Search for how to remove spyware and the advice is unanimous: delete the app, change your passwords, factory reset. Straightforward, and for one kind of intrusion it is correct.
For the most common kind it is the worst possible first move.
The difference is who installed it. If an unknown criminal is behind it, remove it today. If it is a partner, an ex, a family member or an employer — which is the majority of real cases — deleting it does two things you may not want. It tells them you found out, at a moment you did not choose. And it destroys the evidence.
Decide which situation you are in
Somebody in your life may be involved if the phone has been physically accessible to them, if they know your passcode, if they set up the device or pay for the account, or if they have known things they had no ordinary way to know. Go to the careful sequence below.
It is probably an unknown attacker if the phone was compromised through a malicious app you installed yourself, a phishing link, or a public jailbreak, and nobody in your life plausibly had access. Skip to the direct removal section. Speed is your friend there.
If you are unsure, treat it as the first case. The careful path costs you a few days. The fast path, chosen wrongly, cannot be undone.
The careful sequence
1. Change nothing yet
Not the app, not the passwords, not the settings. Do not confront anybody. Assume for now that what you do on the phone is visible, including reading this.
2. Get advice, from a different device
Use a phone or computer the other person has never had access to. A friend's phone, a work machine, a library terminal.
Domestic violence organisations deal with this weekly and will help you plan the order of events around your actual situation. The Coalition Against Stalkerware maintains a directory; NNEDV's Safety Net project in the US and Refuge in the UK both run technology-abuse services. These calls are free and confidential.
3. Document before you delete
This is the step that disappears the moment you tap uninstall, and the one that matters if this ever involves a lawyer, a police officer or a family court.
Screenshots of settings screens are better than nothing. A forensic report from an external analysis is considerably better: it shows what was installed, what access it had, and when, in a form somebody non-technical can read. This is the case where paid tooling earns its place, and it is worth arranging before removal rather than after. Haris Shield produces exactly this kind of report.
4. Secure your accounts, from another device, in this order
Account access is often the real channel, and it survives wiping the phone.
- Email first. It resets everything else. Change the password, turn on two-factor authentication, and check the recovery email and phone number. A recovery address belonging to the other person hands the account straight back, no matter how strong the new password is.
- Apple ID or Google account. Same treatment, plus review the list of signed-in devices and remove ones you do not recognise. Bear in mind removals can be noticed.
- Messaging. Check for linked devices: WhatsApp, Signal and Telegram all let another device stay connected indefinitely. Also check for a forwarding rule quietly added to your email.
- Banking and shopping, where a saved card also reveals where you have been.
Do all of this from a device the other person has never touched.
5. Plan the removal, do not improvise it
Decide deliberately, with support in place, between three options:
- Clean the phone, accepting that the other person may notice.
- Replace the phone, set up fresh, with a new Apple ID or Google account, restoring nothing.
- Leave it alone for now and use a second, private phone for anything sensitive. Sometimes the safest phone is the one that continues to look exactly as it did.
The third option is the one nobody writes about, and for some situations it is the right one.
Direct removal, when nobody in your life is involved
On Android
- Revoke the permissions before uninstalling. Device admin first, under Settings, Security, Device admin apps — an app with device admin rights can refuse to be uninstalled until you remove that. Then Accessibility services, then notification access.
- Uninstall the app, under Settings, Apps.
- Turn Play Protect back on and run a scan.
- Update Android and the Google Play system updates.
- Change your Google password and sign out of unfamiliar devices.
On iPhone
- Remove unrecognised configuration profiles, under Settings, General, VPN and Device Management.
- Update iOS. Most iPhone intrusions rely on flaws Apple has already patched, so this alone removes many of them.
- Change your Apple ID password and review the device list.
- If the phone was jailbroken, updating iOS removes the jailbreak, and a factory reset is the safer answer.
- Consider Lockdown Mode if you have real reason to think you were targeted deliberately.
The backup trap
This is where people undo their own work.
A factory reset wipes the phone. Then you restore your backup, because otherwise you lose your photos and messages, and if the backup was made while the phone was compromised, you can reinstall the problem on day one of your clean phone.
How to avoid it:
- Set up as new, not from a backup, if you can bear it.
- If you must restore, use a backup made before the compromise, if you can date it. The forensic analysis in step 3 is what tells you roughly when things changed.
- Restore data selectively: pull photos and contacts out of the backup rather than restoring apps and settings wholesale.
- After restoring, re-check the settings screens. Configuration profiles and permissions can come back with a settings restore.
And note what a factory reset does not fix: it does nothing about somebody who knows your account password. If the access route is the account, wiping the phone accomplishes nothing at all.
Does a factory reset always work?
For commercial stalkerware on a normal device, yes. For anything with root or a jailbreak, usually yes, since the reset removes the modified system. For state-grade spyware, generally yes for persistence, because most mercenary implants do not survive a reset and some do not even survive a reboot — which is also why they get reinstalled, silently, by the same route as before.
That is the real point. Removal fixes the infection. It does not fix the way in. If the way in was physical access to an unlocked phone, and that access still exists, you will be back here.
Closing the way in
- A passcode nobody else knows. Check no extra fingerprints or face entries have been enrolled.
- Updates the day they arrive, both operating system and app stores.
- Two-factor authentication, starting with email.
- No jailbreaking or rooting, by you or anyone else.
- Account device lists reviewed every few months.
- Sharing features revisited. Location sharing set up in a happier period and forgotten is its own form of monitoring.
The short answer
If somebody you know may be behind it: advice first, documentation second, accounts third, removal last, and never a confrontation before you are ready.
If it is an unknown attacker: revoke device admin before uninstalling on Android, update the operating system, change your passwords from another device, and be careful which backup you restore.
Either way, removal closes the infection, not the door. If you do not change how they got in, the same thing happens again.
Sources
- Coalition Against Stalkerware, Information for survivors: stopstalkerware.org/information-for-survivors
- NNEDV Safety Net, technology safety: techsafety.org
- Apple, About Lockdown Mode: support.apple.com/en-us/105120
- Google, Play Protect: support.google.com/googleplay/answer/2812853
Related reading: stalkerware signs and what not to do, how to detect spyware on Android.