TL;DR
- Your phone holds more sensitive material than your laptop now: photos, banking apps, email, message history, ID documents, two-factor codes. Lose the phone, and you lose access to almost everything else.
- Two settings stop almost every common attack: a strong screen lock you actually use (six-digit PIN minimum, not biometrics alone), and automatic security updates turned on.
- The biggest 2026 risks aren't viruses. They are physical theft with the phone unlocked, SIM-swap, malicious apps from outside the official store, and consent prompts you tapped through without reading.
- iPhones and Androids are both fine if updated. Use the official app store, decline permissions that don't fit the app's purpose, and don't sideload unless you really know why.
- Set up Find My or Device Manager before you lose the phone. Practise the remote-wipe steps once when nothing's wrong.
What it is
A smartphone is a personal computer with five sensors most laptops don't have — microphone, cameras, GPS, accelerometer, biometric scanner — and a constant network connection. Anything that can run on a laptop now runs on a phone. Anything that can be lost on a laptop can be lost from a phone — faster, because phones are pocket-sized and frequently unattended.
Three categories of risk:
- Physical compromise. The phone is stolen unlocked, or shoulder-surfed for the PIN before theft. The thief now has direct access to everything inside.
- Network and account compromise. SIM-swap, phishing apps that look like real banking apps, fake updates, malicious sideloaded apps. The phone stays in your hand; the attacker is elsewhere.
- Consent leakage. You install a flashlight app that wants access to your contacts, microphone, and location. You tap "Allow." For two years it sells where you are and what you say. No alarm, no theft, just slow drainage of your private life to advertisers and worse.
The defences are well-understood. The friction is finding twenty minutes to set them.
How to spot a problem
Signs your phone has been compromised:
- Battery drain that started suddenly without a software update or new heavy app.
- The phone is unusually warm when idle.
- Pop-ups or browser redirects that didn't happen before.
- New apps you didn't install, especially with vague names ("System Helper").
- Mobile-data usage spiking without you streaming anything.
- A "Mobile device admin" or "Profile" you didn't add — especially on Android. Check Settings → Device admin or Settings → General → VPN & Device Management on iPhone.
- Two-factor codes arriving for accounts you didn't try to log into.
- Friends asking why you sent them a strange link.
- Banking app showing a "new device registered" you didn't add.
- Loss of mobile service for no reason — could be SIM-swap in progress.
Signs you set something up wrong (not malicious, but exposed):
- Lock screen is "swipe" or four-digit PIN you can guess from oily smudges.
- Notifications show full message contents on the lock screen, including two-factor codes.
- iCloud or Google account is signed in everywhere and you haven't reviewed devices in a year.
- Apps with location permission you never use.
What to do
The one-sitting setup, in order:
- Update the operating system. Settings → Software Update → install. Reboot. If your phone hasn't received updates in over a year, it is too old to be safe; budget for a replacement.
- Set a strong screen lock. Six-digit PIN minimum, ideally an alphanumeric passphrase. Biometrics (fingerprint, face) are fine for convenience, but biometrics can be legally compelled in many jurisdictions while PINs sometimes cannot. Both is fine; the PIN must be strong.
- Set auto-lock to under a minute. Settings → Display → Auto-Lock (iOS) or the Lock Screen settings (Android).
- Hide message previews on the lock screen. A stolen phone showing your 2FA codes is worse than a stolen phone showing a black screen.
- Turn on Find My iPhone (iOS) or Find My Device (Android), including remote wipe. Then practise — make sure you can sign into the recovery website (icloud.com/find or google.com/android/find) from a different device.
- Set a SIM PIN. The PIN that protects the SIM card itself, distinct from the phone unlock. Without it, a thief can move your SIM to their phone instantly. Settings → Mobile / Cellular → SIM PIN.
- Set a port-out PIN with your carrier. A second PIN that protects your phone number from being transferred. Carrier websites or a phone call. Without it, a SIM-swap attack works.
- Turn on automatic OS updates and automatic app updates in the App Store or Play Store settings.
- Review installed apps; uninstall any you don't actually use. Reduces attack surface and recurring permissions.
- For each remaining app, review permissions. Settings → Privacy & Security. A flashlight does not need contacts. A calculator does not need microphone. Revoke broadly; the app will re-prompt if it really needs the permission.
- Sign into your primary account from a computer (icloud.com, google.com) and review every device showing. Remove ones you don't recognise or don't use anymore.
- Turn on 2FA on the primary account if it isn't already. Use an authenticator app, ideally with cloud sync — if you lose the phone, the authenticator app's cloud restore is what gets you back.
- Back up the phone — to iCloud or Google One automatically, and to a computer occasionally as a second copy.
When something is wrong:
You think the phone is compromised but you still have it.
- From a different device, change the password on your main account (Apple ID or Google) and turn on or reset 2FA.
- Sign out of every other device from that account.
- Look in Settings for any device administrators or profiles you don't recognise; remove them.
- Uninstall any app you don't remember installing.
- If anything still feels wrong, factory-reset the phone. Restore from the most recent backup made before whenever the problem started; if you can't be sure, restore as new and reinstall only what you actually use.
The phone has been lost or stolen.
