Rapid battery drain, a hot phone, strange sounds during calls, or an unfamiliar number in call-forwarding settings are often taken as proof of tapping. In reality, none of these signs alone confirms surveillance.
“Phone tapping” can cover threats of very different kinds: spyware on the smartphone, a stolen messenger account, call forwarding, unauthorised access to cloud storage, or a physical bug installed in a room.
Each scenario needs a different verification approach. A code, mobile app, or antivirus cannot detect every possible leak channel at once. Below we separate real risks from popular myths and explain when a professional check is warranted.
What “phone tapping” actually means
Before you start checking, determine which leak scenario is plausible. That decides what to investigate: the smartphone, the mobile number, accounts, or the physical environment around the person.
1 Spyware. Malicious or secretly installed software may gain access to the microphone, camera, location, messages, files, and call logs. An attacker may install it via physical access to the phone, a phishing link, a malicious file, or an operating-system vulnerability.
2 Account compromise. Sometimes the phone itself is technically intact, but a third party obtains access to an Apple Account, Google Account, Telegram, WhatsApp, email, or a cloud backup. They can then read synchronised data or view information from another device.
3 Call forwarding. Forwarding is a standard mobile-network feature. It may route calls to voicemail or another number when the subscriber is busy, unreachable, or out of coverage. Forwarding alone does not prove tapping, but its settings should be checked if the user did not enable the feature.
4 Intercepting conversations in a room. A confidential conversation may be recorded not through the phone, but with a hidden microphone, recorder, camera, or other covert device. In that case, checking the smartphone will not find the leak source — a TSCM survey of the premises or vehicle is required.
5 Unauthorised access to the device itself. Someone who knows the unlock code may read chats, view photos, add fingerprints, change security settings, or authorise other devices. Technically this is not always “tapping”, but the confidentiality impact can be the same.
Important: end-to-end encryption in a messenger protects data in transit, but it will not help if an attacker already controls the smartphone or account, or is recording the conversation directly in the room.
Get a consultation
A quick case assessment — no obligation
Signs of phone tapping: what should genuinely raise concern
Most popular “tapping signs” have dozens of ordinary explanations. Battery drain, for example, may come from wear, poor signal, system updates, or active background apps. Assess a pattern of events, not a single symptom.
1 An unknown app with critical permissions. Programs granted microphone, camera, location, contacts, SMS, or accessibility access without a clear reason deserve close attention. The app name and icon may conceal its real purpose.
2 Unexpected microphone or camera activity. Modern iOS and Android versions show a system indicator when an app uses the microphone or camera. If the indicator appears without an obvious reason, identify which app obtained access.
3 Third-party devices in your accounts. An unknown messenger session, a new device in Google Account or Apple Account, a sign-in alert from an unfamiliar location, or an unexpected security-setting change are stronger indicators than noise or echo on a call.

4 Unexplained mobile data use. Significant data transfer by an app you barely use may warrant further review. Traffic growth alone does not prove surveillance: backups, automatic updates, or photo sync can be the cause.
5 Changes in system settings. Unknown VPN configurations, device-management profiles, certificates, device administrators, accessibility services, or permission to install apps from unknown sources that the user did not set up can be suspicious.
6 Alerts about a SIM change or loss of service. A sudden stop of mobile service together with SIM-change messages, password resets, or account sign-ins may indicate a number takeover. Contact the operator immediately from another device.
7 Leaks of information known only to a limited circle. If an outsider systematically knows private conversation content, travel routes, meeting plans, or chat details, a comprehensive check may be justified. Establish where the leak exists: phone, account, premises, or people with legitimate access.
The *#21# myth. This and similar service codes may show the status of certain forwarding types, but they do not detect spyware, a covert device, operator-level interception, or messenger access. Results also depend on the mobile operator, network, and phone model.
Strange sounds on a call, a hot handset, reboots, or rapid battery drain are worth investigating, but they are not standalone proof of tapping. Unknown permissions, third-party sessions, configuration changes, and actual leaks of closed information matter far more.
Learn more
We’ll outline the next steps for your case
How to check your phone and when you need professional help
Work through the check in sequence, based on the likely compromise path. If the situation may have legal consequences, do not rush to delete apps, factory-reset the phone, or destroy suspicious files — you may erase digital evidence along with the threat.
1 Review app permissions. On iPhone, check app access to the microphone, camera, location, Bluetooth, and local network in Privacy settings. On Android, use the privacy dashboard and permission manager to see which apps recently accessed sensitive functions.
2 Check installed apps and system configurations. Identify unfamiliar apps, VPNs, management profiles, device administrators, and accessibility services. Do not remove system components merely because of an unfamiliar name — identify their origin first.
3 End third-party sessions. Review active devices in Apple Account, Google Account, Telegram, WhatsApp, email, and other critical services. If an unknown session appears, document it, revoke access, and change the password from a known-safe device.
4 Secure primary accounts. Use unique passwords, two-factor authentication, or passkeys. Check recovery email addresses, recovery numbers, email forwarding rules, and apps granted account access.
5 Update the operating system and apps. Updates close known vulnerabilities and strengthen system protections. An updated phone is not automatically safe, however, if compromise indicators already exist or an attacker still has account access.
6 Contact your mobile operator. The operator can help verify forwarding settings, SIM status, and unauthorised changes in the subscriber account. The operator does not analyse apps, perform smartphone digital forensics, or search for bugs in a room.
7 Arrange a professional check. Where attorney–client privilege, commercial negotiations, a partner dispute, stalking, or targeted surveillance are involved, reviewing settings alone is not enough. A technical smartphone examination, account analysis, and a TSCM sweep of the premises or vehicle may be required.

Treat the phone and the premises as one information environment. Even a fully secured smartphone will not help if a hidden microphone is recording the conversation. Conversely, a TSCM sweep of an office will not remove spyware or a third-party messenger session.
Submit a request
Confidential reply as soon as possible
Conclusion

Checking a phone for tapping should not stop at a service code, antivirus, or a search for popular “signs”. Identify the possible leak channel, analyse permissions and system settings, review accounts, and assess the physical environment where confidential conversations take place.
ProDefence helps determine which check format your situation needs: a smartphone and account audit, a professional TSCM survey of the premises, or a combined review of all potential leak channels.
We do not draw conclusions from battery drain alone, and we do not create a false sense of security after a single-detector check. Work is confidential, aligned with the threat model, technical limits, and the need to preserve possible digital evidence.
Phone check and TSCM
Suspect tapping or a leak of confidential information?
Describe what raised concern: an unfamiliar session, a third-party app, leaked negotiation content, or unexplained smartphone activity. ProDefence specialists will assess the situation and propose a justified check format.
Checks of smartphones, accounts, premises, and vehicles.
