📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

FBI Warning: Turn Off THIS Hidden Phone Setting NOW

Mobile Alert20:02

Transcription

There's a setting hidden inside your phone right now that security agencies have quietly been warning people about, and almost nobody has ever turned it off because almost nobody even knows it's there. It's not some obscure setting buried for advanced users. It's on by default on almost every phone, and it's been quietly exposing people to scams, tracking, and data theft without them ever realizing it.

In the next few minutes, I'm going to show you exactly where it is, why it's dangerous, and how to shut it off in under 30 seconds. And then, because one setting is never the whole story, I'm going to show you four more that work alongside it. The ones that companies and data brokers really don't want you to know about. Stay with me till the end because the third one is the one that even IT professionals miss.

Before we go any further, I want to be up front about something. A lot of videos with titles like this one exaggerate. They tell you your phone is spying on you without ever explaining how, and they never actually show you the setting. That's not what this is. Everything I'm about to walk you through is real. It's documented by actual privacy researchers and by official security advisors, and I'm going to take you through it step-by-step on both iPhone and Android. No fear-mongering after this point, just the actual setting, the actual risk, and the actual fix. And I know that sounds like a big promise for a video about phone settings, but stick with me because by the time we're done, you'll actually understand why this specific setting has been sitting on your device this entire time without you ever being asked a clear, direct question about it.

Most people assume that if something mattered for their privacy, their phone would make it obvious, front and center, impossible to miss. In reality, the settings that matter most are almost always the ones buried three or four menus deep, worded in language that sounds technical and boring on purpose so that almost nobody ever goes looking for them. That's not necessarily some evil plot. A lot of it is just how these systems were designed years ago, before privacy became the conversation it is today. But the effect is the same either way. These settings sit there quietly doing [clears throat] their job in the background, completely untouched for the entire life of the phone.

Let's start with the big one. Every smartphone you've ever owned, iPhone or Android, has a hidden identifier attached to it called an advertising ID. On Android, it's called the Google advertising ID. On iPhone, it's called the IDFA, which stands for identifier for advertisers. Think of it like a license plate that's bolted under your phone. It's a random string of letters and numbers unique to your device. It isn't your name. It isn't your IMEI. But here's the problem. Every single app you install can read it, and every app that reads it can attach whatever data it collects about you to that exact same ID.

So, picture this. A shopping app notices you looked at running shoes last week. A weather app knows your precise location three or four times a day. A game you play in the evenings knows what time you're usually on your phone and how long you tend to stay in a knee brace before moving. On their own, none of those facts seem dangerous. But, because all of those apps can tag their data with the same advertising ID, that information can be quietly combined by ad networks, by data brokers, sometimes by companies you've genuinely never heard of, into a surprisingly detailed picture of your life. Where you live, where you work, what you buy, what you've been searching for late at night, even who you spend time with based on whose phone happens to be near yours regularly.

This isn't some conspiracy theory. This is literally the engine behind the multi-billion dollar mobile advertising industry, and it's also the exact mechanism that data brokers rely on to build the kind of profiles that eventually get sold, sometimes to marketers, and sometimes, and this is the part that should genuinely concern you, to scammers who buy leaked or purchased data sets specifically to run targeted phishing campaigns. If a scammer already knows your name, your rough location, and that you were recently searching for something like debt consolidation, a fake text saying your loan has been approved suddenly looks a lot more convincing than a random message out of nowhere.

This is part of why federal cybersecurity advisories have repeatedly urged people to review their app permissions and disable unnecessary data sharing, specifically pointing out how ordinary background data collection, even from apps that seem completely harmless, creates exactly this kind of exposure over time.

So, here's how you shut it down. If you're on an iPhone, open Settings, tap Privacy & Security, then scroll down and tap Tracking. Turn off the option that says "Allow Apps to Request to Track." While you're in that section, go back one step to Privacy & Security and look for Apple Advertising, then turn off Personalized Ads there as well. That second step matters just as much as the first one. One of them stops other apps from tracking you across the internet, and the other stops Apple's own advertising system from quietly building a profile based on what you do on your device.

If you're on Android, open Settings, tap Privacy, and depending on your phone and your Android version, you might find this under Google, then Ads. Tap on Ads. On newer versions of Android, you'll see an option that says "Delete advertising ID." That's stronger than simply opting out because it actually removes the identifier entirely rather than just flagging it as private. On older versions, instead, you'll see an option that says "Opt out of Ads Personalization," and you just switch that on. If you're using a Samsung phone specifically, go into Settings, then Security and Privacy, then Privacy, and scroll down until you find Google Services, then Ads.