- From any other device, go to icloud.com/find (iOS) or google.com/android/find (Android). Mark the device as lost; trigger a remote wipe if appropriate.
- Call your carrier to report the SIM lost and request a SIM swap to a new card for you, not the thief — confirm your identity with the port-out PIN you set earlier.
- Sign out of every other device on your account from a computer.
- Change passwords on email and bank.
- File a police report; many countries require it for insurance claims, and the IMEI report can sometimes lead to recovery.
SIM-swap in progress (signal disappears unexplained).
- Call your carrier from a different phone immediately.
- Call your bank's fraud line.
- Move any SMS-based 2FA to an authenticator app the moment you regain control. SMS is worse than an app — it is the attack surface for SIM-swap — but still far better than nothing, so keep it on any account that offers no app option.
What NOT to do
- Don't sideload apps from random websites. "Modded" versions of paid apps are how most consumer-Android malware spreads.
- Don't use public USB charging in airports or hotels without a data-blocker. "Juice jacking" is rare but real; a $5 USB data-blocker is cheap insurance, or just use a wall charger.
- Don't tap-through permission prompts. Pause; ask why the app needs this. Decline if unsure — you can re-grant later.
- Don't reuse the screen-lock PIN as a banking PIN. Different secrets.
- Don't share your full Apple ID or Google account with family. Use Family Sharing instead; each person keeps their own account with the shared benefits.
- Don't trust antivirus apps from no-name companies. Many are themselves data-harvesters. The OS's own security is the primary defence; reputable AV (Bitdefender, ESET, Sophos) adds a layer on Android, less needed on iOS.
- Don't keep the phone unlocked in your hand in public. A thief who runs past with an unlocked phone has minutes of full access before the lock kicks back in.
Use AI to help you
Audit your current setup:
"I have a [iPhone model / Android make and model] running [iOS version / Android version]. Below is the list of installed apps and the permissions I've granted to each (you can ask me to add detail). Please audit my setup and tell me: (a) the three highest-risk apps or permissions to revoke, (b) the three settings I've probably not enabled but should, (c) one thing I'm doing right that I shouldn't change, and (d) what to back up before any further changes."
Plan recovery from a lost phone:
"My phone was just lost or stolen. It's a [iPhone / Android] running [version]. I have access to [list — laptop, partner's phone, work computer]. Walk me through the next 60 minutes step by step: what to mark as lost, what to remote-wipe, which accounts to secure first, what to tell my carrier, and what police-reporting steps matter for insurance and for protecting people who might be contacted by the thief using my identity."
A reminder: AI doesn't know the specific menus on the current version of your operating system, and Android menus vary by manufacturer. Use the AI to plan; verify each step against the device's own settings or the manufacturer's support page.
Who to call
The order: carrier for SIM and number protection, the platform (Apple or Google) for account recovery, bank if money is moving or cards are stored, police for theft and serious fraud.
Find the latest contacts for your country with AI:
"I'm in [your country] and I use [iPhone / Android]. List the official channels for smartphone security incidents — my carrier's fraud / lost-phone hotline (provide the major carriers in this country), Apple Support or Google Account recovery, the national cybercrime reporting body, the data-protection authority for spyware or unauthorised tracking, and the local police's mobile-theft register if one exists. For each, give the official website and public phone number. Tell me which to call first depending on whether (a) the phone is stolen and powered on, (b) the SIM has been swapped, (c) spyware has been installed, or (d) banking credentials are at risk. Cite each source. Flag anything that might be outdated."
A short curated list:
- Apple Support — apple.com/support; report device as lost via icloud.com/find.
- Google Account Recovery — accounts.google.com/signin/recovery; lost-device wipe via google.com/android/find.
- English: UK — Action Fraud; NCSC (ncsc.gov.uk). US — FBI IC3; FCC for telecom complaints. Canada — Canadian Anti-Fraud Centre. Australia — Scamwatch.
- German: Germany — Polizei online; BSI für Bürger. Austria — Watchlist Internet. Switzerland — NCSC (ncsc.admin.ch).
- French: France — Cybermalveillance.gouv.fr. Belgium — safeonweb.be.
- Italian: Italy — Polizia Postale.
- Spanish: Spain — INCIBE (017); Mexico — Policía Cibernética.
- Portuguese: Portugal — CNCS / 1407; Brazil — CERT.br.
- Polish: Poland — CERT Polska (cert.pl).
When to escalate beyond chat
- Phone is gone and banking is at active risk — bank's fraud line first, then carrier, then the device-finding website. In that order.
- You suspect spyware — especially from a former partner or an abusive household member. This is stalkerware territory; the device may need a full reset, and the personal-safety dimension may need a domestic-abuse helpline before any technical step.
- Your child's phone was compromised and they've received concerning messages — the technical recovery is one track; the conversation about what was sent or shared is the more important one. See the Child Online Safety article.
- Work phone with sensitive data — tell IT immediately. There may be remote-wipe and incident-report obligations.
Sources & further reading
- Apple Platform Security Guide — annual, public
- Google Android Security white paper — annual, public
- NIST SP 800-124 — Mobile Device Security guidelines
- EFF Surveillance Self-Defense — Smartphone section
- Citizen Lab — published research on mobile spyware