Know Phishing

How to Tell if Your Phone or Computer Has Been Hacked

A slow device or strange pop-up does not automatically mean you have been hacked. Learn which warning signs deserve attention, how to separate ordinary problems from suspicious activity, and what to do if something is wrong.

A slow computer, drained phone battery, frozen app, or unexpected pop-up can be frustrating, but none of those symptoms automatically means your device has been hacked. Devices have ordinary software problems too.

The signs that deserve the most attention are changes you did not make: unknown account activity, unfamiliar apps, altered security settings, unexpected messages sent from your accounts, or evidence that someone obtained remote access.

What are the strongest signs a phone or computer may be compromised?

Look for a pattern of unauthorized changes rather than one vague symptom. An unfamiliar sign-in plus a changed password, unknown software, or disabled security setting is more meaningful than a device simply running slowly.

1. Account activity you do not recognize

Unexpected sign-ins, password-reset messages, changed recovery information, purchases you did not make, or messages sent without your knowledge may indicate that an account—not necessarily the physical device—has been compromised.

2. Apps or programs you did not install

Review installed applications if something feels wrong. Some software is installed automatically with legitimate updates or other programs, so an unfamiliar name is not proof of malware. Investigate before removing something important.

3. Security settings changed unexpectedly

Pay attention if antivirus protection, firewall settings, browser protections, screen locks, or account-security features are turned off without your knowledge.

4. Browser behavior changes

Unexpected redirects, unfamiliar browser extensions, a changed search engine, or repeated unwanted advertising may indicate unwanted software or a browser configuration problem.

5. Your camera or microphone behaves unexpectedly

Modern devices often show an indicator when the camera or microphone is in use. An unexpected indicator deserves investigation, but first check which legitimate application is using the feature.

6. Messages are being sent from your accounts

If friends receive messages you did not send, determine whether the account itself was taken over. Change the account password and review active sessions from a trusted device.

7. Someone had remote access to the device

If you allowed an unexpected caller to install remote-control software or share your screen, treat that as a significant event even if the device appears normal afterward.

Your 30-second compromise check

What should you do first?

1. Secure your most important accounts

From a device you trust, protect your email account first because it is often used to reset other passwords. Then protect financial, shopping, social-media, and other important accounts. Use new unique passwords and enable two-factor authentication.

2. Review account sessions and recovery information

Look for unfamiliar devices or sessions and sign them out when possible. Confirm that recovery email addresses and phone numbers still belong to you.

3. Update the device

Install operating-system, browser, and application updates through their normal built-in update systems.

4. Run a trusted security scan

Use the device's built-in security tools or reputable security software. Avoid downloading a random “cleaner” because a pop-up claims your device is infected.

5. Remove suspicious remote-access software

If an unexpected caller instructed you to install remote-control software, end any active session and remove software you no longer need. If you are unsure what was changed, get help from a trusted technical professional.

What if your bank or payment information may be involved?

Contact the financial institution using a trusted number or its official app. Review transactions and follow its instructions for securing the account or replacing affected cards.

Should you reset the device?

A factory reset or complete operating-system reinstall can be appropriate in some situations, but it should not be the automatic first response to every suspicious symptom. Secure your accounts and preserve important files first. If malware continues, security tools cannot resolve it, or you know an attacker had extensive access, professional help or a clean reset may be appropriate.

What not to do

How do you know you are safer?

Your important accounts should have new unique passwords, two-factor authentication where available, and no unknown sessions. The device should be updated, scanned, and free of unwanted remote-access software or unexplained security changes.

The Know Phishing takeaway

Do not panic over one strange symptom. Look for unauthorized changes, secure important accounts from a trusted device, update and scan the affected device, and get trusted help when suspicious behavior continues.

Related Know Phishing Guides