Is the phone being spied on? How to verify — and how to prove it
The suspicion of being watched through one’s own phone is among the most frequent reasons people seek a forensic examiner — and one where the internet gives the worst advice. Three planes are best kept apart: the signs, which almost never prove anything; the verification, which is precise work; and the evidence, which has rules of its own and is easily destroyed.
The signs: what counts and what does not
The canonical list — battery drain, a warm device, unusual data traffic, noises on calls — is close to useless: each symptom has ten innocent explanations for every sinister one, starting with a system update or an ageing battery. Building a suspicion on that foundation mostly produces anxiety.
Specific, checkable facts deserve attention instead: a login alert on your account from a device you do not recognise; active sessions you never opened; a management profile — of the kind companies use to administer staff phones — present on a personal device; applications holding deep privileges, such as accessibility or device administration, installed on dates that coincide with suspicious moments; the warnings operating systems and some platforms now issue when they recognise known surveillance software. And one criterion external to the technology: someone shows knowledge of things they could only know from the phone. In practice it is often the most reliable sign of all.
How surveillance actually happens
The domestic surveillance market — so-called stalkerware — does not use intelligence-agency techniques. It uses physical access: a few minutes with an unlocked phone are enough to install an application that hides itself and reports back. Or it uses credentials: whoever knows the password to a partner’s cloud account has no need to touch the phone, since backups, locations, photos and sometimes messages can be read comfortably from a browser. A substantial share of “spied phones” is exactly this: an account shared too long, or a password the other person knows.
That distinction — compromised device or accessed account — changes the examination, the evidence, even the remedy. Establishing which it is comes first in any serious check.
What the examination consists of
A technical verification is not “running an antivirus”. It starts by fixing the device’s state with an acquisition, so the work proceeds on a copy; then it examines, methodically, the layers where surveillance leaves traces: installed applications and their packages, configuration profiles, permissions and their history, processes and services, the system’s diagnostic logs, and the device’s network behaviour observed under controlled conditions. Many commercial surveillance products are catalogued and recognisable; beyond those, the work proceeds by anomaly and exclusion.
Two honest caveats. First: not everything on a modern phone can be inspected from outside, so “no traces found” does not equal “no surveillance ever existed” — a serious examination states its limits. Second: the check must precede any clean-up, because every factory reset returns the device to its original state and erases, along with the spyware, every possibility of proving it existed.
From discovery to evidence
Finding is not enough: you must be able to prove. Installing surveillance software on another person’s phone can amount, depending on the facts, to serious offences under Italian law — from unauthorised access to a computer system to unlawful interception — and the examination’s findings can support a criminal complaint or a civil claim. But the rules of all digital evidence apply: what was found must be tied to the device through a documented acquisition, records of operations and integrity checks, on the method described in forensic imaging and hashing. A hurried screenshot of the suspicious app, taken just before resetting the phone, is little more than a memory.
Context matters too: installation dates set against who had access to the device, whether credentials were changed, account logins from attributable addresses. That reconstruction is what turns a technical artefact into a fact that can be pleaded.
Remediation, at the right moment
The correct order of operations
- Document first: acquisition of the device’s state, an inventory of what is installed, a record of operations.
- Then secure: change passwords from a different, safe device; review active sessions and linked devices on every account; enable two-factor authentication.
- Remediate last: full reset, manual reinstallation of only what is needed — without restoring the full backup that might bring the problem back aboard.
A final, non-technical note. Where the suspicion arises inside a difficult relationship, personal safety comes before evidence: in serious cases there are support centres and professionals to turn to, and strategy — including the technical part — should be coordinated with counsel before making moves that alert the person watching.