The whole process takes about 20 seconds on either platform, and once it's done, apps lose the single biggest tool they had for stitching your activity together across completely different services. It's worth pausing here for a second because I don't want this to just sound like a dry technical explanation. Think about what this actually means in practice. Right now, before you make this change, there's a profile of you sitting somewhere on a server, built entirely out of pieces of your daily behavior that felt too small to matter individually. The app you use to track your sleep, the app you use to order food, the browser you use late at night when you're bored and scrolling. None of those companies necessarily know your real name directly, but they don't need to because the advertising ID does the connecting for them. And once that profile exists, it doesn't just sit there being used for slightly more relevant shoe ads. It gets bought, sold, licensed, and passed along a chain of companies you will never see or hear about. And at the very end of that chain, sometimes, is someone whose entire business model is finding people who look like good targets for a scam.

Turning this setting off doesn't erase what's already been collected. I want to be honest about that. But it does stop the profile from growing any further from this point forward. And it removes the threat that ties your future activity back to your past activity. This is also worth mentioning because a lot of people assume that if they've never clicked on a suspicious link, they're safe. But the advertising ID doesn't require you to click on anything. It works purely in the background, passively, as a side effect of simply using your phone normally, which is exactly what makes it so easy to overlook.

Now, let's talk about the second setting, and this one is sneakier because a lot of people actually think they've already dealt with it. You've probably gone into your location settings at some point and turned location off for an app or two that didn't seem to need it. But underneath that, there's a separate layer, a kind of background location history that keeps quietly logging where you go, even after you think you've locked everything down.

On iPhone, this lives inside something called Significant Locations. Apple describes it as a feature that helps your phone learn the places you visit most often so it can offer you better traffic predictions and smarter reminders. What it actually is, functionally, is a running, huh, log stored on your device of every place your phone considers meaningful: your home, your workplace, anywhere you go repeatedly, each one timestamped. Most people have genuinely never opened this menu in their life, and when they finally do, they're often unsettled by just how detailed and specific it is.

To check it on an iPhone, open Settings, then Privacy & Security, then Location Services. Scroll all the way to the very bottom and tap System Services. From there, tap Significant Locations. You'll likely be asked to confirm with Face ID or your passcode, and honestly, that alone tells you something because that's Apple itself acknowledging how sensitive this particular data is. Once you're in, you can scroll through the actual log of places. At the top, there's a toggle you can simply switch off.

On Android, the equivalent doesn't live in the phone's settings menu at all. It lives inside your Google account because it's tied to something called Location History, which historically has defaulted to uploading this data straight to your Google account. Although in more recent years, Google has shifted towards storing a lot of this on the device itself by default in many regions. Because that default has changed more than once and varies depending on your account age and where you live, it's genuinely worth checking rather than assuming. To do that, open the Google app or go to myaccount.google.com in a browser. Tap Data & Privacy. Scroll down to History Settings and tap Location History, which on some versions is labeled Timeline. From there, you can see exactly what's being stored, and you're able to pause it entirely or delete the history outright.

The risk here isn't only about advertising. This kind of location log is exactly the sort of data that gets requested in legal proceedings. Exactly the sort of data that ends up exposed when a company's servers get breached, and unfortunately, exactly the kind of data that's been used in real stalking and domestic abuse situations where someone has access to a shared device or a shared account. It's not an abstract privacy concern. It has genuine real-world weight to it.

And here's something worth sitting with for a moment. A lot of people, when they first open this log, whether it's Significant Locations on iPhone or Timeline on Android, expect to see something vague, maybe a general sense of the city they live in. What they actually find is startlingly specific. The exact building they were in, the exact time they arrived, and the exact time they left. Sometimes patterns going back months, sometimes longer, quietly building a map of their entire life without a single explicit prompt asking permission along the way. It's not that any single entry in that log is dangerous on its own. It's that the whole log together forms a routine, and a routine is exactly the kind of information that turns a random target into a predictable one. This is why security researchers keep coming back to this particular setting, not because any one data point is scary, but because of what the complete picture adds up to.

Now, here's the one I promised you at the start, the setting that even a lot of IT professionals overlook because it isn't filed under privacy at all. It's tucked away under connectivity. Both iPhone and Android have a background feature that keeps your Wi-Fi and Bluetooth radios quietly scanning for nearby networks and devices, even when Wi-Fi and Bluetooth themselves appear to be switched off from your Control Center or your quick settings panel.

