Cybersecurity & Privacy

Phone Hacked Signs: 8 Red Flags & What to Do Now

RexJafor

RexJafor

September 8, 2026

44 views
0 comments
22 min read
Updated: September 8, 2026

Your battery dies by 2pm, an app you never downloaded is sitting on your home screen, and an OTP you did not request just landed in your inbox. Is your phone hacked, or is it just getting old? Most people cannot tell the difference, and that hesitation is exactly what attackers count on.

The threat is not theoretical. Kaspersky blocked close to 2 million attacks on mobile devices in the second quarter of 2026 alone, and banking Trojans — malware built to steal your login details and intercept your OTP codes — made up roughly 31% of everything it detected. Over 304,000 new malicious Android installation packages appeared in that single quarter. Phones are now where the money, the identity documents and the account recovery codes live, so that is where the attacks go.

This guide gives you the real phone hacked signs to look for, the innocent explanations that get mistaken for hacking every day, a step-by-step way to check your own device on both Android and iPhone, and exactly what to do in the first hour if the answer is yes — including where to report it in Bangladesh.

KEY TAKEAWAYS

  • One symptom is not proof. A hot battery or a slow phone on its own usually means age or a bad app update. Real compromise almost always shows two or more signs at the same time.
  • The loudest signals are account signals: OTPs you did not request, login alerts from new devices, messages sent from your accounts, and a phone that suddenly drops to “No Service” while everyone around you has bars.
  • Money-focused malware dominates in 2026. Banking Trojans and remote-access apps that abuse Accessibility permissions are the most common threat to ordinary users — not movie-style zero-click spyware.
  • Order matters when you respond. Cut the connection, remove the malicious app, then change passwords from a different device. Changing passwords on an infected phone just hands the new ones over.
  • 2026 gives you one-tap defences. Android’s Advanced Protection and iPhone’s Lockdown Mode and Safety Check turn on a whole stack of protections without any technical knowledge.
  • Report it. In Bangladesh you can call 999, contact the CID Cyber Police Centre, and freeze your mobile-money account through the official operator helpline — the sooner, the better your chance of recovery.

Quick answer: the 10 signs at a glance

Short answer: the clearest phone hacked signs are unexplained battery drain and heat, a jump in mobile data use, apps you never installed, camera or microphone indicators lighting up on their own, OTP codes and login alerts you did not request, messages sent from your accounts, a sudden loss of mobile signal, unfamiliar transactions, aggressive pop-ups and redirects, and an official security alert from Apple, Google or your bank. Two or more together is your cue to act.

Sign What it usually means Your first move
1. Battery drains fast, phone warm when idle Something is running non-stop in the background — possibly a spy or mining app Open battery usage and find which app is on top
2. Mobile data usage spikes Data is being uploaded off your device to somewhere else Check per-app data use for the last 30 days
3. Apps you never installed Malware dropper, stalkerware, or a sideloaded APK Audit your app list plus Accessibility and admin access
4. Camera or mic indicator turns on by itself An app is accessing the sensors while you are not using it Tap the indicator to see which app is responsible
5. OTPs and login alerts you did not request Someone already has your password and is trying to get in Never share the code; change that password immediately
6. Messages sent from your accounts Your account or the device itself is being used to spread scams Sign out of all sessions and warn your contacts
7. Sudden “No Service” or SOS only Possible SIM swap — your number has been moved to another SIM Call your operator from another phone right away
8. Unfamiliar charges or transfers Financial malware or a compromised wallet or card Freeze the account through the official helpline
9. Pop-ups, redirects, changed settings Adware or a browser hijacker is installed Remove recently installed apps and clear browser data
10. Official alert from Apple, Google or your bank A platform has detected something you cannot see yourself Act on it, but verify it inside the official app first

What “hacked phone” actually means in 2026

“Hacked” gets used for four very different problems, and the fix for one is useless against another. Working out which category you are in saves hours.

