How to Check If Your iPhone Is Hacked in Settings: Evidence, Not Guesswork
Share
If you suspect your iPhone has been hacked, the most useful thing Settings can do is not “scan for hackers.” It can show evidence about which layer may have been compromised: your Apple Account, sharing permissions, device-management configuration, app access, or—far more rarely—the device itself.
That distinction prevents two common mistakes. A hot phone, fast battery drain or a crashing app can have ordinary causes and does not prove compromise. At the other extreme, an unknown device signed in to your Apple Account, an unrequested verification code, a profile you did not authorize, or a genuine Apple threat notification deserves prompt attention.
The safest approach is to preserve the evidence and check the highest-signal places first. Do not factory-reset the iPhone merely because one symptom feels suspicious; an erase can destroy useful clues before you know what actually happened.
Your Apple Account device list is the strongest first check in Settings
Open Settings → your name and scroll through the devices associated with your Apple Account. Tap any device you do not immediately recognize and inspect its details.
Apple lists several account-compromise signals that carry much more weight than generic performance symptoms: a sign-in notification for a device you do not recognize, a two-factor authentication code you did not request, messages or purchases you did not make, security details you did not change, a password that unexpectedly stops working, or a device placed in Lost Mode by someone else.
If an unfamiliar device really is attached to your account, remove it and change your Apple Account password. Apple also recommends checking the personal and security information at account.apple.com and confirming with your email provider and cellular carrier that you still control the email addresses and phone numbers tied to the account. This matters because an iPhone can be perfectly healthy while the account used on it has been compromised.
Safety Check answers a different question: who can still reach your information?
On iOS 16 or later, go to Settings → Privacy & Security → Safety Check. Safety Check is especially useful when the concern involves a former partner, family member, shared account arrangement, or someone who previously had legitimate access rather than an unknown remote attacker.
Use Manage Sharing & Access when you want to review access deliberately. Apple’s Safety Check can help you review people you are sharing information with, apps that have access to information, devices connected to your Apple Account, and security information. It can also reset app privacy permissions.
Emergency Reset is intentionally more sweeping. It can stop sharing quickly, so it is appropriate when immediate personal safety matters, but it should not be treated as a routine “malware cleaner.” Changing sharing relationships can also be visible to other people, so consider the personal-safety consequences before making abrupt changes.
An unknown management profile is concrete evidence; the menu itself is not
Go to Settings → General → VPN & Device Management. Apple says that if you do not see any profiles there, no device-management profiles are installed.
If a profile is present, its existence is not automatically malicious. Schools and businesses legitimately use configuration profiles and mobile device management to configure accounts, VPNs, apps and other settings. On a work- or school-owned iPhone, ask the administrator before deleting anything.
On a personal iPhone, a profile you never approved deserves investigation. Apple notes that device-management tools and custom apps can manage device functions and may allow access to data or location information. Removing a profile also removes the settings, apps and data associated with that profile, which is why identifying it before deletion matters. Apple’s current instructions for reviewing and removing profiles are in its Personal Safety User Guide.
App permissions tell you what software can reach, not who installed it
Next, review Settings → Privacy & Security. Look at sensitive categories such as Location Services, Microphone, Camera, Photos, Contacts and Bluetooth. The useful question is not whether an app has a permission; it is whether the permission makes sense for what you use that app to do.
A navigation app with location access may be expected. A simple calculator with access you cannot explain deserves scrutiny. Revoke permissions you no longer want, then see whether the app still behaves normally.
You can also inspect Settings → General → iPhone Storage to see installed apps. An unfamiliar app is a reason to investigate its identity and installation history, but do not assume every unfamiliar name is spyware: system components, employer-managed software and apps installed long ago can be easy to forget.
If you use App Privacy Report, it can add another layer of context by showing how apps have accessed certain data and contacted domains. Treat that as evidence to interpret, not an automatic malware verdict.
Battery drain and heat are weak signals until you can tie them to something specific
Open Settings → Battery and compare app activity with your actual use. A sudden unexplained change is worth investigating, especially if an unfamiliar app appears near the top. But battery use alone cannot tell you that an iPhone has been hacked.
Navigation, gaming, video calls, background photo processing, a recent software update, poor cellular signal and an aging battery can all increase power use or heat. The same is true of cellular-data spikes: Settings → Cellular can show which apps used mobile data, but heavy usage from a known streaming or cloud app has a very different meaning from unexplained activity by software you do not recognize.
This is an important evidence rule: performance symptoms become useful only when they connect to a second, more specific anomaly. Do not let a single battery graph push you into erasing a device.
