Is My Phone Hacked? Real Signs, the *#21# Myth and a 10-Minute Check
In a hurry? Quick summary
- ✓A hot, slow phone with a draining battery is almost always an old battery or a heavy app. The signs that matter are different: OTPs you never requested, messages your contacts got that you never sent, apps you didn't install, or WhatsApp suddenly logging you out
- ✓No dial code can tell you whether a phone is hacked. *#21# only shows whether your voice calls are being forwarded; ##002# switches all forwarding off. Never dial a code that a caller dictates to you — that is how forwarding gets switched on
- ✓In India "hacked" usually means one of four things: an account taken over, a fake APK you were tricked into installing, calls forwarded to a scammer, or a monitoring app put there by someone who had your phone in hand
- ✓The 10-minute check: Play Protect scan, the app list, special permissions (Accessibility, device admin, SMS), call forwarding, Google account devices, and WhatsApp linked devices
- ✓If you find something and money is involved, call your bank and 1930 first. Then remove the app, change passwords from a different device, and factory reset if a remote-access or banking-trojan app was on the phone
Your phone has been running hot, the battery is gone by 4 pm, and a WhatsApp forward says to dial a secret code to find out whether you're being hacked. So you search "phone hack hai ya nahi kaise pata kare" and get twenty videos repeating the same five symptoms and the same code.
Most of that advice is wrong in both directions. The symptoms it lists are usually an ageing battery, and the things that really happen to Indian phone users — a hijacked WhatsApp, a fake "wedding invitation" app reading OTPs, calls quietly forwarded to a stranger — often show none of those symptoms. This guide covers what "hacked" really means here, which signs matter, what the codes do and don't do, a 10-minute check you can run right now, and what to do if you find something.
What "hacked" actually means in India
For ordinary users, a compromise is almost always one of these:
1. An account is taken over, not the phone. Someone has your Google, Instagram or WhatsApp login — through a phishing page, a reused password from a leaked site, or a 6-digit code you were talked into sharing. The phone itself is clean. This is the most common case by far.
2. A malicious app you installed yourself. A message arrives on WhatsApp, often from a contact whose own phone is already infected: a wedding invitation, an "RTO e-challan", a bank KYC update, a PM-Kisan form. The attachment is an .apk file. Once installed, it asks for SMS, notification and Accessibility access, reads every OTP that arrives, and forwards itself to your contacts. A real invitation is a photo, a PDF or a link. It is never an app.
3. Calls forwarded to someone else. A caller posing as a delivery agent or customer care asks you to dial a code "to confirm your order". The code switches on call forwarding to their number, and they then use the "call me instead" option to receive verification calls for your WhatsApp or bank.
4. A monitoring app installed by someone who held your phone. A partner, relative or colleague with a few unlocked minutes can install a commercial spy app (stalkerware) that copies messages, location and photos.
There is a fifth category — government-grade spyware such as Pegasus, reported on the phones of journalists and activists. It exists, it is rare, it costs a fortune per target, and it is not what a warm phone means.
Signs that mean very little on their own
- Battery draining fast. Batteries lose capacity after two to three years. Settings → Battery shows which app is using it; it is usually Instagram, YouTube or a game.
- Phone heating up. Charging, gaming, video calls, summer, and a thick case.
- Slow phone. Storage over 90% full and years of updates on old hardware.
- Data running out. Auto-play video and background backups.
- Ads popping up in notifications. Almost always a website you allowed to send notifications. Chrome → Settings → Notifications, and remove sites you don't recognise.
- A web page shouting "13 viruses found!" That is an advertisement, not a scan. Close the tab.
Any one of these, alone, is not evidence. A sudden change in several, together with something from the next list, is.
Signs that do matter
- OTPs, password-reset emails or login alerts you did not request
- Contacts say they received messages, links or money requests you never sent
- An app on the phone you don't remember installing, especially one with a generic name like "System Update" or "Sync Service"
- An unknown app holding Accessibility, device admin or SMS access
- Play Protect is switched off, or "Install unknown apps" is allowed for WhatsApp or your browser, and you didn't do it
- WhatsApp shows "your number is registered on another device", or there is an unknown entry under Linked devices
- The SIM suddenly shows "No service" for hours while others on the same network are fine
- The camera or microphone indicator (green dot on Android 12 and later) lights up when you aren't using either
- A transaction, a loan enquiry or a new SIM in your name that you know nothing about
The truth about *#21#, *#62# and ##002#
These are standard network codes for call forwarding. Here is what each one really does:
*#21#shows whether all your voice calls are being forwarded, and to which number. On a normal phone it says "not forwarded".*#62#shows where calls go when your phone is unreachable. It commonly shows a number belonging to your own operator's voicemail or missed-call service. An unfamiliar number here is not proof of anything; ask your operator before panicking.##002#cancels every kind of forwarding in one go. It is safe to dial at any time.