Type How it gets in What the attacker gets Tell-tale sign
Account takeover (most common) Phishing link, leaked password, an OTP you were tricked into sharing Facebook, Gmail, WhatsApp, mobile wallet Login alerts, sent messages you did not write
Banking Trojan / RAT Sideloaded APK, fake “update”, an app that demands Accessibility access Banking logins, OTP SMS, remote control of the screen Odd transactions, screen acting on its own
Stalkerware Someone with physical access to your unlocked phone for a few minutes Location, messages, calls, photos, microphone Heat and drain with no visible app; hidden admin app
SIM swap Fraudster reissues your number using stolen identity details Every SMS OTP you own — bank, wallet, social accounts Signal dies and never returns; calls stop arriving

Notice that only two of the four involve malware at all. That is why “I ran a scan and it found nothing” does not mean you are safe — if your Facebook password leaked in a breach, no antivirus on earth will flag it. If your accounts are the problem, start with our Facebook account hacked recovery guide and the steps for a hacked Gmail account.

The 10 signs your phone is hacked

Read each sign with its innocent explanation attached. That pairing is what stops you from wiping a perfectly healthy phone — and what stops you from ignoring a real compromise.

1. The battery drains far faster than it used to, and the phone is warm when idle

Spyware, remote-access Trojans and crypto-mining apps have to keep running to be useful. That means constant CPU work, constant network activity and a phone that feels warm in your pocket while you are not using it. The pattern that matters is a sudden change: the same phone, same apps, same habits, and half the battery life it had last month.

Not always hacking: lithium batteries lose real capacity after two to three years, and a single buggy app update can burn 30% of a charge in a day. Check battery usage by app before you panic.

2. Mobile data usage jumps with no change in your habits

Anything stealing from your phone has to send it somewhere. Photos, message logs, contact lists and screen recordings are heavy, and they show up as a data bill that does not match what you actually did. Look at the per-app breakdown for the last 30 days: if an app you do not recognise, or a system-sounding app like “Service Update” or “Device Care”, is using hundreds of megabytes, that is worth investigating.

3. Apps you never installed — or ordinary apps with extraordinary permissions

An unfamiliar icon is the obvious version. The dangerous version is quieter: a “flashlight”, “PDF reader” or “battery saver” app that holds Accessibility access, device admin rights or notification access. Those three permissions let an app read what is on your screen, type into other apps, capture your OTP notifications and block you from uninstalling it. Modern banking Trojans in Bangladesh and across South Asia almost always ask for Accessibility right after install, framed as “enable this to continue”.

Not always hacking: phone makers and carriers preload apps you never chose, and some genuinely need Accessibility (screen readers, password managers, call recorders). Judge by whether the app has a legitimate reason to read your whole screen.

Walking through every permission you have granted is a useful habit — our app permissions audit guide shows what to revoke and what to keep.

4. The camera or microphone indicator turns on by itself

Both platforms now show a coloured dot in the status bar whenever the sensors are live: green for camera, orange or amber for microphone. If that dot appears while your screen is on the home screen or in a chat app, something is using the sensor. Tap or swipe down on the indicator to see which app it was. This is one of the few signs that is close to hard evidence, because the operating system itself is reporting it.

5. OTP codes and login alerts you did not request

A one-time code arriving out of nowhere means someone already knows your password and is standing at the door. The same goes for “new login from…” emails, or a notification asking you to approve a sign-in you did not start. Never approve it and never read the code out to anyone, including someone claiming to be from bKash, Nagad, a bank or Facebook support — no legitimate organisation asks for it. See our breakdown of OTP scams and the scripts fraudsters use.

Act now: an unrequested OTP is not a warning about the future. It means the attack is happening while you read this. Change that account’s password immediately and sign out of all other sessions.

Compromised phones and accounts get monetised by spreading. Friends message you asking why you sent a strange link, or a family member says you asked them for money on Messenger or WhatsApp. Check the Sent folder, the message history and the account’s active sessions — if outgoing messages exist that you did not write, treat it as confirmed.

7. Your phone drops to “No Service” or SOS while others around you have signal

If your number has been transferred to a fraudster’s SIM, your handset loses network and never gets it back, while calls and SMS for your number arrive on their device. Every SMS-based OTP you have now belongs to them. This is the single most time-critical sign on the list. Full detail is in our guide to SIM swap fraud and how to prevent it.

Not always hacking: a dead SIM, a network outage in your area, or a phone that has drifted into airplane mode explains most cases. Restart once, try the SIM in another handset, then call your operator if it is still dead.

