How to Detect Spyware on Your iPhone (2026 Checklist)

·
8 min read

Switching to Mac is reader-supported. We may earn a commission when you buy through links on our site. Learn more.

Your battery’s been draining faster than it should. Your data bill jumped. Maybe you got a strange alert you can’t place. You’re hoping it’s nothing, but fingers crossed isn’t a security strategy.

This guide walks you through every layer of a modern iPhone security check: surface warning signs, hidden configuration profiles, compromised Apple ID access, and what to do if Apple has already flagged your device as a target.

Image of words "How to Detect iPhone spyware"

How Spyware Gets on an iPhone

iPhones are relatively hard to compromise. That doesn’t mean immune. The main ways monitoring ends up on a personal device are configuration profiles, Apple ID compromise, and, in rare cases, targeted mercenary spyware.

Configuration profiles and MDM. Mobile Device Management is a legitimate tool for work phones, employers use it to configure email, enforce security policies, and manage apps. On a personal iPhone, a profile you didn’t install can give someone else real control: filtering your traffic, installing apps, logging device activity. This is one of the most common methods for monitoring a personal iPhone without the owner knowing.

Apple ID compromise. If someone has your Apple ID credentials, they don’t need physical access to your phone. Everything synced to iCloud, texts, call history, photos, is accessible remotely. Account-level compromise often goes unnoticed because the phone itself seems fine.

Targeted mercenary spyware. Tools like Pegasus are deployed against journalists, activists, and executives. Apple sends direct alerts when it suspects a device has been targeted this way. Attacks like this against ordinary iPhone users are uncommon, but they’re real, and Apple has built dedicated notifications around them.

Cartoon image of a tiny spy next to a hand holding an iPhone

Step 1: Spot the Warning Signs

No single symptom below confirms spyware on its own. Two or three at once is enough reason to work through the rest of this checklist.

  • Battery drains much faster than normal, or the phone runs hot while idle
  • Mobile data spikes, a jump in gigabytes you can’t explain
  • Unfamiliar apps on your Home Screen or App Library with generic names like “System Service” or “Device Health,” or apps with blank icons
  • Messages or emails sent from your account that you didn’t write
  • Pop-ups or redirects inside apps that don’t normally show ads
  • Two-factor authentication codes arriving when you didn’t try to sign in anywhere

A hot phone might be a buggy app. A strange SMS could be spam. If several are happening at once, keep going.

A figure in a hoodie typing on an iPhone

Step 2: Check for Configuration Profiles and MDM

This is the most commonly skipped check, and often the most revealing.

  1. Open Settings > General > VPN & Device Management.
  2. Look under Configuration Profiles and Mobile Device Management.
  3. On a personal iPhone, you should see nothing here, or only profiles from an employer or school you knowingly enrolled with.
  4. If something unfamiliar appears, tap it to see what it controls: web content filters, app installs, device monitoring.
  5. To remove it, tap Remove Profile or Delete Profile.
iOS Settings > General > VPN & Device Management showing an unrecognized configuration profile listed, with the profile entry highlighted

If the profile is password-protected and you didn’t set that password, standard removal won’t work. Skip to the nuclear option at the end of this guide.

Step 3: Review Your Apple ID and Connected Devices

A compromised Apple ID is often more dangerous than spyware on the device itself.

  1. Open Settings and tap your name at the top.
  2. Scroll down to see every device signed into your Apple ID.
  3. Tap any device you don’t recognize and tap Remove from Account.
  4. On the main Apple ID screen, open Sign-In & Security and verify that the trusted phone numbers for two-factor authentication are only yours.
iOS Settings > Apple ID page with the list of signed-in devices visible, with an unrecognized device selected showing the Remove from Account option

If two-factor codes are showing up when you didn’t initiate a sign-in anywhere, someone is actively trying to access your account. Change your Apple ID password immediately, from a different device if you can.

Step 4: Check Battery and Data Usage Per App

Spyware running in the background has to show up somewhere in your usage stats.

  1. Open Settings > Battery.
  2. Tap Last 10 Days and review the Battery Usage by App list.
  3. Look for apps you don’t recognize, or system processes with heavy background activity you can’t explain.
iOS Settings > Battery > Battery Usage by App in the Last 10 Days view, with an unrecognized app near the top of the list showing high background usage
  1. Open Settings > Cellular (labeled Mobile Data in some regions).
  2. Scroll through the app list and look at data usage per app.
  3. An app you don’t recognize using large amounts of data, or something mundane like a calculator using any cellular data at all, warrants a closer look.

Step 5: Audit Your Privacy Permissions

Spyware needs sensor access to be useful. Camera, microphone, and location are the main targets.

