CYBER WELFARE

Protect your Digital Privacy

Signs someone accessed your phone: what to look for

When somebody signs in to an online account, the service records the event and often warns you. When somebody opens your phone, there is no system sending you a notification: you are the only detection system.

That changes how the signals should be read. There are no logs to consult, there are behaviours to notice — and most of them go unnoticed precisely because they look ordinary.

This post collects the indicators of compromise (IOC) applied to mobile devices. It expands on the recommendation six digit passcode.

Three very different situations

Telling them apart is useful, because the signals and the responses change.

Occasional access. Somebody opened the phone for a few minutes — an acquaintance, a colleague, somebody in a shared space. The signals are minimal and concern what was looked at.

Prolonged access. The device was out of your control long enough for something to be configured: an app installed, a forwarding rule turned on, an account linked.

Remote access through the accounts. Nobody touched the phone, but somebody got into the maker’s account or a connected service, and can see location, backups, synced messages.

The third is the hardest to notice and the least considered.

Technical indicators

IndicatorWhat it meansWhy it mattersWhere you see itWhat to do
An unknown device in your accountsSomebody connected a device to your servicesIt may indicate access that is still activeThe “devices” section of your main accountsRemove it, change the password, check the second factor
Installed apps you do not recogniseSomething was added without your involvementSome apps can observe activity or locationThe list of installed applicationsRemove it; check the permissions of the remaining ones
Permissions granted you do not rememberAn app has access to location, microphone, contactsBroad permissions allow continuous data collectionThe device’s privacy settingsRevoke the permissions that are not needed
A device administrator or profile addedA configuration profile has been installedIt can allow extended control over the deviceGeneral settings, profiles or device management sectionRemove it if you do not recognise it; check with support if it is a work device
Forwarding rules on your mailMessages are being copied elsewhereIt keeps working even after a password changeYour email account’s settingsRemove it and change the password
Abnormal data or battery consumptionSomething is working in the backgroundA weak clue on its own, meaningful alongside othersBattery and data statisticsCheck which apps are consuming; the topic is covered in Phone running slow: malware or age?
A sign-in to the maker’s account from an unusual placeSomebody got into the account linked to the deviceIt allows location and backups to be seen without touching the phoneSecurity emails, the maker’s account areaChange the password, turn MFA on, check the linked devices

Signs you can observe yourself

SignalWhat it meansWhy it mattersHow you noticeWhat to do
The phone is in a different position from how you left itSomebody picked it upIt is the simplest and most ignored signalYou find it turned over, moved, with the screen onCheck the sent messages and the recently opened apps
Messages showing as read that you did not openSomebody opened the conversationsIt indicates reading, not necessarily moreNotifications gone, conversations without a badgeCheck what was opened; change the unlock code
Messages sent that you did not writeSomebody acted in your nameIt exposes your contactsContacts reporting odd messagesWarn your contacts, change your account passwords
The unlock code no longer worksIt was changed by somebody elseLoss of control over the deviceYou cannot unlock it despite typing it correctlyLock it remotely, change your email password
Calls or messages suddenly not arrivingThe number may have been transferred to somebody elseIt compromises verification codes sent by textThe phone loses service for no reasonContact your operator at once
Somebody knows things you never sharedPossible access to the device’s contentAn indirect but concrete signalA conversation in which a private detail surfacesCheck linked devices and forwarding rules
Settings changed that you do not rememberSomebody modified the configurationIt often precedes something elseAutomatic lock lengthened, notifications turned back onRestore the settings, change the code

The most neglected signal

It deserves isolating: the phone found in a different position from how you left it.

It is a trivial observation, easily explained by distraction, and for exactly that reason it gets filed away without a thought. But it is often the only available signal of occasional access — because no other clue will be generated.

The appropriate reaction is not alarm: it is two thirty-second checks.

