Skip to main content
mendmyi
A black iPhone 15 lying face up beside a closed MacBook Pro on a pale grey bench, joined by a single USB-C cable into the bottom of the phone, ready for a full erase and reinstall
Care

What to Do if Your Phone Is Hacked after a Scam

By Riki Baker · Updated 2 October 2026

A hacked phone is one that someone else has had access to, either the device itself through a screen-sharing app, a malicious app or a management profile, or the accounts signed in on it through a stolen password. Fixing it means dealing with both, and the order matters more than the speed.

Most people reach for the phone first, because the phone is the thing in their hand. Change your passwords on it, delete the strange app, maybe reset it. That gets the order backwards. If someone can still see the phone, they watch you type the new passwords. If you reset it before you have saved your passwords, you lock yourself out of your own handset and lose every login you did not write down. And if you then restore the backup you took yesterday, you reinstall whatever they left.

So: accounts first, from a different device. Then your passwords and a backup. Then the erase. Then set up as new. The rest of this guide is those five steps in order, and why each one is where it is.

  1. 1
    Secure your accounts, from a different device

    Email and banking passwords first, two-step verification on, your bank by dialling 159. Not from the phone you suspect.

  2. 2
    Save your passwords and back up

    Your Apple Account or Google Account password first, then every other login you use, then check iCloud or Google backup is on. The erase in step 3 takes everything.

  3. 3
    Erase it and reinstall the operating system

    A full erase destroys the encryption keys, so nothing on the phone survives. Do it yourself from Settings, or have it done and documented.

  4. 4
    Set it up as new, not from the old backup

    The backup taken while someone had access can bring the problem straight back. Sign in and let the cloud refill it instead.

  5. 5
    Expect the follow-up call

    People who have been scammed once get called again by someone offering to get the money back for a fee. Your bank and the police never charge.

First, what a scammer could actually do

The version that brings most people to us starts with a call. Someone from the bank's fraud team, or the broadband provider, or "Microsoft", says there is a problem and offers to fix it. They talk you through installing a screen-sharing app. Barclays describes what follows: once they have control, they try to access your bank accounts and steal your money. NatWest names the apps involved as AnyDesk, TeamViewer or LogMeIn, all legitimate tools with a legitimate purpose, which is why the app stores let you install them.

On a phone, that app mostly shows them your screen and lets them watch you type. That is enough. They see the balance, they see the one-time code arrive, and they talk you through a transfer to a "safe account" that is theirs. UK Finance counted 248,070 of these authorised push payment cases in 2025, with £576.4m lost, up 19 per cent on the year before.

The quieter version leaves something behind. A configuration profile on an iPhone, which Apple says may allow access to data or location information on the device. Call forwarding switched on so that the bank's verification call goes to them. A forwarding rule in your email so that every password reset is copied to an address you have never seen. None of that needs the phone to be "infected" in the way the word suggests. It needs five minutes with the phone unlocked, which is exactly what the call bought them.

1. Secure your accounts from a different device

Borrow a laptop, a partner's phone, a tablet. Not the phone you suspect. Then work through the NCSC's steps for recovering a hacked account, starting with email, because every other account's password reset lands in it. Change the password. Check for a forwarding rule, which the NCSC calls "a common tactic". Log every device and app out of the account. Turn on two-step verification. Then do the same for your Apple or Google account, and for banking.

Then the bank, on a number that cannot be faked

Call your bank by dialling 159. It works like 101 for the police or 111 for the NHS and connects you to your own bank; Stop Scams UK's point is that the number cannot be faked and 159 will never call you. If money has gone, report it to Report Fraud, the service that replaced Action Fraud in December 2025, on 0300 123 2040. Since October 2024, UK banks have had to reimburse most authorised push payment fraud up to £85,000, provided you report it promptly and cooperate.

If you suspect your Apple Account specifically, Apple's own checklist is to change the password, remove any device you do not recognise, and check with your network that no SMS forwarding has been set up on your number. That last one is the step people miss, and it is the one that lets a scammer keep receiving your codes after everything else is locked down.

2. Save your passwords and back up before you erase anything

A single black iPhone 15 lying face up on a pale grey surface with a small closed brass padlock resting beside it

The first is your Apple Account or Google Account password. After an erase, an iPhone with Find My on will not activate until that password is entered: Apple's Activation Lock page says the password is required before anyone can erase, reactivate or use the device, and that if you cannot recover the account you may be unable to use the phone at all. Android has the same lock under a different name, Factory Reset Protection, and Google adds one more thing: if you have just changed that Google password, wait 24 hours before you reset. Which, after step 1, you probably have.