Unexpected verification prompts are account evidence, not proof of iPhone malware
If you receive an Apple Account sign-in prompt or two-factor authentication code you did not request, do not approve it and do not share the code. Check your account device list and security information instead.
Apple’s current account-compromise guidance specifically treats unrecognized sign-in activity and unsolicited verification codes as warning signs. If you cannot change your password because someone else already changed it, Apple directs users to account recovery through iforgot.apple.com.
This distinction matters because phishing can compromise an account without installing anything on the iPhone. A factory reset would not fix a stolen Apple Account password; securing the account would.
A genuine Apple threat notification is a separate, high-severity branch
Apple threat notifications are designed for people Apple believes may have been individually targeted by mercenary spyware. Apple says these attacks are exceptionally sophisticated and that the vast majority of users will never be targeted.
As of 2026, Apple says a genuine threat notification can appear on the iPhone Lock Screen and in Settings, be sent by email, and appear as a banner after signing in to account.apple.com. Apple also says its threat notifications never ask you to click a link, open a file, install an app or profile, or provide your Apple Account password or verification code by email or phone.
If you receive one, take it seriously and verify it by signing in to the Apple Account site directly rather than following a message link. Apple recommends enabling Lockdown Mode and seeking expert help; its current threat-notification guidance points targeted users to specialized assistance.
Lockdown Mode is not a diagnostic test
Lockdown Mode is an extreme protection option for the small number of people who may face highly sophisticated targeted attacks. It deliberately restricts parts of the normal iPhone experience to reduce attack surface.
Do not turn it on merely to see whether battery drain or pop-ups disappear. That does not diagnose malware. If you have received a genuine Apple threat notification or have credible reason to believe you are individually targeted by mercenary spyware, follow Apple’s guidance. For ordinary phishing, account takeover or suspicious app-permission concerns, secure the affected layer instead.
Stolen Device Protection addresses the passcode-theft scenario
A different security problem occurs when someone physically steals an iPhone and knows its passcode. Apple’s Stolen Device Protection adds extra requirements for sensitive actions, including biometric authentication and, for some changes, a security delay.
On a supported iPhone, review it under Settings → Face ID & Passcode → Stolen Device Protection. Apple says the feature is available with iOS 17.3 or later and must be enabled before the device is lost or stolen. It is prevention, not evidence that someone already hacked the phone.
Do not erase the iPhone until you know what evidence you are trying to remove
A factory reset is sometimes appropriate, but it is a poor first diagnostic step. It cannot by itself secure a compromised email account, cellular account or Apple Account. It can also remove local evidence that would have helped you understand an unfamiliar profile, app or configuration.
If the strongest evidence is an unknown Apple Account device, secure the account. If it is an unauthorized sharing relationship, use Safety Check. If it is an unknown profile on a personal device, document and investigate the profile before removing it. If Apple has sent a genuine mercenary-spyware threat notification, follow the specialized response path instead of improvising a cleanup.
Only move toward erasing or restoring the iPhone after you have secured the accounts that will be used to set it up again and, where the incident is serious, preserved the information an expert may need.
Four patterns make the next action much clearer
Unknown device plus unrequested verification codes: treat this first as an Apple Account compromise. Change the password, remove unknown devices, review trusted information and confirm control of linked email addresses and phone numbers.
Unknown profile on a personal iPhone: treat this as a device-configuration issue. Identify what the profile manages, document it if needed, then follow Apple’s profile-removal guidance. Do not remove an employer or school profile without checking with the administrator.
Battery drain or heat with no account, profile, app or permission anomaly: do not label the phone hacked yet. Troubleshoot the performance symptom on its own merits and keep watching for higher-signal evidence.
Verified Apple threat notification: move out of ordinary consumer troubleshooting. Follow Apple’s mercenary-spyware guidance, consider Lockdown Mode and seek specialized security help.
The goal is to identify the compromised layer before you change it
There is no single Settings screen that can certify an iPhone as “clean,” and no single symptom that proves it has been hacked. What Settings does provide is a surprisingly useful evidence map.
Your Apple Account device list can expose unauthorized account access. Safety Check can reveal sharing and access relationships. VPN & Device Management can show installed management profiles. Privacy & Security can expose permissions that no longer make sense. Battery and Cellular data can support an investigation when they point to a specific app. Genuine Apple threat notifications create an entirely different, high-risk response path.
Work from the strongest evidence outward. That gives you a better chance of fixing the real problem without destroying clues, resetting unrelated settings or mistaking an ordinary software issue for an attack.