How to tell if your iPhone has been hacked (and what to do next)
- ESET Expert

- 5 hours ago
- 8 min read
iPhones are difficult to hack, but they are not immune to sophisticated attacks. Learn how to distinguish genuine signs of compromise from common device issues, strengthen your security, and take the right steps if you suspect your iPhone has been hacked.

iPhones are hard to hack but not immune. Protect your device by switching on automatic iOS updates, creating a strong Apple ID + 2FA, and – if you’re a high-risk user – enabling Lockdown Mode. Remember that even updated iPhones have been hit by zero-click spyware. But these are extremely rare. Most “signs” of compromise have innocent explanations. Do not confuse them with genuine indicators of malicious activity.
Apple’s iPhones have long been considered the gold standard when it comes to cybersecurity. And that’s largely still true, thanks to its rigorous vetting of apps on the App Store, the way it isolates apps from each other, and various security features built into devices. But we live so much of our lives on our mobile phones today that it’s understandable to be concerned if you think something’s wrong.
The good news is that genuine threats like commercial spyware are relatively few and far between. And most are usually fixable with a few simple steps. Don’t mistake false alarms for genuine threats.
Can an iPhone actually be hacked?
The short answer is yes: but the vast majority of users will be sufficiently protected by Apple’s range of security features. Still, there are theoretically various ways that hackers can target your device. And even fully updated, non-jailbroken handsets could be compromised by advanced spyware, although this is extremely rare.
Warning signs your iPhone may be compromised
Some signs of compromise should be taken more seriously than others. It pays to understand the difference between each group.
Signs worth taking seriously
Unknown configuration profiles or mobile device management (MDM). Configuration files change how your device behaves. MDM is usually deployed by companies to manage fleets of devices. Both could signify that someone has access to your device and is trying to manipulate it. Check by going to Settings → General → VPN & Device Management. On a personal device this list should be empty or contain only profiles you knowingly approved
An Apple ID you don’t recognize. Your Apple ID/account automatically tracks the devices signed into it. If there are any IDs you don’t recognize, someone else may have access to this account. Go to Settings → [your name] to look for devices using your Apple ID
Unprompted two-factor authentication (2FA) prompts. This signals someone trying to sign into your Apple ID/account on a new device. If you don’t recognize the request, don’t allow it
Unfamiliar apps with broad permissions. Apps may look innocuous, but if you don’t remember installing them and their permissions seem excessive, it could be a sign of malware. Go to Settings → Privacy & Security to review apps and revoke permissions
An Apple threat notification. This is the most serious sign of infection. Apple sometimes flags users it believes have been targeted by advanced spyware. If you see such a message, either sent via email or a notification on your device, follow Apple’s instructions. But be sure this message is really coming from Apple not from scammers impersonating the company.
Signs that are usually nothing
Be less worried about battery drain, as this could happen for a variety of innocuous reasons, including recent iOS updates, background activity, gaming/streaming or an old battery. Similarly, a warm phone can be caused by recent updates, bulky downloads, or using GPS, video calls, or games. The device may have been left in the sun, or it might have been charging wirelessly.
The device should cool down after a while. Also, don’t assume the worst if your iPhone apps crash once in a while. Sometimes even iOS software can be buggy, especially after updates or if memory space is limited.
The “secret codes” myth
Don’t believe everything you read online. Man-Machine Interface codes (MMI codes) are not a sign of spyware – they are dialer sequences to interact directly with your cellular network. *#21# simply checks the status of certain call forwarding settings. And ##002# clears certain call forwarding settings. It’s the same with other similar codes.
How iPhones really get compromised in 2026
Be aware of the following potential threat vectors:
Phishing/malicious websites: Arguably the most common way iPhones get compromised. You might click through on a convincing-looking email/message from a hacker and get tricked into handing over your password and one-time verification code. Alternatively, you might visit a malicious website which automatically installs malware without your knowledge in a “drive-by-download” attack.
Fake or abused apps: The App Store is pretty good at vetting malicious apps, but it is not 100% effective in doing so. If you install a malicious app it may try to steal information off your phone, or sign you up to expensive subscription-based services.
Physical access and stalkerware: If someone has access to your phone and is able to unlock it (e.g. by knowing your passcode) they could change your account settings, read your messages, add other trusted devices to your account and more. Stalkerware isn’t as common on iOS as Android.
Apple ID / iCloud takeover: If a hacker is able to hijack your Apple/iCloud account by phishing or malware, they could access some of the most sensitive information you access via your iPhone, including photos, contacts, notes, calendars, iCloud drive files and location.
Zero-click mercenary spyware: This is the rarest and most advanced threat. Specially crafted spyware is designed to hijack your device and usually arrives via a message. However, the message may not require you to open it or perform any other interaction from your side. Furthermore, these threats are only ever used to target high-risk individuals like journalists, activists, senior executives and political figures.
DarkSword is a rare example of a drive-by-download attack designed to compromise iPhone devices. Used by commercial spyware vendors and nation state hackers since at least November 2025, it combines exploits for six vulnerabilities in iOS and Safari to install malware on targeted devices. All victims have to do is simply visit a malicious web page. Full device compromise and data theft follows. However, these vulnerabilities have been patched by Apple.
