Quick answer: a slow iPhone or a battery that drains faster than usual almost never means you’re hacked — those are normal wear-and-tear symptoms. Instead, real compromise leaves precise, detectable configuration footprints. Here are the 3 checks that take 30 seconds.
Verify whether your active VPN encryption tunnel exposes your real IPv4, IPv6, or DNS requests to local network sniffers and client servers. 100% in-browser, zero telemetry stored.
Test My Connection for Leaks →
Real iPhone compromise almost always leaves one of three fingerprints: a configuration profile you didn’t install (Settings › General › VPN & Device Management), a device you don’t recognize signed into your Apple ID (Settings › [your name] › scroll to device list), or an app you never downloaded. If none of those three show anything unfamiliar, the slowdown or battery drain you’re worried about is almost certainly unrelated to hacking — iOS updates, an aging battery, and background app refresh account for the vast majority of “is my iPhone hacked” searches that turn out to be nothing.
Is My iPhone Hacked? The Signs That Don’t Actually Mean Anything
Before the real checks, it’s worth ruling out what people usually search this question over. A hot phone, a draining battery, or a laggy Safari tab feel alarming, but on their own they’re not evidence of compromise:
- Battery draining faster: Apple states batteries retain up to 80% capacity after 500 charge cycles (~2–3 years).
- Phone feels sluggish: Usually a recent iOS background indexing pass or full internal storage.
- Data usage spiked: 9 times out of 10, it’s auto-downloaded podcasts or cloud photo sync.
- Phone warm during calls: Standard thermal behavior under sustained cellular/display loads.
- Unfamiliar Configuration Profile: Enables remote management & traffic rerouting.
- Unknown Apple ID Login: Hardware terminal accessing your synced Keychain & photos.
- Sideloaded Unknown App: Bypassing the App Store via developer enterprise certs.
- Persistent Green/Orange Dot: Mic or Camera active when no apps are running.
None of these are worthless signals — they’re just not specific enough to act on alone. The three checks below are specific enough.
1 Check 1: Unknown Configuration Profiles
This is the single most useful check on this page, and it takes under a minute. Configuration profiles are how organizations (and, less legitimately, attackers) push settings onto an iPhone remotely — VPN configs, restrictions, or in rare malicious cases, tools that monitor traffic.
If that section doesn’t appear at all, you have no profiles installed — that’s the good outcome. If it does appear, look at what’s listed. A profile from your employer or school is expected if you use a work or school device. A profile you don’t recognize, installed a specific date you remember something odd happening, is worth removing immediately: tap the profile, then Remove Profile.
2 Check 2: Devices Signed Into Your Apple ID
Go to Settings › [your name] at the top of the Settings app, then scroll down to the device list. Every device currently or recently signed into your Apple ID shows up here — your iPhone, any iPads, Macs, or Apple TVs you own. If you see a device model you don’t recognize, or a device you sold or gave away years ago that should have been signed out, that’s a real signal someone else has access to your Apple ID, not just your phone.
Tap the unfamiliar device and select Remove from Account. Then immediately change your Apple ID password from a device you trust, and check that two-factor authentication is enabled — if it somehow got turned off, that’s how an attacker would keep access after being removed once. Our 2FA setup guide covers exactly how to lock that down properly.
3 Check 3: Apps You Didn’t Install
Scroll through your home screen and app library for anything you don’t recognize. This sounds obvious, but it’s the check people skip because they assume a hack would look more dramatic. In practice, a genuinely unfamiliar app — especially one with a generic name like “System Update” or “Device Health” — installed through a configuration profile or a sideloading exploit is one of the more concrete signs something happened.
If you find one: don’t open it. Go to Settings, find the app under the app list, and delete it directly from there rather than tapping into it first. Then run the configuration-profile check above, since a rogue app on iOS almost always arrived alongside a profile that granted it more access than the App Store normally allows.
Using Apple’s Built-In Safety Check
iOS 16 and later includes a feature built for exactly this kind of situation, though it’s designed more for stopping someone with legitimate-turned-hostile access (an ex-partner, for example) than for detecting remote malware. Apple’s own Safety Check guide walks through two modes:
Immediately cuts off all sharing and resets permissions for every person and app in one single step. Use if you suspect active immediate snooping.
