Morning Overview

11 warning signs your phone has been hacked

A compromised phone rarely announces itself with a single obvious clue; more often it leaves behind small, easy-to-miss changes in how the device behaves day to day. Security teams at Norton, Malwarebytes, Apple, Google and the FTC each maintain their own checklists for spotting the pattern before real damage is done. Here are eleven signs pulled from those checklists that a device or account may already be compromised.

1. Camera Indicator Light: The Dot That Turns Itself On

Camera Indicator Light — Image Credit: Kindel Media/Pexels
Image Credit: Kindel Media/Pexels

Most smartphones flash a small dot near the top of the screen whenever the camera or microphone turns on, and Norton’s phone-hacking checklist treats an indicator that lights up on its own as a possible sign that something is quietly recording. The company adds a caveat that matters: some advanced spyware can access the camera or mic without ever triggering the light.

That means a clean indicator is reassuring but not proof of safety, so a stray flash deserves more than a shrug. Checking which apps hold camera and microphone permission is the next step once the dot appears uninvited.

2. Battery Drain: The Battery That Can’t Keep Up

Battery Drain — Image Credit: 10 Apps That Are Draining Your Battery
Image Credit: 10 Apps That Are Draining Your Battery

A phone that suddenly can’t make it through the afternoon is one of the clearest tells on Malwarebytes’ hacking-signs list, which points to malware running in the background and burning through the device’s resources around the clock.

The drop tends to be sudden and steep rather than the slow fade of an aging battery, which is the detail that separates a hacked phone from one that simply needs a new one. Malwarebytes notes ordinary software bugs can cause the same symptom, so it is a clue rather than a verdict.

3. Overheating While Idle: Warm For No Reason

Smartphone On Table — Image Credit: Santeri Viinamäki - CC BY-SA 4.0/Wiki Commons
Image Credit: Santeri Viinamäki – CC BY-SA 4.0/Wiki Commons

Heat during a long gaming session is nothing to worry about, but Norton’s list of hacking warning signs flags a phone that warms up while it is simply sitting untouched, especially when the heat shows up alongside other odd behavior.

Norton attributes idle overheating to a misbehaving app or, less often, malicious software working in the background. A phone that runs warm at rest, with no video streaming or navigation app open, is worth a closer look at what is actually running underneath.

4. Data Usage Spike: The Data You Didn’t Use

Data Usage Spike — Image Credit: Castorly Stock/Pexels
Image Credit: Castorly Stock/Pexels

A data bill that jumps with no new streaming habit or download spree is one of the signs Malwarebytes lists for a hacked phone, since malware often ships information off the device to a remote server in the background.

Checking the phone’s own data-usage breakdown by app can surface the culprit, since a legitimate app rarely needs a sudden and sustained spike to function. A one-time jump after an update is normal; a spike that keeps climbing is the pattern worth chasing down.

5. Storage Vanishing On Its Own: Without Anything New Installed

Smartphone Storage — Image Credit: Image by Freepik
Image Credit: Image by Freepik

Storage that quietly fills up without a single new photo or app installed is a sign Norton includes on its hacking checklist, since malicious code can consume real space installing new files or duplicating what is already on the phone.

The loss tends to show up gradually rather than all at once, which is part of why it goes unnoticed until the phone warns it is nearly full. A storage breakdown that doesn’t match the phone’s normal habits is the tell worth watching for.

6. Phone Screen Ads: Ads Where They Don’t Belong

Phone Screen Ads — Image Credit: Anton/Pexels
Image Credit: Anton/Pexels

Pop-ups showing up on pages that should never carry advertising, including government websites the FTC specifically names, are treated by the agency as a symptom that a device is already infected rather than a nuisance of ordinary browsing.

The FTC’s malware guidance groups this with a browser home page that changes on its own and searches that redirect to unfamiliar sites. Seeing ads on a .gov page in particular is a strong tell, since legitimate government sites do not run third-party advertising at all.

7. Unprompted Calls And Texts: A Phone With A Mind Of Its Own

Smartphone Glow — Image Credit: SHVETS production/Pexels
Image Credit: SHVETS production/Pexels

Apps launching on their own, calls placed and texts sent without a finger touching the screen: Malwarebytes treats that behavior directly as a sign that malware has already been installed and is operating the phone independently.

This sign tends to arrive alongside others on the list, like battery drain or data spikes, rather than showing up alone. A phone that behaves like someone else has their hands on it, even briefly, is one of the least ambiguous signs on any hacking checklist.

8. Unrequested Two-Factor Codes: On A Trusted Device

Smartphone Notification — Image Credit: Anna Shvets/Pexels
Image Credit: Anna Shvets/Pexels

A two-factor code arriving on a trusted device or by text without ever being requested is named outright by Apple’s guide to a compromised account as a sign someone else already has the password and is trying to get past the second step.

Apple groups it with sign-in alerts for unrecognized devices and a password that suddenly stops working. The instinct to ignore or dismiss the code is the wrong one; it signals an attacker at the door, not a system malfunction.

9. Recovery Email Changed Without Warning: Locked Out Before Anyone Notices

Laptop Screen — Image Credit: Geleparaplu - CC BY-SA 4.0/Wiki Commons
Image Credit: Geleparaplu – CC BY-SA 4.0/Wiki Commons

A recovery phone number or backup email that changes without the account owner touching it is high on Google’s list of compromise warning signs, since it is exactly how an intruder locks the real owner out of the account’s own recovery path.

Google’s support page also flags changes to the account name, security question and two-step verification methods in the same category. Anyone notified about an added recovery method has 30 days to dispute it before it takes effect.

10. Friends Getting Spam: Spam With Your Name On It

Friends Getting Spam — Image Credit: freestocks.org/Pexels
Image Credit: freestocks.org/Pexels

Friends reporting spam or strange messages that appear to come from someone’s own address made Google’s compromised-account checklist for exactly that reason, alongside emails that vanish from the inbox without ever landing in Trash.

Google also lists sent messages the account owner never wrote as part of the same pattern. Taken together, these are signs that someone else is actively using the account to send mail, not just viewing what’s already there.

11. Suspicious Sign-In Alert: Stopped Before It Started

Smartphone Alert — Image Credit: RDNE Stock project/Pexels
Image Credit: RDNE Stock project/Pexels

A ‘suspicious sign-in prevented’ email means Google already blocked an access attempt from a location or device that didn’t match the account’s usual pattern, which is why the alert is worth reading closely rather than archiving.

Google’s own support page warns that hackers have started forging copies of this exact email to phish the very people it is meant to protect. Checking the account’s actual recent security events, rather than trusting the email’s links, is the safer way to confirm it’s real.