I will not remotely inspect a personal phone, identify who may be accessing it, remove an unknown administrator, recover deleted data, or provide individual forensic support. While I appreciate this may be a stressful and urgent situation for you or a person you represent, I do not make exceptions. Please follow the steps below.
Do not send me screenshots, videos, logs, IMEIs, telephone numbers, passwords, or account recovery codes. Direct your evidence to local authorities.
Do not pay strangers who claim they can identify an attacker from screenshots, an IP address, an IMEI or a list of Android system apps. Do not install remote-support software for them and never share passwords or verification codes. Malicious actors can and will take advantage, further complicating your predicament.
Do not assume that because another person appears to know something from the phone, they have access to the phone itself. They may instead have access to an online account, a synchronised browser, photo sharing, a linked messaging session, the mobile account or SIM, call forwarding, location sharing, a backup account, or another device on which the account remains signed in.
The presence of Android Enterprise, Android Device Policy, Google Workspace, Knox, a work profile, certificates, system applications, developer terminology, “viewer”, “beta”, “heartbeat”, system/priv-app, or a large number of installed apps does not prove someone has taken over a device.
A telephone number, IP address, IMEI or serial number alone does not give someone remote control of an Android device.
If you remain concerned unauthorised access has happened or is happening, follow the relevant checks below. Nothing here replaces any need to contact the appropriate authorities.
If a partner, ex-partner or someone with physical access may be monitoring you, use a different trusted device to seek help. Removing access or changing settings can alert an abuser. In the UK, Refuge's Tech Safety service provides specialist guidance; call 999 if anyone is in immediate danger.
Before resetting or deleting anything:
If the phone is lost, stolen or no longer under your physical control, use Google's Find Hub from a trusted device to locate it, mark it as lost or erase it. Erasing is permanent and prevents further location through Find Hub, so preserve what you need first where possible.
Do not factory-reset the phone until the data and evidence you need are safely copied.
Open Settings and use its search box for the checks below. Android manufacturers use different menu layouts, so searching is more reliable than following one fixed path.
A work profile is identified by a briefcase badge on work apps and normally a Work tab in the app drawer and under Settings → Passwords and accounts.
On a personally owned phone, the organisation manages the work profile, not personal photos, personal messages or personal app data. Remove it with:
Settings → Passwords and accounts → Work → Remove work profile
Confirm the deletion, then uninstall the associated policy app if it remains. This deletes work-profile data only. A factory reset is not required. See Introduction to work profile for the privacy boundaries.
Google Family Link supervision can let a parent see a phone's location, approve or block apps, set time limits and remotely lock the device. Those controls can feel like a takeover, but Family Link cannot remotely read the screen, emails or messages, listen to calls, or choose a new screen-lock password.
Search Settings for Parental controls and check Settings → Digital Wellbeing and parental controls or Settings → Google → All services → Kids and family → Parental controls. Also look for a notice that the Google Account is supervised.
Use Google's Family Link supervision guide to stop supervision. A person under 18 needs a parent's approval, and both people are notified when supervision stops. Removing a supervised account removes its supervision settings from that phone; adding the same account again restores them. A factory reset does not turn a supervised account into an unsupervised account.
A personal work profile and a fully managed device are different.
Reset the device only after completing the other relevant sections. During setup, watch what happens before adding any Google Account:
Personally owned devices cannot be silently added to Android zero-touch by an ordinary individual who merely knows the IMEI or serial number. Devices are registered through authorised reseller and enterprise systems. See Are employee-owned devices eligible for zero-touch? for how this works.
Search Settings for and review:
Most apparent “phone takeovers” are account-access related rather than Android Enterprise management. Work from the main email account outward because control of email is commonly used to reset everything else.
Google's account-side Advanced Protection Program is an optional additional layer for people at elevated risk of targeted attacks. It uses passkeys or security keys for sign-in, applies extra checks and limits some third-party access. This is separate from Android's device-side Advanced Protection described later: enabling one does not mean the other is enabled.
Repeat the account-security process for email, social media, cloud storage, banking, mobile-carrier and manufacturer accounts. Do not assume that securing the Google Account signs other services out.
