BLOG

How to Tell If Your Cell Phone Is Tapped

Worried that someone is listening in? Your phone holds your messages, photos, banking, and location, so the fear of it being tapped is real. The good news: there are quick checks you can run yourself and clear warning signs to watch for. This guide covers the dial codes that reveal call forwarding, the symptoms of a compromised phone on iPhone and Android, and the steps to lock everything down.

One important thing up front: the popular “secret codes” do not detect spyware or prove your phone is tapped. They only reveal call-forwarding settings. We’ll show you what they actually tell you, what they don’t, and the signs that matter more.

Quick Codes to Check Call Forwarding

These MMI/USSD codes reveal whether your calls or texts are being diverted — something an attacker could abuse — but they will not show spyware or confirm surveillance. Use them as a fast first check, not as evidence. Dial the code as if making a call:

CodeWhat it actually shows
*#21#Shows whether call forwarding / diversion is active on your line
*#62#Shows the number your calls go to when your phone is unreachable
*#67#Shows call forwarding when your line is busy
*#61#Shows call forwarding when you don’t answer
##002#Turns off all call forwarding
*#06#Displays your IMEI – save it to report loss or theft

These codes work on most GSM networks for both Android and iPhone, though some carriers limit them. On Android, you can also open a hidden diagnostics menu by dialing *#*#4636#*#* to review usage and radio information.

Warning Signs Your Phone May Be Compromised

Because the codes only cover call forwarding, symptoms matter more. Watch for:

  • Battery draining quickly without heavy use
  • The phone running warm while idle
  • Unexpected spikes in data usage
  • Apps you don’t recognize, or familiar apps crashing often
  • The screen lighting up or the device restarting on its own

Any one of these can have an innocent explanation, so treat them as prompts to investigate rather than proof of surveillance. The reason attackers go after phones at all is simple: they hold everything valuable in one place and are often the least-protected device we own, which is exactly why mobile security is so often the path of least resistance for attackers. The specific clues differ a little by platform:

On iPhone

  • Unexpected battery drain and heating while idle
  • Data spikes and random app crashes
  • Unusual behavior from Siri or unfamiliar configuration profiles under Settings

On Android

  • System apps crashing frequently
  • Background apps using large amounts of data
  • Unrecognized apps requesting sensitive permissions

Can Spyware Hide With No Obvious Signs?

Yes. Many people assume a tapped phone always shows obvious symptoms, but modern spyware can run quietly in the background while collecting messages, credentials, location, or account data — deliberately avoiding anything that would tip off the user. That’s why prevention beats detection: keep your software updated, use strong passwords and multi-factor authentication, review your app permissions regularly, and remove apps you no longer need. Reviewing which apps can reach your microphone, camera, and location is especially worthwhile, since those are the permissions surveillance tools abuse most. Building these habits into a simple monthly routine does more to keep you safe than any single dial code, and it’s the heart of our guide to protecting your mobile devices, which walks through the settings worth locking down.

Can You Tell If You’re Being Tapped by Law Enforcement?

Honestly, not from your handset. Lawful interception happens at the carrier level and is designed to be invisible on the device — the old “clicks and static” myths come from analog phone lines and aren’t reliable indicators on today’s digital networks. There is no code that reveals it. If this is a genuine legal concern, speak with a lawyer rather than relying on a dial code.

How to Protect Your Phone and Shut Down a Tap

If you suspect your phone is compromised, work through these steps in order:

  1. Update your OS and apps. Security patches close the holes spyware relies on.
  2. Run a reputable mobile security scan. Use a trusted antivirus/anti-malware app to check for spyware.
  3. Review app permissions. Delete anything you don’t recognize or no longer use.
  4. Change your key passwords. Start with your Apple ID or Google account, then your email and social apps, and turn on two-factor authentication.
  5. Avoid suspicious links and sideloaded downloads. They’re the #1 way spyware gets installed.
  6. Factory reset if problems persist. Back up first, reset, then change your passwords again afterward.

Work through them in order, and don’t stop at the first fix — a determined intruder often leaves more than one way back in. If you’d like a full step-by-step walkthrough of cleaning a compromised device from start to finish, follow our companion guide, How Do I Unhack My Phone?, which covers the process in detail.

When a Tapped Phone Becomes a Business Problem

Most of the time, a tapped personal phone is a personal problem. But if the device is also used for work, the stakes are higher. A single compromised handset that reads a company email, holds saved logins, or connects to internal apps can hand an attacker a foothold into the whole organization. This is the reality behind bring-your-own-device policies: the security of your business now depends partly on the personal phones your team carries.

It only takes one unpatched phone or one reused password for that foothold to open, and the smaller the team, the more a single incident hurts. Attackers know this, which is why small and mid-sized businesses are increasingly probed through the phones employees carry rather than through hardened company servers. For companies, the answer isn’t to dial a code; it’s to put monitoring, device management, and expert oversight in place so a compromised phone is caught and contained quickly. That’s the role that managed security services play for organizations that can’t watch every device themselves.

The Bottom Line

If you’re asking “is my phone tapped?”, start with the call-forwarding codes to rule out diversion, then watch for the warning signs above and act on the protection steps. The codes are a quick check — but updates, strong passwords, and careful app habits are what actually keep intruders out. Most people who work through this list find an innocent explanation, and the few who don’t will have caught the problem early, which is the entire point. Your phone is your personal gateway; treat it like your front door, and don’t leave it unlocked. The habits in this guide take only a few minutes a month, yet they close the doors that opportunistic attackers rely on finding open. And if the worst happens and a real compromise spreads beyond a single device, having a plan already in place matters more than any code, which is why every organization should line up incident response support before they ever need it.

Frequently Asked Questions

What are common signs my phone is tapped?

Background noise is an unreliable indicator on modern digital networks. Better signs are rapid battery drain, unexpected data spikes, apps you didn’t install, and the device restarting or lighting up on its own.

Do codes like *#21# or ##002# prove my phone is tapped?

No. These codes only reveal call-forwarding and diversion settings. They’re useful for ruling out one type of interference, but they don’t detect spyware or confirm tapping. Treat them as a quick diagnostic, not proof.

How do I check if call forwarding was turned on without my knowledge?

Dial *#21# to see whether call forwarding is active, and ##002# to switch all forwarding off. If you find forwarding you didn’t set up, disable it and contact your carrier.

What should I do first if I think my phone is tapped?

Update your OS and apps, review and remove unfamiliar apps, run a reputable mobile security scan, change your key passwords, and enable two-factor authentication. If problems persist, back up your data and do a factory reset.

Can someone tap my phone without installing an app?

It’s possible through OS or app vulnerabilities, but most real-world compromises still rely on malicious apps, phishing links, or stolen credentials. Keeping software up to date sharply reduces the risk.

Does a factory reset remove spyware?

A factory reset removes most malicious software, but change your passwords and review account security afterward, since your credentials may already be exposed.settings, but they do not conclusively prove a phone is tapped. They should be treated as diagnostic tools rather than definitive evidence of surveillance.

Leave the first comment