8. Unfamiliar transactions, top-ups or app-store charges

Small amounts first, larger ones later, is the standard pattern — fraudsters test whether anyone is watching. Check bKash and Nagad statements, your bank SMS alerts, and the subscription list in Google Play or the App Store. Money moving out of a mobile wallet is often the first hard proof that a banking Trojan is on the device. Our guide to bKash and Nagad scams covers how these operations run.

9. Pop-ups, redirects, a changed homepage, or settings that reset themselves

Full-screen ads outside of any app, a browser that keeps landing on pages you did not choose, a new default search engine, or Wi-Fi and Bluetooth switching on by themselves are classic adware and hijacker symptoms. Adware is the least dangerous category here, but it usually arrives bundled with something worse.

10. An official security alert from Apple, Google, your bank or your operator

Apple sends threat notifications to users it believes have been targeted by mercenary spyware, and shows them at the top of your Apple Account page as well as by email and iMessage. Google Play Protect flags harmful apps directly on the device. Banks send alerts about logins from new devices. These deserve immediate action — but verify them the safe way: open the official app or type the website address yourself instead of tapping a link in the message, because fake “security alerts” are themselves one of the most successful phishing tactics of 2026. Our guide on spotting phishing emails and fake links shows the difference.

5 signs that are usually not hacking

Competing guides rarely say this, and it matters: most people who think they have been hacked have not been. Rule these out first.

What you noticed Usual explanation When to worry anyway
Phone is slow and laggy Full storage, an ageing device, or a heavy OS update It started overnight after you installed something
Ads that match a conversation you had Ad targeting from your searches, location and social graph The mic indicator lights up while you talk
Spam calls and scam SMS Your number is on a leaked list — nothing on your phone is infected The messages reference real, recent transactions
Phone gets hot while charging or gaming Normal thermal behaviour, especially with fast charging It is hot with the screen off and nothing running
A stranger’s number appears in call history Pocket dial, a returned missed call, or someone else using your phone There are outgoing calls at hours you were asleep

How to check your phone: Android and iPhone

Work through this in order. It takes about ten minutes and it does not require any technical skill or paid tool.

What to check Android iPhone
Battery hogs Settings → Battery → Battery usage Settings → Battery → last 10 days
Data use per app Settings → Network & internet → Data usage (name varies by brand) Settings → Cellular → scroll to the app list
Full app list Settings → Apps → See all apps (includes hidden ones) Settings → General → iPhone Storage; also check App Library
Dangerous permissions Accessibility → Downloaded apps; Security & privacy → Device admin apps; Notification access Settings → Privacy & Security → App Privacy Report
Unwanted profiles Settings → Passwords & accounts — remove accounts you did not add Settings → General → VPN & Device Management — delete unknown profiles
Malware scan Play Store → profile icon → Play Protect → Scan No scanners exist on iOS — use Safety Check instead
Who else is signed in Google Account → Security → Your devices Settings → tap your name → device list at the bottom
Call and SMS forwarding Phone app → Settings → Call forwarding; on most GSM networks, dial *#21# to view Settings → Apps → Phone → Call Forwarding
One-tap lockdown Settings → Security & privacy → Advanced Protection (Android 16 and later) Settings → Privacy & Security → Safety Check, and Lockdown Mode

If you suspect someone close to you installed monitoring software rather than a random criminal, the checks are different and the safety considerations matter more — follow our dedicated guide on how to check for stalkerware on your phone.

What to do if your phone is hacked: the first hour

Sequence is everything. Doing step 4 before step 1 hands your new passwords straight to the attacker.

Before anything else: if money is moving, freeze the account first. Call your bank’s card hotline, bKash on 16247 or Nagad on 16167 from a different phone, and ask them to block the account. Everything else can wait ten minutes; a live transfer cannot.