Another highly targeted and rare campaign affecting a very small number of iPhone users was Graphite. It was a zero-click attack arriving as an iMessage which exploited vulnerability known as CVE-2025-43200. Again, this was aimed at human rights activists and journalists rather than the populace at large. Apple also patched this vulnerability, proving that updating your device is one of the most effective steps you can take against possible compromise.
What to do if you think your iPhone has been hacked
Don’t panic and follow this recovery framework, step by step:
1. Update iOS immediately (Settings → General → Software Update; turn on automatic updates). Link to Apple support.
2. Run Apple’s Safety Check (Settings → Privacy & Security → Safety Check) to review who/what has access; revoke unknowns.
3. Secure your Apple ID - change the password, turn on two-factor authentication, review trusted devices and signed-in sessions.
4. Remove unknown configuration profiles, MDM and VPNs (Settings → General → VPN & Device Management); delete apps you don’t recognize.
5. If you may be a high-risk target (journalist, activist, executive): turn on Lockdown Mode, take any Apple threat notification seriously, and get expert help (e.g. Access Now’s Digital Security Helpline). Only perform a factory reset as a last resort - and note that a firmware or spyware-level compromise could outlast a reset. It’s better to escalate in these circumstances, rather than rely on a reset.
Did Apple send you a threat notification?
This is one of the few alerts you should take seriously. It is reserved for only the most sophisticated and targeted attacks (like those above) where Apple directly notifies you that your device may have been targeted by mercenary spyware. You will most likely receive a notification when you sign into your Apple account. It could also be an alert sitting in your settings and/or you may additionally receive an email. This is not the same as a spammy “virus” popup.
If you receive only an email and no other notification, it could be a phishing attempt. Remember: Apple will never ask you to install software or call a support number in these notifications. If you receive one of these alerts, update your device, change your passwords/logins, switch on Lockdown Mode and consider expert assistance.
How to lock down your iPhone against the next attack
Prevention is always better than cure. So, consider the following:
Update your iOS as quickly as possible, to fix any vulnerabilities which hackers could exploit
Turn on automatic updates which will keep your device on the most secure version going forward
Be phishing-aware when receiving any unsolicited emails, messages or even calls. Never hand out your logins or other personal information if requested. Always double check with the stated sender (and not via replying to the message)
Review your app permissions to check if any are requesting more than they should be, as this could be a warning sign
Ensure you use a strong Apple ID password and two-factor authentication (2FA), and never share verification codes with someone who contacts you out of the blue. This will minimize the risks associated with phishing
Use Lockdown Mode if you think you’re particularly vulnerable to mercenary spyware. This is a special feature which reduces your attack surface, although it will also limit some of your phone’s functionality
Choose a reputable security app for iOS from a trusted provider which features web/phishing protection. This will help to block malicious sites used to deliver attacks like DarkSword. And phishing websites designed to harvest your credentials. Be aware, however, that it won’t block sophisticated spyware.
Tips from ESET expert
- OLADIMEJI ADETUNJI, LEAD, TECHNICAL SUPPORT |
Apple iPhones are still among the most secure devices you’ll find on the market. But it’s equally important to realize that nothing can be 100% immune to compromise, and phishing in particular remains an ever-present threat.
If you see something that doesn’t look right, don’t jump to conclusions. Look for genuine signs of malicious activity. If you’re a high-risk user, you might want to take extra precautions like Lockdown Mode. But for regular iPhone users, do the basics including strong passwords and automatic updates, and you’ll stand the best chance of staying safe.
FAQS
Can iPhones be hacked?
Yes, but it’s rare. Apple’s built-in security features make iPhones one of the most secure smartphones available. Most attacks rely on phishing, stolen Apple ID credentials, or malicious apps rather than sophisticated hacking. Advanced mercenary spyware does exist, but is typically used against high-risk targets like journalists, and activists.
Can someone hack my iPhone without me clicking anything?
Yes, but these “zero-click” attacks are extremely rare. They exploit zero-day (unknown to developers) vulnerabilities to hijack a device without any user interaction, usually through services like iMessage. They are used specifically to target high-risk users, as above.
Do secret codes show if my phone is tapped?
No, this is a myth. MMI codes like *#21# and ##002# do not detect spyware or reveal whether your phone has been hacked. They simply display or reset certain call forwarding settings.
Does a factory reset remove spyware?
In most cases, it will remove conventional malware and unwanted apps. But if your Apple ID has been compromised, this approach will not secure your account. If you’re compromised by mercenary spyware a factory reset may not be sufficient.
Can an iPhone get spyware without jailbreaking?
Yes. But remember that jailbreaking removes many of Apple’s built-in security protections, so think carefully before doing it.
What is Lockdown Mode and should I use it?
It’s an optional iPhone security feature designed to protect against sophisticated cyberattacks such as mercenary spyware. It reduces your device’s attack surface by restricting certain features and services, which can limit some functionality. Most people won’t need it, but it is recommended for individuals who face an elevated risk of targeted attacks, such as journalists, human rights activists, political figures and senior executives.



Comments