusually much about someone's activities, they may be obtaining that information by accessing online accounts rather than directly controlling the phone.

On an iPhone, users can check devices connected to their Apple Account by opening Settings, tapping their name at the top and scrolling through the list of signed-in devices.

Android users can visit their Google Account, select Security and look under Your devices.

Any unfamiliar phone, tablet or computer should be investigated. If it does not belong to you, sign it out and immediately change the account password.

Watch for unusual battery drain

A rapidly declining battery is one of the most noticeable signs that something has changed, particularly when a person's phone habits have remained the same.

Users can check Settings > Battery on both iPhones and Android devices to see which applications are consuming the most power.

An unfamiliar application consuming significant battery power deserves attention.

However, battery drain should not automatically be interpreted as evidence of hacking. A newly installed software update can temporarily increase battery consumption, so users should consider recent updates and other ordinary explanations before assuming the worst.

Another warning sign is a phone that becomes unusually warm while it is not being used.

A device sitting in a pocket or on a table with the screen off should generally not be working hard enough to become noticeably hot. Persistent heat can indicate that an application or background process is using significant processing power.

Check your mobile data

Unexpected data consumption can also provide a clue.

Some forms of spyware collect information such as photographs, messages or location data and transmit it elsewhere. That activity can consume mobile data.

On an iPhone, users can check Settings > Cellular to see which applications are using data.

Android users can search the Settings menu for “data usage”, although the exact location and wording vary between manufacturers.

An unexplained spike does not necessarily mean spyware is present, but it is worth investigating alongside other warning signs.

Look for unfamiliar apps

An application that you do not remember installing should not be opened simply to find out what it does.

Instead, check its name and investigate where it came from.

Android users should also examine settings related to Accessibility, Notification access and Device admin apps. These are legitimate Android features, but malicious applications can abuse certain permissions to gain extensive control over a device.

If an unfamiliar application has access that does not make sense for its function, that should raise questions.

Pay attention to the camera and microphone indicators

Modern smartphones provide visual warnings when applications access sensitive hardware.

On iPhones, a green dot indicates that the camera is being used, while an orange dot indicates microphone access.

Android devices display a green indicator when the camera or microphone is being accessed.

If the indicator appears when the user is not intentionally using either feature, swiping down from the top of the screen can help identify the application responsible.

Again, the appearance of an indicator is not automatically proof of malicious activity. The important question is whether the application using the camera or microphone is one the user expects to be doing so.

Unexpected security codes could mean someone is trying to log in

An unsolicited password-reset email or security code should not be ignored.

It can indicate that someone is attempting to access one of the user's accounts.

The situation becomes more urgent if the phone simultaneously displays “No Service” or “SOS” despite being in an area where it normally has network coverage.

That combination can be associated with a SIM swap, in which a criminal attempts to move a victim's telephone number to another SIM card under their control.

Anyone who suddenly loses mobile service under suspicious circumstances should contact their network provider immediately, preferably using another phone.

What if someone you know may be monitoring you?

The situation requires additional caution when the suspected person is a partner, former partner or family member.

Deleting a suspected monitoring application immediately may alert the person who installed it.

The Federal Trade Commission has warned that people using technology to monitor another person may react when their access is disrupted. Anyone who believes they may be under this kind of surveillance should consider seeking help from a domestic violence or safety organisation before making changes to the device.

The National Domestic Violence Hotline in the United States can be contacted at 800-799-SAFE (7233), through live chat or by texting START to 88788. Users should contact such services from a device that the suspected person has never been able to access.

iPhone users can also use Safety Check, found under Settings > Privacy & Security > Safety Check. The feature allows users to review and stop certain forms of sharing, including location and access to shared content, while also reviewing app privacy permissions.

What to do if you suspect your phone or accounts have been compromised

1. Secure your email account first

Email is often the recovery route for other online accounts.

If possible, use another trusted device to change your email password. Then secure important accounts such as banking and social media.

Each account should have a unique password. Password managers can make that easier by generating and storing different passwords for different services.

2. Protect your mobile number

Contact your mobile network provider and ask what protections are available against SIM swaps and unauthorised number transfers.

This is particularly important because access to a telephone number can sometimes be used to intercept text-message authentication codes.

3. Enable two-factor authentication

Two-factor authentication adds another layer of protection even if someone obtains a password.

Where available, an authenticator application can be preferable to SMS-based codes because an attacker who takes control of a telephone number may also be able to receive text messages.

Users should also consider passkeys where supported. Passkeys allow accounts to be authenticated using the device's existing security mechanisms, such as a fingerprint or facial recognition.

4. Review app permissions

On iPhone, users can go to Settings > Privacy & Security and review permissions for location, microphone, camera, contacts and other sensitive information.

On Android, permissions can generally be reviewed through Settings > Security & Privacy > Privacy > Permission manager, although menus vary between manufacturers.

Remove unnecessary permissions and uninstall applications that are no longer needed.

5. Run a security scan

Android users can use Google Play Protect by opening the Play Store, tapping their profile picture, selecting Play Protect and running a scan.

iPhone users should check Settings > General > VPN & Device Management for unfamiliar configuration profiles.

An unknown profile can be a serious warning sign, although work-issued phones may legitimately contain profiles installed by an employer. Users should therefore check with their organisation's IT department before removing one.

6. Restart the phone

Restarting a phone is simple, but it can interrupt certain malicious processes that exist only temporarily in a device's memory.

The National Security Agency's mobile-device security guidance recommends regularly restarting mobile devices.

7. Consider a factory reset as a last resort

If suspicious behaviour continues after accounts, applications and permissions have been checked, a factory reset may be appropriate.

A reset removes the device's contents and returns it to its factory state.

Before doing so, users should back up important photographs and contacts and ensure they know the passwords for their accounts.

After resetting, it is safer to reinstall applications individually from the official App Store or Google Play rather than automatically restoring every application from an old backup.

A factory reset, however, will not solve a compromised online account or a hijacked telephone number. That is why securing accounts and the mobile number should come first.

Prevention remains the strongest defence

Users can reduce their exposure by keeping their phones updated, installing applications only from official app stores and avoiding unexpected links sent by text message or email.

Rather than clicking a link that supposedly comes from a bank, delivery company or other service, users should open the official application or type the organisation's website address themselves.

A strong phone passcode, preferably six digits or longer, also provides greater protection than a short four-digit code.

Regularly restarting the device and reviewing account activity can provide another layer of protection.

For anyone who suspects something is wrong, two checks can be completed in just a few minutes: review the devices signed in to your Apple or Google account, and contact your mobile carrier about protecting your number.

Those checks can quickly reveal whether the problem is actually inside the phone—or whether someone is attempting to gain access through the accounts and telephone number connected to it.