Is My Phone Hacked? The Signs That Mean Something, and the Ones That Do Not
Search this question and you will get the same list everywhere: the battery drains, the phone runs hot, data usage is up. Those lists are not wrong so much as useless, because every symptom on them has half a dozen ordinary explanations. Here is what actually distinguishes a real signal from an anxious one.
Why the usual symptoms prove nothing
A hot phone with a short battery life is, overwhelmingly, a phone with an ageing battery, a recent operating system update still reindexing, a badly behaved app, or poor signal forcing the radio to work harder.
That does not mean the symptom is meaningless. It means it is not diagnostic on its own. A symptom that is present in thousands of healthy phones for every compromised one cannot tell you which you have. Treat those signs as a reason to look further, never as a conclusion.
The one notification that does mean something
If you use an iPhone, there is a signal that is genuinely specific.
Apple sends threat notifications to users it believes have been individually targeted by mercenary spyware. When it detects activity consistent with such an attack, it displays a Threat Notification at the top of the page after you sign in to account.apple.com, and also sends an email and an iMessage to the addresses and numbers on the Apple Account.
Two things about this are worth understanding properly.
Apple will not explain what triggered it. Its own wording: it is unable to provide information about what causes it to issue threat notifications, because that may help attackers adapt their behaviour to evade detection in future. So there is no checklist you can reverse-engineer from a notification.
These attacks target very few people. Apple describes mercenary spyware as vastly more complex than ordinary cybercriminal activity and consumer malware, costing millions of dollars, aimed at a very small number of specific individuals, often with a short shelf life. Targets are typically people who are targeted for who they are or what they do: journalists, activists, diplomats, senior officials.
For the overwhelming majority of people reading this, that is not what is happening. Saying so plainly is more useful than feeding the worry.

The checks that are actually worth doing
These are concrete, verifiable and take a few minutes. They also cover the far more common problem, which is not spyware but an account compromise.
Look at the devices on your account. Both Apple and Google list every device signed in to your account. An unfamiliar device there is a far stronger signal than any battery symptom, and it points at the real risk: someone with your credentials, not software on your handset.
Review app permissions, especially accessibility. Accessibility services can read screen content and simulate input, which is exactly what a malicious app wants. Check which apps hold that permission and whether each one has a reason to.
Check which apps can install other apps and whether any device administrator is enabled that you do not recognise.
Look at what is actually installed, including apps with no icon in the launcher. On a phone that someone else set up or had physical access to, this is where a stalkerware app would sit.
Check mail forwarding and recovery options on your email account. If someone wanted persistent access, that is where they would put it, and it survives any phone cleanup.
When physical access is the real story
Consumer-grade stalkerware is a different problem from mercenary spyware, and it is far more common. It usually requires someone to have had your unlocked phone in their hands.
If that is a realistic possibility for you, the technical checklist is secondary. Changing passwords from a device the other person has never touched, and enabling two-factor authentication, matters more than any scan. If you are in a situation where your safety may be at risk, a support organisation is a better first call than a security forum.
If you did receive an Apple threat notification
Take it seriously and do not improvise. Apple explicitly suggests enlisting expert help, and points to the rapid-response emergency security assistance from the Digital Security Helpline run by the nonprofit Access Now, reachable around the clock through their website.
This is one of the rare cases where the right move is to stop following generic advice, including this article, and speak to people who handle these cases.
The honest summary
Most phones that feel hacked are not. The symptoms everyone lists are real experiences with mundane causes, and treating them as evidence leads people to reinstall everything while the actual problem, a compromised account, stays untouched.
Check the devices on your account, review accessibility permissions and installed apps, and secure the email account that can reset everything else. If you receive an Apple threat notification, that is different in kind, and it deserves expert help rather than a checklist.
The description of Apple threat notifications, including the statement that Apple will not disclose what triggers them and the referral to the Access Now Digital Security Helpline, is taken from Apple’s own support documentation, checked at the time of writing. This article does not claim to detect targeted spyware; no consumer tool does. Commercial links carry the rel=“sponsored nofollow” attribute; an affiliate commission may apply at no extra cost to you.