When somebody signs in to an online account, the service records the event and often warns you. When somebody opens your phone, there is no system sending you a notification: you are the only detection system.
That changes how the signals should be read. There are no logs to consult, there are behaviours to notice — and most of them go unnoticed precisely because they look ordinary.
This post collects the indicators of compromise (IOC) applied to mobile devices. It expands on the recommendation six digit passcode.
Three very different situations
Telling them apart is useful, because the signals and the responses change.
Occasional access. Somebody opened the phone for a few minutes — an acquaintance, a colleague, somebody in a shared space. The signals are minimal and concern what was looked at.
Prolonged access. The device was out of your control long enough for something to be configured: an app installed, a forwarding rule turned on, an account linked.
Remote access through the accounts. Nobody touched the phone, but somebody got into the maker’s account or a connected service, and can see location, backups, synced messages.
The third is the hardest to notice and the least considered.
Technical indicators
| Indicator | What it means | Why it matters | Where you see it | What to do |
|---|---|---|---|---|
| An unknown device in your accounts | Somebody connected a device to your services | It may indicate access that is still active | The “devices” section of your main accounts | Remove it, change the password, check the second factor |
| Installed apps you do not recognise | Something was added without your involvement | Some apps can observe activity or location | The list of installed applications | Remove it; check the permissions of the remaining ones |
| Permissions granted you do not remember | An app has access to location, microphone, contacts | Broad permissions allow continuous data collection | The device’s privacy settings | Revoke the permissions that are not needed |
| A device administrator or profile added | A configuration profile has been installed | It can allow extended control over the device | General settings, profiles or device management section | Remove it if you do not recognise it; check with support if it is a work device |
| Forwarding rules on your mail | Messages are being copied elsewhere | It keeps working even after a password change | Your email account’s settings | Remove it and change the password |
| Abnormal data or battery consumption | Something is working in the background | A weak clue on its own, meaningful alongside others | Battery and data statistics | Check which apps are consuming; the topic is covered in Phone running slow: malware or age? |
| A sign-in to the maker’s account from an unusual place | Somebody got into the account linked to the device | It allows location and backups to be seen without touching the phone | Security emails, the maker’s account area | Change the password, turn MFA on, check the linked devices |
Signs you can observe yourself
| Signal | What it means | Why it matters | How you notice | What to do |
|---|---|---|---|---|
| The phone is in a different position from how you left it | Somebody picked it up | It is the simplest and most ignored signal | You find it turned over, moved, with the screen on | Check the sent messages and the recently opened apps |
| Messages showing as read that you did not open | Somebody opened the conversations | It indicates reading, not necessarily more | Notifications gone, conversations without a badge | Check what was opened; change the unlock code |
| Messages sent that you did not write | Somebody acted in your name | It exposes your contacts | Contacts reporting odd messages | Warn your contacts, change your account passwords |
| The unlock code no longer works | It was changed by somebody else | Loss of control over the device | You cannot unlock it despite typing it correctly | Lock it remotely, change your email password |
| Calls or messages suddenly not arriving | The number may have been transferred to somebody else | It compromises verification codes sent by text | The phone loses service for no reason | Contact your operator at once |
| Somebody knows things you never shared | Possible access to the device’s content | An indirect but concrete signal | A conversation in which a private detail surfaces | Check linked devices and forwarding rules |
| Settings changed that you do not remember | Somebody modified the configuration | It often precedes something else | Automatic lock lengthened, notifications turned back on | Restore the settings, change the code |
The most neglected signal
It deserves isolating: the phone found in a different position from how you left it.
It is a trivial observation, easily explained by distraction, and for exactly that reason it gets filed away without a thought. But it is often the only available signal of occasional access — because no other clue will be generated.
The appropriate reaction is not alarm: it is two thirty-second checks.
- Look at the messages sent in the last few hours.
- Look at the recently opened applications.
If neither shows anything unusual, distraction is the most likely explanation. If something does not add up, you have just gained time.