Then every other password you use

The erase takes everything, so write down all of them, not just the account one. Passwords saved to iCloud Keychain or Google Password Manager are not in this group; they come back when you sign in. Authenticator codes, notes, and app logins you set up once and forgot are. If you want a file of your saved passwords, Apple's export is Mac-only, from the Passwords app, and Apple warns that the exported file is unencrypted and should be deleted once it has been imported elsewhere.

Then check the backup

On an iPhone, open Settings, tap your name, then iCloud, and make sure Photos, Contacts and iCloud Backup are switched on; Apple's page on backing up with iCloud has the steps. On Android it is Settings, Google, Backup, plus backup in the Google Photos app (Google's steps). Synced photos, contacts and passwords come back on the clean phone on their own once you sign in. The full backup is your safety net in case something was never synced; step 4 explains why it is not the thing you restore first.

People skip this step because it feels like admin. It is the one that decides whether you leave the shop with a working phone or a very clean, very empty one.

3. Erase the phone and reinstall the operating system

The NCSC's advice for a compromised phone or tablet is blunt: they "can't usually be fixed by an antivirus product" and "the safest solution is to do a factory reset". Which?'s advice after a remote-access scam is a factory reset or an IT expert to confirm the device is safe to reuse, and Microsoft's is that if you have given scammers access to your device, consider resetting it. Nobody serious suggests deleting the app and hoping.

Why the erase works

The reset works because of encryption. On an iPhone, Erase All Content and Settings destroys the keys in a part of the chip built to be wiped, and Apple's deployment guide says this "renders all user data cryptographically inaccessible". Android has been encrypted by default since Android 10, and Google's compatibility rules require every factory reset to delete data to the NIST SP 800-88 standard. NIST calls the method cryptographic erase and puts it in its stronger "purge" tier, because recovery afterwards is infeasible even in a laboratory. A multi-pass "military grade" wipe is a hard-drive idea from another decade; on a phone it is the keys that matter.

Do it yourself, or have it done and documented

Have it done, checked and documented

This is the step to bring to us. Our security reset is what people are sent in for: we check the phone for a jailbreak or root, a management profile and signed-in accounts that are not yours, erase it with erasure software that holds an ADISA Product Claims Test certificate, meaning ADISA's research centre independently and forensically verified that nothing could be recovered after its wipe, reinstall the operating system from fresh (Apple's restore "reinstalls iOS and erases all your data") and hand you a report with the identifiers, the date and the result. It takes about an hour, any phone or tablet, £24, walk in at Haverhill or free tracked mail-in from anywhere in the UK. If you are coming from Newmarket, Cambridge, Bury St Edmunds, Sudbury or Saffron Walden, each has its own page with what to bring and how long it takes.

The report is the part a Settings erase cannot give you. When a bank has flagged your phone, a document that says it was erased, when and how, is worth more than your word that you pressed the button. If nobody needs proof and you are confident, Erase All Content and Settings on an iPhone, or Factory data reset on Android, runs the same cryptographic erase; our guide to wiping a phone walks through it.

4. Set it up as new, not from the backup

A single pristine black iPhone 15 standing upright on a pale grey surface with its screen dark, nothing else in frame

This is the step that undoes the other three if you get it wrong. The phone offers to restore from your most recent backup, and the most recent backup was taken while the scammer had access. The NCSC's guidance on malware from scam texts is explicit: do not back up before the reset, because "the backup will also contain the malware", and only restore a backup if you are confident it was created before the problem. Lloyds, Halifax and Bank of Scotland say the same to customers whose device their app has blocked: set the device up as a new clean install, do not restore from another device or backup, and do not reinstall optional apps during setup.

What comes back on its own

Setting up as new is less painful than it sounds, because the things you care about were never in the backup in the first place. They are in your account. Sign in and your contacts, your iCloud or Google Photos library and your synced passwords come back on their own. Then reinstall only the apps you recognise and use, one at a time, from the official store. If you would rather someone did that with you, we offer it as a separate Data Transfer service, £24, booked with the reset.

Once the phone is clean and signed in, reinstall your banking app and let it register the device afresh. If the bank's app flagged the phone before the reset, this is the point at which it should accept it again.

5. Expect the follow-up call

Scam victims are a list, and the list gets sold. In the weeks after, you may be called by someone who knows exactly what happened to you and offers to recover the money for an upfront fee, sometimes claiming to be from the police, the regulator or a law firm. The FCA calls these recovery room scams and its advice is short: if you are asked to pay a fee to get your money back, end all contact.

The same goes for a call from "the bank" asking you to ring back on the number on your card. Lloyds documents a version where the number is genuine but the line never cleared, so you dial straight back to the fraudster. Hang up, wait, use a different phone if you have one, and dial 159.