  1. Cut the connection. Turn on airplane mode and switch off Wi-Fi. This stops data leaving the device and stops remote commands arriving, without deleting evidence.
  2. Remove the suspicious app. Revoke its Accessibility and device-admin access first, then uninstall. If the uninstall button is greyed out, that greyed-out button is the confirmation — boot into safe mode (hold the power button, then long-press “Power off”) and remove it there.
  3. Run a scan and install pending updates. Play Protect on Android, or a reputable paid mobile security app. On both platforms, install every pending OS update: most successful attacks use flaws that were patched months ago.
  4. Change passwords from a different, clean device. Email first, because it controls the resets for everything else, then mobile wallets, banking, Facebook and WhatsApp. Use unique passwords per account — a password manager is the only realistic way to do this.
  5. Sign out everywhere. Every major account has a “log out of all devices” or active-sessions screen. Use it, so old stolen session tokens stop working.
  6. Move off SMS-based codes. Switch your important accounts to an authenticator app or passkeys, which a SIM swap cannot touch. See our walkthrough on setting up two-factor authentication everywhere.
  7. Tell your contacts. A short message saying “my account was compromised, ignore any links from me” prevents your friends becoming the next victims.
  8. Check what leaked. Look at whether your credentials appeared in a known breach and change anything reused — start with a data breach check.
  9. Factory reset if symptoms persist. This is the reliable cure for stubborn Android malware. Back up photos and documents only, not apps or app data, and never restore a full backup made after the problems began — that reinstalls the infection. Step-by-step help is in our guide to removing a virus from an Android phone.
  10. Report it. See the Bangladesh reporting section below. Keep screenshots, transaction IDs and timestamps — investigators need them.

How attackers get into a phone

Almost every real-world case traces back to one of five routes, and four of them need you to tap something.

  • Malicious apps and sideloaded APKs. Cracked apps, “free premium” versions, betting apps and loan apps shared in Telegram or WhatsApp groups are the biggest single source of Android infections. Some malware also slips into official stores by staying dormant until it detects the right victim.
  • Phishing links. A fake delivery notice, prize claim, bank alert or job offer that leads to a convincing login page. You type the password; they collect it. No malware required.
  • SIM swap and social engineering of the operator. Attackers use leaked personal details to have your number reissued, then reset every account that uses SMS codes.
  • Physical access. Five minutes with an unlocked phone is enough to install stalkerware or add a hidden account. A strong screen lock and biometrics close this off.
  • Untrusted networks and charging points. Open Wi-Fi with no password and public USB charging ports are lower-probability risks than the items above, but they are real. Carry your own charger and read our public Wi-Fi safety guide.

How to stop it happening again

The platforms did a lot of work in 2026. Most of it is off by default, which means the protection is sitting in your settings waiting for one tap.

Turn this on Where What it stops
Advanced Protection Android 16 and later: Settings → Security & privacy → Advanced Protection Bundles theft protection, safer browsing, stricter app rules, blocks 2G, and reboots the phone if it stays locked for three days
Lockdown Mode iPhone: Settings → Privacy & Security → Lockdown Mode Blocks the attachment, link-preview and web features spyware exploits. For high-risk users: journalists, activists, public figures
Safety Check iPhone: Settings → Privacy & Security → Safety Check Cuts every person and app that currently has access to your data, in one action
Automatic updates Both: system update settings, plus auto-update for apps Closes the known vulnerabilities that most attacks actually rely on
App-based 2FA or passkeys Security settings of each account Makes SIM swaps and OTP interception useless against your accounts
Play Protect Play Store → profile icon → Play Protect Scans installed and newly installed apps, including sideloaded ones

Android 17, released in June 2026, added more on top: one-time passcodes are now automatically hidden from most apps for three hours so malicious software cannot read them, theft protection is on by default on new and reset devices, and calls that claim to be from your bank can be cryptographically verified. iPhone users get a similar step forward with iOS 27, expected later this month. Whichever platform you are on, the single highest-value habit is boring: install updates the week they arrive.

The 5-minute monthly check: open your app list and delete anything you have not used in three months → review Accessibility and device-admin access → check active sessions on Facebook, Gmail and WhatsApp → confirm your recovery email and phone number are still yours → install pending updates. Five minutes, once a month, catches almost everything early.

Where to report it in Bangladesh

Reporting fast matters for two reasons: financial transfers can sometimes be halted while they are still in transit, and a formal record protects you if your identity is used for something else later.