A concrete example
Mark leaves his phone in a gym changing room, in an unlocked bag. When he comes back he finds it where he left it.
Two weeks later, his partner asks him why he looked up information on a subject they have never discussed. Mark looked up nothing.
He checks the device: there is an application he does not remember installing, with permissions over location and notifications.
The signal had been there — a phone left unattended for forty minutes — but it had produced nothing visible at the time.
The lesson: after a period in which the device has been out of your control, it is worth checking the installed applications. It is the only way to detect prolonged access that leaves no other trace.
What to check, and how often
| Frequency | What to check |
|---|---|
| After the phone has been left unattended | Sent messages, recently opened apps, installed applications |
| Every 2–3 months | Devices linked to your main accounts; installed apps; granted permissions |
| Every 6 months | Configuration profiles or device administrators; forwarding rules on your mail |
| When something does not add up | Data and battery consumption per application |
| If phone service is interrupted | Contact your operator: it may not be a fault |
What is not an indicator
| Situation | Why it is usually not a signal |
|---|---|
| A battery lasting less over time | Batteries degrade: only a sudden change counts |
| A phone getting warm during heavy use | Normal behaviour with video, browsing or charging |
| Updated apps asking for new permissions | Part of the update cycle: check the permission, do not be alarmed |
| A “new” device in your account list | Often it is yours, after a system update |
| Unusual advertising notifications | They indicate your data is circulating in marketing lists, not access to the phone |
| High data use after an update | System updates are heavy |
The rule holds: an isolated signal deserves a check, two signals together deserve action.
If you find an indicator
- Change the device’s unlock code.
- Check the installed applications and remove what you do not recognise.
- Check the permissions granted to apps: location, microphone, contacts, notifications.
- Check for configuration profiles or device administrators.
- Check the forwarding rules on your mail: they keep working even after a password change.
- Change the passwords of your main accounts, starting with email, from a device you trust.
- Check the devices linked to each account and remove the unknown ones.
If the signals are many or serious, the cleanest route is resetting the device to factory settings, followed by reconfiguration. It is quicker than looking for what was changed.
The case of remote access through the account
It deserves its own section, because it leaves no trace on the device and for that reason nearly always escapes notice.
The phone is linked to a maker’s account, which handles updates, data backup and location. Whoever obtains that account’s credentials — reused, guessed, or obtained through a deceptive message — can in many cases:
- see where the device is, in real time;
- reach the backup of your data: photos, contacts, sometimes messages;
- see which other devices are linked to the same account.
The phone, meanwhile, works normally. There is no clue to observe on the screen.
Where to check. In the maker’s account area, from a computer: the list of linked devices, recent sign-ins, the associated email address.
How to protect yourself. Treat that account as critical: a unique, long password and a second factor enabled. It is often the least protected of the important accounts, precisely because it is not perceived as a service in its own right.
Two warnings
The absence of signals is not a guarantee. Access lasting a few minutes, if limited to reading, leaves almost nothing behind. That is why the protection rests on the unlock code and the automatic lock, not on observation.
Be careful with anything offering to check for you. Applications promising to “check whether your phone is being spied on” often ask for very broad permissions, and in some cases are themselves the problem. Every check described here is done with the device’s own settings, without installing anything.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Knowing where to look on a mobile device and what to look for |
| Awareness | Understanding that on a phone the detection system is you |
| Secure Behaviour | Making two quick checks after the device has been left unattended |
Reference level: FL3 — Autonomous.
Conclusion
No access alerts arrive on a phone. The most reliable signal is often the most trivial one: the device not being where you left it.
There is no need to live on alert. There is a need to know that, after a period in which the phone was out of your control, two minutes of checking are worth more than any monitoring application.
What to do right now. Open the list of applications installed on your phone and scroll to the bottom. If there is one you do not remember installing, you have just found something useful.
Related content
- Six digit passcode — the recommendation this belongs to
- Attacks on the lock screen — what generates these signals
- How to secure your phone unlock — what to do when you find one
- Impact of an unlocked phone — what is reachable if the signal is confirmed
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