  1. Open Settings > Privacy & Security.
  2. Tap Location Services, Microphone, and Camera in turn.
  3. Look for apps you don’t recognize, or apps with access they have no reason to have.
  4. An app with Always location access that isn’t a navigation tool you deliberately configured is worth questioning.
  5. Remove permissions from anything suspicious, or delete the app entirely.
iOS Settings > Privacy & Security > Location Services showing a list of apps with their location access levels, with an unfamiliar app set to Always highlighted

Also watch the real-time indicators. iOS shows a green dot when the camera is active and an orange dot when the microphone is in use. If either appears when you’re not on a call and haven’t opened a media app, swipe down to open Control Center, it shows which app last accessed the sensor.

Step 6: Look for Jailbreak Indicators

Some spyware requires a jailbroken device to install. Look for apps named Cydia or Sileo, both are jailbreak app managers with no business being on a standard iPhone.

If you find either and didn’t intentionally jailbreak your device, go straight to the erase step. There’s no reliable cleanup path from an unauthorized jailbreak.

Step 7: Use Safety Check

Safety Check is designed for situations where someone with physical access to your phone may have set up monitoring, a controlling partner, a suspicious employer, anyone who shouldn’t have that level of access.

  1. Open Settings > Privacy & Security > Safety Check.
  2. Choose Emergency Reset to immediately stop all location sharing, reset all privacy permissions, and sign out of iCloud on other devices.
  3. Or choose Manage Sharing & Access to step through each person, app, and service with access to your data and cut off individual connections.
iOS Settings > Privacy & Security > Safety Check showing both the Emergency Reset and Manage Sharing & Access options

Emergency Reset is fast. Manage Sharing & Access is more precise. Use whichever fits the urgency.

Step 8: Update iOS

Some spyware exploits in-memory vulnerabilities that a reboot can clear. Others rely on security holes Apple has already patched.

  1. Hard reboot first: press Volume Up, then Volume Down, then hold the Side button until the Apple logo appears.
  2. Open Settings > General > Software Update and install whatever’s available.
iOS Settings > General > Software Update showing a pending iOS update with the Update Now button highlighted

Staying current closes known holes. It’s not a guarantee, targeted spyware often exploits zero-days, but skipping updates creates unnecessary exposure.

Step 9: Run a Desktop Spyware Analyzer

On-device antivirus apps for iPhone can’t scan the full system, iOS sandboxing prevents it, and most of what’s listed under that label in the App Store is security theater. Computer-based backup scans are a more reliable approach.

Tools like Certo iPhone and iMazing’s Spyware Analyzer connect to your iPhone from a Mac or Windows computer, analyze the backup for known spyware indicators, rogue profiles, and anomalies, and produce a readable report. Neither catches custom spyware frameworks, but for most situations they add a useful second layer of verification.

On a Mac, the connection runs through Finder. On Windows, you’ll need iTunes or the Apple Devices app installed before running the scanner.

Step 10: If You Receive an Apple Threat Notification

Apple sends alerts, by email, on the Lock Screen, and inside Settings, when it believes a device has been targeted by mercenary or state-sponsored spyware. These are based on Apple’s own threat intelligence. False positives are rare.

If you get one:

  • Follow the steps Apple specifies in the notification. They typically involve updating iOS, strengthening your password, and confirming two-factor authentication is active.
  • Check for any official notices directly inside Settings under your Apple ID name, rather than clicking links in an email.
  • If your profession or situation makes you a plausible surveillance target, journalism, legal advocacy, activism, contact a security professional rather than handling it alone.

The Nuclear Option: Erase and Start Fresh

Found a jailbreak you didn’t put there? A profile you can’t remove? Worked through every step above and still can’t account for something suspicious? Erase the device.

  1. Back up to iCloud or to your Mac or Windows computer first.
  2. Go to Settings > General > Transfer or Reset iPhone > Erase All Content and Settings.
  3. Set up as a new iPhone. Restore your contacts and photos, but be selective about which apps you reinstall, and skip any configuration profiles you can’t identify.

Treat the backup with care. Restoring a backup that contains a rogue profile means picking up right where the compromise left off.

When to Contact Apple Support

Reach out to Apple Support if:

  • You received a genuine Apple threat notification and want guidance on what to do next
  • You found an MDM profile or configuration you can’t remove
  • Someone changed your Apple ID recovery options and you’ve lost account access

For targeted surveillance situations, a digital forensics professional will be more useful than a general support call. Getting through this checklist without finding anything alarming is the best possible result, and if that’s where you land, the effort was worth it.