What they cannot do: detect malware, spy apps, a hijacked account or "tapping". No code can. Call forwarding also diverts voice calls, not your SMS, so a clean *#21# result says nothing about an app reading your messages.
The real danger runs the other way. Codes that start with *21* or *401* followed by a phone number switch forwarding on. In 2024 the telecom department told operators to stop code-based activation of call forwarding because of exactly this scam, yet police advisories about "dial this code" calls have kept coming. The rule is simple: never dial a code a caller reads out to you. Some networks use different codes or block them, so the reliable place to look is the Phone app → Settings → Call forwarding, which works on every operator.
The 10-minute check (Android)
Menu names differ slightly between Samsung, Xiaomi, Realme and others. The search bar inside Settings finds each of these.
- Run Play Protect. Play Store → your profile photo → Play Protect → Scan. If it was switched off and you didn't do that, treat it as a warning sign in itself.
- Read the full app list. Settings → Apps → See all apps. Search the name of anything you don't recognise before deleting it. Remove AnyDesk, TeamViewer QuickSupport and similar remote-access apps unless you put them there for a reason that still exists.
- Check special access. Settings → Accessibility → Downloaded apps, then Settings → Apps → Special app access → Device admin apps, Notification access, Display over other apps and Install unknown apps. Anything unfamiliar gets switched off and uninstalled. Accessibility is the permission that lets an app read your screen and tap for you.
- Check who can read SMS. Settings → Privacy → Permission manager → SMS. Your messaging app, your dialler and a few apps you chose. Not a torch, a photo editor or a "challan" app.
- Check call forwarding. Phone app → Settings → Call forwarding, or dial
*#21#. Cancel anything you didn't set with##002#. - Check your Google account. Open myaccount.google.com → Security → Your devices and sign out of any device you don't own. Confirm the recovery phone and email are yours. On a computer, open Gmail settings and make sure no forwarding address has been added.
- Check messaging and social sessions. WhatsApp → Settings → Linked devices. Telegram → Settings → Devices. Instagram → Accounts Centre → Password and security → Where you're logged in. Log out anything unfamiliar.
- Check the SIMs in your name. The Sanchar Saathi portal or app has a "know the mobile connections in your name" option. Report any number that isn't yours.
On iPhone, malicious apps are rare unless the phone is jailbroken. The realistic risks are someone knowing your Apple ID password or an unknown configuration profile. Check Settings → your name for the device list, Settings → General → VPN & Device Management for profiles you didn't install, and run Settings → Privacy & Security → Safety Check.
If you found something: what to do, in order
- Money first. If a payment went out or you shared a banking OTP, call your bank's fraud line and then 1930 immediately. Our guide to UPI, OTP and SIM-swap scams covers the first 30 minutes in detail.
- Remove the app. If it won't uninstall, first remove it from Device admin apps. If it still resists, restart in Safe mode (on most phones: hold the power button, then press and hold "Power off") and uninstall from there.
- Cancel forwarding with
##002#. - Change passwords from a different, clean device. Email first, because email resets everything else. Then banking, then social. Use "sign out of all devices" wherever it is offered and turn on 2-step verification. If you have been reusing one password everywhere, this is the moment to move to a password manager such as Dashlane, so one leak no longer opens every account.
- Secure WhatsApp. Log out unknown linked devices and set a PIN under Settings → Account → Two-step verification. If you were logged out, re-register your number to push the other person out.
- Tell your contacts. One message: "My phone/account was compromised, ignore any link or money request from me." It stops the chain.
- Factory reset when a remote-access app or fake banking/challan APK was installed, an unknown app held device-admin or Accessibility access, or you can't find the cause but the activity continues. Back up photos and contacts only, then reinstall apps fresh from the Play Store.
- Report it. File at cybercrime.gov.in even if no money was lost, and report the scam number through Chakshu on Sanchar Saathi.
If the incident involves threats over private photos or a recorded video call, that is a different playbook; see our sextortion guide.