Lets you review and revoke access person-by-person and app-by-app without resetting trusted accounts. Slower but non-destructive.
Find it at Settings › Privacy & Security › Safety Check.
Signs of a Jailbreak You Didn’t Do
A jailbroken iPhone removes Apple’s normal app restrictions, which is what lets more invasive spyware run in the first place. If you didn’t jailbreak your own phone, look for: an app called Cydia or Sileo on the home screen (the standard jailbreak app stores), apps crashing more than usual as they conflict with modified system files, or noticeably faster battery drain that started abruptly rather than gradually. None of these alone is proof, but two or more together, especially paired with an unfamiliar configuration profile, is a strong enough signal to move to the response steps below rather than keep investigating on the device itself.
If You Found Something: The 5-Minute Containment Protocol
If any of the three checks above turned up something real, the order of operations matters:
- Change your Apple ID password first, from a device you’re confident is clean — a browser on someone else’s computer works fine for this one step.
- Remove the unfamiliar device or profile using the Settings steps above.
- Check 2FA is still active on your Apple ID and re-enable it if it was somehow turned off.
- Update iOS to the latest version — Settings › General › Software Update. Security patches close the specific exploits attackers rely on.
- If a specific person had physical access to your unlocked phone, change your device passcode too — a profile install requires the device passcode.
A full factory reset (Settings › General › Transfer or Reset iPhone › Erase All Content and Settings) is the nuclear option, and it’s rarely necessary if the four steps above are done properly. Reserve a full reset for cases where you found an unauthorized jailbreak.
Lockdown Mode: When It’s Actually Warranted
“Lockdown Mode offers an extreme, optional level of security for the very few users who, because of who they are or what they do, may be personally targeted by some of the most sophisticated digital threats.”
— Apple, Lockdown Mode announcement, July 2022
Apple’s Lockdown Mode is an extreme protection setting built for a narrow group of people — journalists, activists, and others who might specifically be targeted by state-sponsored spyware like Pegasus. It disables message attachments from unknown senders, blocks most link previews, and restricts wired connections when the phone is locked.
For the overwhelming majority of people reading this guide, Lockdown Mode is overkill. It’s worth turning on (Settings › Privacy & Security › Lockdown Mode) specifically if you have concrete reasons to believe you’re personally targeted.
How to Check If My Phone Is Hacked: The 3-Minute Version
If you just want to know how to check if your phone is hacked without reading the full breakdown above, here’s the condensed version in order of signal strength. First, go to Settings › General › VPN & Device Management — an unrecognized configuration profile here is the single most reliable sign of compromise on iPhone. Second, check Settings › [your name] for devices signed into your Apple ID you don’t recognize. Third, scan your home screen for apps you never installed. If all three come back clean, your iPhone almost certainly isn’t hacked, and normal explanations (battery age, a recent iOS update, background app refresh) account for whatever prompted you to check in the first place.
Frequently Asked Questions
How do I know if my iPhone is hacked, without checking every setting manually?
Can someone hack my iPhone just by knowing my phone number?
Does a factory reset guarantee my iPhone is clean again?
I found a device I don’t recognize in my Apple ID device list — what’s the very first thing I should do?
Is it normal for my iPhone’s battery to drain faster after an iOS update?
Can antivirus software detect iPhone hacking?
What should I do if your iPhone has been hacked?
How do you know if your iPhone has a virus?
Is My iPhone Hacked? The Verdict
For nearly everyone searching “is my iPhone hacked,” the honest answer is no — a slow phone or fast-draining battery has a mundane explanation. The three checks that actually matter take under two minutes combined: configuration profiles, Apple ID devices, and unfamiliar apps. If all three come back clean, trust that result rather than continuing to worry over normal wear-and-tear symptoms. If one of them turns up something real, the response steps above — password change, device removal, iOS update — resolve the overwhelming majority of cases without needing a full reset.