If messages, links or requests for money may have been sent from a compromised account, warn contacts through a different trusted channel. Tell them not to trust recent messages until you confirm the account is secure.
A manufacturer account can have meaningful access without appearing under Device admin apps or Accessibility.
Available actions vary by manufacturer, model, region and what was enabled beforehand. Do not rely on an old list of remote features; check the provider's current official page.
A clean Device admin or Accessibility screen does not show where cloud data is going. Inspect the destination account for each service, not merely whether the service is enabled.
Removing an unwanted destination stops future access only where the service says it does. It does not delete copies somebody has already downloaded, saved to another account or restored elsewhere.
Loss of service, missing verification texts, unexpected SIM-change messages or calls being redirected are carrier-account problems, not proof that Android itself is managed.
Open the Phone app's settings and look for Call forwarding, often under Calling accounts, Calls, Supplementary services or a particular SIM. Check every forwarding condition for every SIM and remove any destination you did not set.
There is no universal Android path, and some carriers do not expose every network setting in the dialler. Contact the carrier using a number from its official website and ask it to verify call forwarding on the network even if the handset screen looks clean. Reset the voicemail PIN as well; do not reuse the phone unlock PIN or carrier-account password.
Ask the carrier to:
Do not rely on SMS for account recovery until the carrier confirms the number is secure.
Also review linked-device and session controls for messaging services in section 3. Someone can retain access through WhatsApp, Telegram, Signal or another service even after losing access to the Google Account.
Search Settings for and review:
An app's long list of declared permissions, whether shown in a manifest, system-app database or diagnostic report, does not mean every permission is currently granted or being used. The current Settings screens, Privacy dashboard and observable account or device activity are what matter.
Open Play Store → profile picture → Play Protect → Scan. Uninstall apps Play Protect identifies as harmful. Also install all Android, Google Play system and app updates.
Open Settings → Apps → See all apps and review the complete list, not only the app drawer or Home screen. Some installed apps have no launcher icon. Uninstall an unfamiliar app only after recording its name and checking that it is not a system, carrier, accessibility, work, school or safety app you intentionally use.
For a strange-looking system app or package name, search the BAYTON Android system app database. Use the exact package name from the app-information screen where available, then check the observed manufacturer, device and Android versions. The database shows which packages have been seen preloaded across real device profiles and what they are for. A match can explain a normal system component; a missing result does not prove an app is malicious because coverage is not universal.
Do not search an app store or website for an “anti-spy”, “hacker detector”, “stalkerware scanner” or similar app and grant it broad permissions merely because of its label or advertising. It is still untrusted third-party software and may produce alarming claims without establishing compromise. Use Android's built-in Settings checks and Play Protect. If a qualified forensic examiner needs a specialist tool, let that examiner choose and operate it while preserving evidence.
If you are comfortable working with Android diagnostic output, a bug report can corroborate some of the checks above before a reset. Follow How to capture a bug report and device logs, note the exact capture time and how the report was generated, keep the complete original ZIP unchanged and inspect a separate copy locally. If police or a qualified forensic examiner asks for the report as evidence, provide the whole original archive through the secure evidence channel they specify rather than only screenshots, copied lines or selected files. The main bugreport-...txt file contains Android system-service state (dumpsys), diagnostic output (dumpstate) and system messages (logcat).
Useful places to search include:
DUMP OF SERVICE device_policy: can identify a device owner, profile owners, active device administrators, their package/component names and policies. Labels vary between Android releases. An active administrator is not necessarily a device owner, and a recognised work, school, parental-control or lost-device app may be legitimate.DUMP OF SERVICE account: can show configured account types and, depending on the Android version, manufacturer and redaction applied, account identifiers. An unfamiliar account type may simply belong to an installed app; compare it with the accounts in Settings and the owning package before drawing a conclusion.DUMP OF SERVICE user, UserInfo, managed profile and Private Space to corroborate which Android users or profiles exist. The exact wording and detail vary by build.DUMP OF SERVICE package: can show installed package names, versions, installation paths, components and permission state. Search for the exact package name found elsewhere in the report. A /system, /product or /system/priv-app path is not evidence of compromise by itself.A bug report is a snapshot plus a limited amount of historical logging. It may omit or redact information, and manufacturers add their own sections, so absence from a report does not prove absence from the device. It also cannot replace the account, sharing and carrier checks in sections 3 to 5: a Google Photos partner, linked messaging session, remote account login or network-side forwarding rule may not appear in it at all.
