The Bizzi Route

29 August 2026 International analysis

Search

Technology

Smartphone owners warned over 'harmless' apps in hacking surge

Consumer group Which? warns that most smartphone hacking cases it handles trace back to seemingly harmless apps, urging users to review permissions and delete suspicious downloads.

Smartphone owners warned over 'harmless' apps in hacking surge
Smartphone owners warned over 'harmless' apps in hacking surge

Consumer experts have issued a fresh warning to smartphone owners after finding that the vast majority of hacking incidents handled by their technical support team can be traced back to a seemingly harmless app. The warning comes amid a surge in reported cases, with many victims unaware that the software they downloaded voluntarily was the entry point for cybercriminals.

According to the consumer group Which?, the overwhelming share of compromised phones dealt with by its specialists had one thing in common: a dodgy application installed by the user. These apps often present themselves as legitimate tools, games, or utilities, but in reality they carry hidden code designed to harvest personal data, track activity, or grant remote access to the device.

The findings highlight a growing blind spot in mobile security. While many users are cautious about phishing emails and suspicious links, the same level of scrutiny is rarely applied to app downloads. Which? researchers point out that malicious apps frequently slip through official store checks, particularly when they are distributed through third-party platforms or sideloaded directly onto the device.

Experts recommend a series of practical steps to reduce the risk. Users should review the permissions requested by each app before installation, paying close attention to those that ask for access to contacts, messages, location, or camera functions without a clear reason. Apps that request administrative privileges or the ability to overlay other applications should be treated with particular suspicion.

Another key piece of advice is to keep the operating system and applications up to date. Security patches released by manufacturers and developers often close vulnerabilities that have already been exploited in the wild. Delaying updates, the group notes, leaves devices exposed to known attack vectors that could have been neutralised with a simple download.

The warning also extends to app behaviour after installation. Sudden battery drain, unexpected pop-ups, unfamiliar charges, or a noticeable slowdown in performance can all be indicators that something is running in the background without the user's knowledge. In such cases, the safest course of action is to uninstall the app immediately and run a security scan.

For those who believe they have already been compromised, Which? advises changing passwords for all critical accounts, enabling two-factor authentication, and contacting their bank if any financial information may have been exposed. In more serious cases, a factory reset may be necessary to remove persistent malware that survives standard uninstallation.

The broader lesson, according to the group, is that mobile devices are now a primary target for cybercriminals precisely because they hold so much sensitive information. Banking apps, messaging services, email clients, and digital wallets all make the smartphone an attractive prize. The convenience of app stores should not be mistaken for guaranteed safety, and users must take personal responsibility for what they install.

This latest advisory reflects a wider trend in cybersecurity, where the weakest link is increasingly the human decision to grant access. Technical safeguards are only effective when paired with informed behaviour. As the number of connected devices grows, so does the attack surface, and the warning from Which? serves as a reminder that the most innocuous-looking download can carry the highest risk.

Harriet Beaumont

Author

Staff Reporter

Harriet Beaumont covers public affairs, politics, business, culture and daily news for The Bizzi Route. The role focuses on verification, context, and clear explanations for readers.