How to know if your phone is hacked at all

If you are reading this after a scam call, you already know. If you are reading it because the phone feels wrong, the signs below are in rough order of how much they mean. The famous one, a hot phone with a flat battery, is at the bottom on purpose.

Verification codes you did not ask for

Someone is trying to sign in to an account using your number. The code is doing its job; the password behind it is probably known.

A screen-sharing app you did not choose

AnyDesk, TeamViewer or a "support" app installed during a call. While it is open, the caller sees what you see.

A profile under VPN and Device Management

On an iPhone, Settings, General, VPN and Device Management. A profile you did not install can control settings and route traffic.

Settings that changed themselves

Call forwarding switched on, a new email forwarding rule, a recovery number you do not recognise, a device you have never owned signed in to your account.

Friends getting messages you did not send

Your messaging account or number is being used from somewhere else.

Battery, data or heat for no reason

Weak evidence on its own. A phone can run hot and flat for a dozen innocent reasons, and this is the sign every list leads with because it sounds the most dramatic.

On the codes that every video promises will reveal a hack: *#21# is a standard GSM network code that shows whether call forwarding is switched on for your number, defined in the 3GPP TS 22.030 specification alongside the rest of the star-hash codes. It tells you nothing about apps, profiles or passwords. It is still worth a dial, because forwarding set up to intercept your bank's verification calls shows up there, and *#002# cancels all forwarding. One check, not a verdict.

The bottom line

So, what to do if your phone is hacked: treat it as two problems wearing one coat. The accounts are fixed with passwords, two-step verification and a call to 159, from a device you trust. The phone is fixed with a full erase and a clean reinstall, which on anything modern destroys the encryption keys and leaves nothing behind. Do them in that order, save your passwords and check the backup before the erase, and set the phone up as new afterwards instead of restoring the backup from the week it went wrong.

If your bank has told you to get the phone reset, bring it to us. We check it, erase it with erasure software ADISA has independently and forensically verified, reinstall the operating system and give you the report to show the bank, in about an hour, £24. Walk into 3 Queen Street in Haverhill, or ask for a free tracked mail-in label from anywhere in the UK.

Hacked phone: your questions answered

What is the first thing to do when your phone is hacked?

Pick up a different device and change the passwords that matter most, starting with your email, because every other password reset lands there. Turn on two-step verification as you go. Then call your bank by dialling 159, which connects you to your own bank and cannot be faked. Do all of that before you touch the phone itself. The reset comes after the accounts, not before.

My bank told me to reset my phone. What do they actually mean?

A full erase and a clean reinstall of the operating system, so nothing a caller installed or changed is left on the device. Lloyds, Halifax and Bank of Scotland tell customers whose device their app has flagged as unsafe to restore it to factory settings and set it up as a new clean install without restoring a backup. You can do the erase yourself from Settings, or have it done with certified erasure software and a report to show the bank.

Does a factory reset remove a hacker or a virus?

From the phone, yes. On a modern iPhone or Android the reset destroys the keys that encrypt the storage, so everything on it, named or not, is gone, and the operating system goes back on clean. What it cannot do is reach your accounts. If someone knows your email or banking password, or has set up forwarding on your number with the network, a reset changes nothing about that. The phone and the accounts are two separate jobs.

Can a hacker see everything on your phone?

During a screen-sharing session, they see what is on your screen and can watch you type. That is why the "safe account" scam works: the caller watches the balance and the transfer. A management profile or a malicious app can go further and read what the phone does in the background. Once the app is uninstalled, the profile removed or the phone erased, that access ends. Access to your accounts from their own device is the part that outlives the phone, which is why the passwords change first.

Does dialling *#21# tell you if your phone is hacked?

No. It is a standard network code that shows whether call forwarding is switched on for your number, and nothing else. It will not show spyware, a remote-access app or a stolen password. It is still worth dialling, because a scammer who set up forwarding to catch your bank verification calls will show up there, and *#002# switches all forwarding off. Treat it as one check, not a verdict.

Will I lose my photos and contacts if I reset my phone?

Anything on the phone is erased, so before you come in, save all your passwords and check the backup. Anything already in your Apple or Google account comes back when you sign in: photos in iCloud or Google Photos, contacts, and passwords saved to iCloud Keychain or Google Password Manager. Things that were never synced, such as authenticator app codes and notes kept only on the device, do not, so write those down too. Take a full iCloud or Google backup as a safety net, then set the phone up as new rather than restoring the backup taken while the scammer had access.

Told to get your phone reset? Bring it to us.

Save your passwords, then bring the phone. We check it, erase it with ADISA-verified erasure software, reinstall the operating system and give you the report for the bank, in about an hour, £24. Walk in at 3 Queen Street, Haverhill, or ask for a free tracked mail-in label.