Is my phone hacked or infected with Pegasus spyware?
It is one of the most common questions in digital security, and one of the hardest to answer honestly: is my phone hacked? Maybe the battery is draining faster than it used to. Maybe someone seems to know things they shouldn’t. Maybe you just have a bad feeling. This guide walks through how to think about it clearly — the signs that actually matter, the ones that usually don’t, how to check on iPhone and Android, and what to do if the answer turns out to be yes.
Before anything else, one framing that saves a lot of worry: there are two very different threats hiding inside this one question, and they behave in opposite ways.
Two different threats, two different answers
Commodity spyware and “stalkerware” is cheap, widely available software that a person — an abusive partner, a suspicious employer, a family member — installs to monitor someone. It usually needs brief physical access to your unlocked phone to set up. Crucially, it is often sloppy: it can leave visible traces and cause the exact symptoms people worry about.
Mercenary spyware — Pegasus, Predator, Graphite and the like — is the opposite. It is nation-state grade, sold to governments, aimed at specific high-value targets, and engineered to be invisible. It typically shows no symptoms at all.
Which one you should worry about depends far more on who you are than on how your phone feels. A journalist, lawyer, activist, or official faces a different threat than someone worried about a controlling ex — and the checks below differ accordingly.
Signs that might point to commodity spyware
If someone has installed monitoring software on your device, you may notice some of these. None is proof on its own — most have ordinary explanations too — but a cluster of them is worth taking seriously:
- Battery draining much faster than it used to, or the phone running warm when idle.
- Unexpected spikes in data usage — spyware quietly uploads what it collects.
- Apps, profiles, or settings you don’t recognise, especially a “device admin” app or a configuration profile you didn’t add.
- The phone behaving oddly — restarting on its own, screen lighting up unprompted, slow performance.
- Someone knowing things they could only know from your messages, location, or calls.
Be fair to yourself here: a two-year-old battery drains faster, apps update and use data, and phones get slow. Symptoms raise a question; they rarely answer it.
The uncomfortable truth about the serious stuff
Here is what most “signs your phone is hacked” articles won’t tell you: if you are the target of mercenary spyware, you almost certainly will not notice anything. No battery drain you’d spot, no strange app, no pop-up. Some versions live only in the phone’s memory and disappear on reboot specifically so they leave nothing behind. People find out they were targeted when a research lab examines their device or Apple sends them a threat notification — not because the phone “felt off.”
So the absence of symptoms is not proof you’re clean. For high-risk people, “it seems fine” is exactly what a well-built implant is designed to make you think.
How to actually check
On iPhone:
- Update iOS. Many infections rely on flaws that a current update has already closed.
- Check for an Apple threat notification. Apple directly alerts users it believes were targeted by mercenary spyware, at the top of your Apple ID account page and by email/iMessage to the address on file. If you ever get one, treat it as real.
- Review Settings → General → VPN & Device Management for configuration profiles you didn’t install, and check your Apple ID for devices and sessions you don’t recognise.
- Turn on Lockdown Mode (Settings → Privacy & Security). It removes attack surface and has blocked real attacks.
- Reboot. It won’t fix a persistent infection, but it can clear a memory-only one.
On Android:
- Update Android, then run a Play Protect scan.
- Review installed apps and “Device admin apps” (Settings → Security) for anything unfamiliar — stalkerware often hides here, sometimes with an innocuous name.
- Check which apps have accessibility, notification, or admin permissions, which monitoring tools abuse.
If you have real reason to be concerned — you’re a journalist, activist, or in an unsafe relationship, or you got a threat notification — go beyond self-checks and get a proper forensic look. Amnesty International’s Mobile Verification Toolkit (MVT) and consumer tools like iVerify and iMazing’s spyware analyzer examine a device far more rigorously than any on-phone setting. Access Now’s Digital Security Helpline offers free, confidential help to civil-society targets.
If you think your phone is compromised
- Don’t tip off whoever installed it by suddenly deleting apps — especially in a domestic-abuse situation, where a change in behaviour can escalate risk. Make a safety plan first.
- Use a different, trusted device for anything sensitive until you’ve sorted it out.
- Change important passwords from that clean device, and turn on two-factor authentication.
- Update, reboot, and consider a factory reset — but understand a reset removes commodity spyware far more reliably than it removes a sophisticated implant, and restoring from an infected backup can reinfect you.
- Get expert help rather than going it alone if the stakes are high.
Where SireShield fits
Notice how much of the above is guesswork — reading tea leaves from battery life and hoping a one-time scan catches something built to hide. That guessing game is exactly the problem SireShield exists to remove.
Instead of asking “does my phone feel off today?”, SireShield watches your device continuously for the quiet signals mercenary spyware leaves behind, helps you reduce the exposure that makes you a target in the first place, and gives you a clear, fast response the moment something changes — so the answer to “is my phone compromised?” is monitored in real time, not left to intuition.
You can’t stop the rain. But you can carry an umbrella — and you can know the moment it starts.
If you’re a journalist, lawyer, official, or anyone entrusted with information worth stealing, learn more and apply for access.
Further reading: The Citizen Lab and Amnesty International’s Security Lab publish independent, technical guidance on detecting and defending against these tools.