If you think someone you know is watching your phone
Stalkerware needs physical access, so the question is who has held your unlocked phone. The check is step 3 above: an app with Accessibility, device-admin or notification access that you didn't put there, plus Play Protect switched off. Change your screen lock to a PIN nobody else knows and change your Google password from another device.
Two honest cautions. Removing the app can alert the person who installed it; if your safety at home is a concern, seek help from a device they can't see before you remove anything. And if you are the one tempted to install such an app on a partner's phone: unauthorised access to another adult's device can be an offence under the IT Act, and it ends trust faster than whatever you were hoping to find.
Do you need a security app?
Play Protect is the baseline and it is free. For someone who installs only from the Play Store, keeps the phone updated and doesn't hand it around, that plus the check above is enough.
A dedicated security app earns its place if you sometimes install APKs from links, you've already been hit once, or the phone belongs to a parent who taps whatever arrives on WhatsApp.
A VPN, for the record, is not a hacking shield: it hides your traffic from the network you're on and does nothing about a malicious app or a stolen password. Our VPN guide explains what it is for.
The bottom line
A phone that is hot, slow and hungry is usually just old. A phone that is compromised usually looks normal, and gives itself away through activity you didn't cause: an OTP, a message, an app, a login. No dial code can tell the difference, though *#21# and ##002# are worth knowing for the one thing they do. Run the 10-minute check now, and again whenever something feels off. If you find something: money first, then the app, then passwords from a clean device.
Frequently asked questions
- Does dialling *#21# tell you if your phone is hacked?
- No. *#21# is a network code that shows whether unconditional call forwarding is switched on for your number, and to which number. It says nothing about malware, spy apps or stolen passwords, and fact-checkers have debunked the viral claim that it reveals hacking or tapping. It is still a useful check, because scammers do trick people into forwarding their calls. If it shows a number you don't recognise, dial ##002# to cancel all forwarding and call your operator.
- What are the signs that my phone is hacked?
- The reliable ones are about activity, not performance: OTPs or password-reset messages you didn't ask for, contacts receiving messages or money requests you never sent, an app you don't remember installing, an unknown app holding Accessibility or device-admin access, Play Protect switched off, WhatsApp saying your number was registered on another device, or a login alert from Google for a device you don't own. Battery drain, heat and slowness on their own usually have boring causes.
- What should I do first if my phone is hacked?
- If money has moved or a banking OTP was shared, call your bank's fraud line and then 1930 before anything else, because minutes matter. Next, uninstall the suspicious app (use Safe mode if it refuses), cancel call forwarding with ##002#, and change your email, banking and social passwords from a different device you trust, signing out every other session. If a remote-access or fake banking app was installed, back up photos and contacts and factory reset the phone.
- Can someone hack my phone with just my number?
- Knowing your number is not enough to get inside the phone. What a number does allow is scam calls, attempts to take over WhatsApp by tricking you out of the 6-digit code, and SIM-swap fraud at a telecom store. Picking up a call does not infect an updated phone, and on a current Android a link alone rarely installs anything — you have to install the file and grant permissions yourself. Attacks that need no tap from you do exist, but they are expensive and aimed at specific high-profile targets.
- Does a factory reset remove a hacker?
- It removes malicious apps in almost every ordinary case, which is why it is the right last step after a fake APK or remote-access app. It does not fix what lives outside the phone: call forwarding set at the network, linked WhatsApp or Google sessions, passwords already stolen, or a SIM issued to someone else. Do those steps too, and after the reset install apps fresh from the Play Store instead of restoring old APK files.
More in this topic
Sextortion in India: What to Do, and How to Make Yourself a Hard Target
How sextortion scams actually run in India, the one rule that matters most (don't pay), the exact steps to take right now, what the law says, and how to make yourself a hard target.
7 September 2026 · 8 min read
UPI, OTP and SIM-Swap Scams: How They Work, and the 10-Minute Phone Lockdown
How UPI refund scams, OTP calls, digital arrest and SIM-swap fraud actually work in India, what to do in the first 30 minutes if you're scammed, and a 10-minute checklist to lock down your phone.
7 September 2026 · 8 min read
Do You Actually Need a VPN in India? An Honest Guide
What a VPN actually encrypts and hides, what it can't protect you from, the CERT-In rules that changed Indian servers, and when it's genuinely worth paying for one.
7 September 2026 · 9 min read