  1. Look at the messages sent in the last few hours.
  2. Look at the recently opened applications.

If neither shows anything unusual, distraction is the most likely explanation. If something does not add up, you have just gained time.

A concrete example

Mark leaves his phone in a gym changing room, in an unlocked bag. When he comes back he finds it where he left it.

Two weeks later, his partner asks him why he looked up information on a subject they have never discussed. Mark looked up nothing.

He checks the device: there is an application he does not remember installing, with permissions over location and notifications.

The signal had been there — a phone left unattended for forty minutes — but it had produced nothing visible at the time.

The lesson: after a period in which the device has been out of your control, it is worth checking the installed applications. It is the only way to detect prolonged access that leaves no other trace.

What to check, and how often

FrequencyWhat to check
After the phone has been left unattendedSent messages, recently opened apps, installed applications
Every 2–3 monthsDevices linked to your main accounts; installed apps; granted permissions
Every 6 monthsConfiguration profiles or device administrators; forwarding rules on your mail
When something does not add upData and battery consumption per application
If phone service is interruptedContact your operator: it may not be a fault

What is not an indicator

SituationWhy it is usually not a signal
A battery lasting less over timeBatteries degrade: only a sudden change counts
A phone getting warm during heavy useNormal behaviour with video, browsing or charging
Updated apps asking for new permissionsPart of the update cycle: check the permission, do not be alarmed
A “new” device in your account listOften it is yours, after a system update
Unusual advertising notificationsThey indicate your data is circulating in marketing lists, not access to the phone
High data use after an updateSystem updates are heavy

The rule holds: an isolated signal deserves a check, two signals together deserve action.

If you find an indicator

  1. Change the device’s unlock code.
  2. Check the installed applications and remove what you do not recognise.
  3. Check the permissions granted to apps: location, microphone, contacts, notifications.
  4. Check for configuration profiles or device administrators.
  5. Check the forwarding rules on your mail: they keep working even after a password change.
  6. Change the passwords of your main accounts, starting with email, from a device you trust.
  7. Check the devices linked to each account and remove the unknown ones.

If the signals are many or serious, the cleanest route is resetting the device to factory settings, followed by reconfiguration. It is quicker than looking for what was changed.

The case of remote access through the account

It deserves its own section, because it leaves no trace on the device and for that reason nearly always escapes notice.

The phone is linked to a maker’s account, which handles updates, data backup and location. Whoever obtains that account’s credentials — reused, guessed, or obtained through a deceptive message — can in many cases:

  • see where the device is, in real time;
  • reach the backup of your data: photos, contacts, sometimes messages;
  • see which other devices are linked to the same account.

The phone, meanwhile, works normally. There is no clue to observe on the screen.

Where to check. In the maker’s account area, from a computer: the list of linked devices, recent sign-ins, the associated email address.

How to protect yourself. Treat that account as critical: a unique, long password and a second factor enabled. It is often the least protected of the important accounts, precisely because it is not perceived as a service in its own right.

Two warnings

The absence of signals is not a guarantee. Access lasting a few minutes, if limited to reading, leaves almost nothing behind. That is why the protection rests on the unlock code and the automatic lock, not on observation.

Be careful with anything offering to check for you. Applications promising to “check whether your phone is being spied on” often ask for very broad permissions, and in some cases are themselves the problem. Every check described here is done with the device’s own settings, without installing anything.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsKnowing where to look on a mobile device and what to look for
AwarenessUnderstanding that on a phone the detection system is you
Secure BehaviourMaking two quick checks after the device has been left unattended

Reference level: FL3 — Autonomous.

Conclusion

No access alerts arrive on a phone. The most reliable signal is often the most trivial one: the device not being where you left it.

There is no need to live on alert. There is a need to know that, after a period in which the phone was out of your control, two minutes of checking are worth more than any monitoring application.

What to do right now. Open the list of applications installed on your phone and scroll to the bottom. If there is one you do not remember installing, you have just found something useful.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.