  • National emergency service: 999. The fastest route for anything urgent, including ongoing extortion or threats.
  • CID Cyber Police Centre, Bangladesh Police. The specialist unit for hacking, online fraud and digital forensics. Complaints can also be filed at your local police station, which forwards them on.
  • Police Cyber Support for Women (PCSW): 01320-000888, or the email and Facebook page run by Police Headquarters. Dedicated support for women and children facing account hacking, blackmail or harassment.
  • Your bank or mobile financial service. bKash on 16247, Nagad on 16167, or your bank’s card hotline. Ask for the account to be frozen and for a written record of your complaint.
  • Your mobile operator, for SIM issues. Dial 121 from another SIM of the same operator, or visit a customer care centre with your NID.

Take screenshots of everything before you delete anything, and note exact dates, times and transaction IDs. Our full walkthrough of the process is in how to report cybercrime in Bangladesh.

Myths that waste your time

  • “Someone can hack me just by knowing my number.” A phone number alone gets an attacker phishing and SIM-swap attempts, not access to your device. Both still need you or your operator to make a mistake.
  • “iPhones cannot be hacked.” iOS is a harder target and there is no app-level malware on a non-jailbroken device, but phishing, account takeover, stalkerware through iCloud, and commercial spyware all work against iPhone users.
  • “Answering a call from a strange number infects you.” It does not. It does confirm your number is live, which usually means more scam calls.
  • “A factory reset fixes everything.” It clears device malware, but it does nothing about a stolen password, a compromised email account or a SIM swap. Reset and secure the accounts.
  • “A free VPN or free antivirus keeps me safe.” Many free security apps monetise your data, and some are malware. See what free VPNs do with your data.

Frequently asked questions

What are the most common phone hacked signs?

Sudden battery drain with the phone warm while idle, a jump in mobile data use, apps you never installed, camera or microphone indicators activating on their own, OTP codes and login alerts you did not request, and messages sent from your accounts. Any two of these together justify a full check.

Can I tell if my phone is hacked by dialling a code?

Partly. On most GSM networks, dialling *#21# shows whether calls and messages are being forwarded elsewhere, and ##21# cancels unconditional forwarding. These codes only reveal network-level forwarding — they say nothing about malware installed on the device, despite what viral videos claim.

Can someone watch me through my phone camera?

It is possible with spyware or an app you granted camera permission to, though it is far rarer than the fear suggests. The camera indicator dot appearing when you are not using the camera is the signal to check. Reviewing which apps hold camera access takes under a minute and closes off the ordinary version of this risk.

Does a factory reset remove hackers from my phone?

It removes malware installed on the device, yes. It does not remove an attacker who has your passwords, controls your email, or has taken over your phone number. Reset the phone, then change your passwords from a clean device and enable app-based two-factor authentication.

Is Android or iPhone easier to hack?

Android sees far more malware, mainly because apps can be installed from outside the official store and because update timing varies by manufacturer. iPhone has a smaller malware problem but is equally exposed to phishing and account takeover. In practice, user behaviour and update discipline matter more than the logo on the back.

Can my phone be hacked while it is switched off?

Not in any practical sense for ordinary users. Software cannot execute on a fully powered-down device. Your accounts, however, can be attacked at any time, whether the phone is on or off — which is another reason account security matters more than device paranoia.

Do I need an antivirus app on my phone?

On Android, a reputable security app adds a useful layer alongside Google Play Protect, especially if you install apps from outside the Play Store. On iPhone, no app can scan the system, so “antivirus” products are mostly VPN and web-filtering tools in disguise. Be sceptical of anything free that promises full protection.

How quickly should I act if I see these signs?

Immediately, and in this order: freeze money, cut the connection, remove the app, then change passwords from another device. Attackers move within minutes of gaining access, so the gap between noticing and acting is the part you actually control.

The bottom line

A single odd symptom is usually a tired battery or a bad app update. A cluster of them — especially anything touching your accounts, your codes or your money — deserves ten minutes of checking today rather than a week of worrying. Run the Android or iPhone checks above, turn on Advanced Protection or Lockdown Mode, move your important accounts off SMS codes, and you will have closed the doors that almost every real attack walks through.

Next, secure the accounts that live on that phone: work through our 10-step Facebook security checklist and the full account recovery guide if anything has already been compromised.

Comments (0)

No comments yet. Be the first to comment!

Related Posts

You might also like these articles