A bug report can contain account or device identifiers, installed packages, network details, recent activity and app-written log messages. Do not post it publicly, paste it into a forum or chatbot, or upload it to an unknown “bug report analyser”. Share it only through a secure channel with the manufacturer, account or service provider, law enforcement or a qualified forensic examiner who has asked for it. Do not send it to me.
Finding a device owner, profile owner, active administrator or unfamiliar account is actionable evidence to investigate through the relevant organisation, app or account provider. It is not attribution: the report does not establish who configured it or whether their intent was malicious.
Use the phone manufacturer's official instructions to restart in Safe Mode. On many phones, open the power menu, touch and hold Power off, then confirm Safe Mode. Downloaded apps are temporarily disabled until the next normal restart.
If unexplained on-screen behaviour stops in Safe Mode, a downloaded app is likely responsible. Restart normally, then uninstall recently added or unfamiliar apps one at a time. Safe Mode does not sign other people out of online accounts or stop account forwarding, backups, linked sessions or location-sharing settings, so it is a diagnostic step rather than proof that the phone is secure.
Android's Verified Boot design shows a warning on every boot when the bootloader is unlocked because software integrity cannot be guaranteed. If a used phone shows an unlocked-bootloader or custom-operating-system warning that the seller did not disclose, treat the device as untrusted: do not put sensitive data on it, return it to the seller where possible, or ask the manufacturer or an authorised repair provider to restore and verify official software.
A normal factory reset does not prove the bootloader or operating system has been returned to its official state. Do not blindly relock the bootloader, flash firmware or run copied ADB commands; doing so can destroy evidence or data and may make the device unusable.
On supported Android devices, device-side Advanced Protection provides a single hardened mode under Settings → Security and privacy → Advanced Protection → Device protection. It keeps Play Protect enabled, blocks installs and updates from unknown sources, restricts unverified Accessibility tools, protects USB data access while locked, prevents 2G connections on supported hardware and enables other protections. See What is Advanced Protection, and can it be managed? for the full explanation.
This Android device setting is distinct from Google's account-side Advanced Protection Program in section 3. Review and enable each separately where it suits the risk and the device supports it.
A reset is appropriate after confirmed account compromise, an unknown high-privilege app that cannot be removed, or persistent unexplained behaviour after the checks above.
If enterprise setup returns before any account is added, follow section 2. Repeated resets will not remove reseller-based enterprise registration.
If Settings is blocked, or unexplained behaviour continues after a clean setup without enterprise enrolment, contact the manufacturer or an authorised repair provider and ask it to reinstall the device's official signed firmware. This can destroy data and evidence. Do not follow an unknown person's flashing instructions, unlock the bootloader, or run ADB commands copied from a forum unless you understand exactly what they will remove. Replacing the phone is the final option, after the accounts and mobile number have been secured; otherwise the same account problem can simply follow to the replacement.
Treat these as evidence worth acting on:
These are not evidence on their own:
If the relevant checks do not produce evidence matching one of these categories, I cannot determine from screenshots of Android system components that the phone has been taken over. That does not prove compromise is impossible; it means there is no actionable evidence for me to diagnose remotely. Use the exit route for the system that shows the evidence: the account provider, mobile carrier, organisation, seller, manufacturer, bank, police or qualified forensic examiner.
Menu names and paths differ between manufacturers. Where a device-specific page is listed below, prefer your own manufacturer's official documentation for the equivalent screen.
Safety and support
Accounts and data recovery
Linked sessions and remote-device services
Management, supervision and other users
Advanced diagnostics
Apps, permissions and network settings
Resetting the device
On this site