Why does this even exist? There's a legitimate reason behind it. It's there to make location accuracy better because your phone can figure out where you're far faster using nearby Wi-Fi routers and Bluetooth beacons than it can using GPS alone, especially indoors where GPS struggles. That part is a genuinely useful feature. But, here's the security problem underneath it. Retailers, shopping malls, and airports increasingly use Bluetooth and Wi-Fi beacons specifically to track foot traffic, which stores you walk in a mall and how long you linger near a particular display, whether you're a returning visitor to that location. Your phone's scanning while off feature is part of what quietly makes that kind of tracking possible because your device keeps broadcasting and listening even when you assume both radios are completely dead.

To turn this off on an iPhone, go to Settings, then Privacy & Security, then Location Services, then scroll down to System Services at the bottom, the same menu you were in a moment ago. From there, turn off Wi-Fi Networking, and also turn off Bluetooth and Wi-Fi Scanning, which sits just below it.

On Android, open Settings, tap Location, then tap Location Services, and from there turn off Wi-Fi Scanning, and also turn off Bluetooth Scanning.

I do want to be honest with you about the trade-off here because I'd rather tell you the downside than pretend there isn't one. Turning these off can occasionally make location-based features slightly slower or a little less accurate indoors. Like your Maps app taking an extra second or two to lock onto your exact position inside a mall or an airport terminal. For most people, that's a completely fair trade-off for the privacy you get back, but it is a real one, and you should go in knowing that rather than being surprised by it later.

What makes this particular setting worth calling out specifically is how invisible it is, even to people who consider themselves fairly careful about their privacy. You can turn off Wi-Fi from your Control Center, watch the icon go gray, and reasonably assume the radio is now completely inactive. That assumption is wrong, and it's wrong by design, because the manufacturers built it that way on purpose for the sake of convenience and faster reconnections. It's a reasonable trade-off from an engineering standpoint, but almost nobody is ever told about it in plain language, which means almost nobody makes an informed choice about whether they actually want that trade-off for themselves.

Setting number four isn't really one single toggle, it's more of a category, and honestly, it might be the most important one on this entire list, because it's the one most directly tied to actual scam cases people have experienced. Every time you install an app, it asks you for permissions: camera access, microphone access, your contacts, your location. Most people tap "Allow" once in the moment because the app told them it needed it to work properly. The problem is that permission almost never expires on its own. It just sits there active indefinitely, long after you've completely forgotten you ever granted it in the first place.

This is exactly the pattern that cybersecurity advisories have flagged again and again, not some single flashy exploit, but the slow accumulation of permissions spread across dozens of apps, most of which never get revisited even once after the day they were installed.

To audit this on an iPhone, go into Settings, then Privacy & Security, and go through each category one at a time: Camera, Microphone, Contacts, Photos, Location Services. For each one, you'll see a full list of every app that currently has access. Ask yourself honestly, for each app on that list, does this app actually need this permission right now to function the way I use it? A flashlight app does not need access to your contacts. A calculator does not need access to your microphone. If there's no clear, obvious reason, revoke it.

On Android, go to Settings, then Apps, tap See all apps, and look for something called Permission Manager, which on some phones sits under Settings, then Privacy, then Permission Manager directly. This flips the whole process around in a useful way. Instead of going app by app, you go permission by permission. So, you can instantly see, for example, every single app on your phone that currently has microphone access all at once. Revoke anything that doesn't clearly need to be there. And for anything you're not quite ready to cut off completely, both platforms let you set access to "While Using the App" instead of "Always." And that one small change closes off most of the realistic risk on its own.

This is genuinely the step that takes the longest, realistically somewhere between 5 and 10 minutes if you actually go through it properly instead of rushing it, but it's also the one with the highest payoff because it's not really about advertising at all, it's about what happens if one of those apps you trusted turns out to be less trustworthy than you assumed or gets compromised down the line. If it never had the permission to begin with, none of that matters because there was nothing for it to take.

One thing I'd genuinely encourage you to do while you're going through this list is pay attention to how you react emotionally as you go because most people have a very specific moment during this process where they stop and think, "Wait, why does this app have that?" Maybe it's a note-taking app with access to your microphone. Maybe it's a photo editor with access to your entire contact list. That reaction, that little jolt of confusion, "Oh," is worth trusting because in almost every case, if you have to stop and ask why an app needs something, the honest answer is that it probably doesn't, and the permission was simply granted in a rushed moment during setup without a second thought. Companies know this, too, which is exactly why so many permission requests are timed to appear during onboarding when you're focused on getting the app working rather than carefully evaluating each request on its own merits.

And the last one isn't really a setting at all. It's a habit. And it happens to be one that's been specifically recommended in official cybersecurity guidance. Fully power off your phone at least once a week. Not a restart, an actual complete shutdown. Phone entirely off, then back on again after a few seconds.

Here's why this matters more than it might sound like it should. There's a category of attacks called zero-click exploits that don't need you to tap anything, open anything, or click a suspicious link at all. They exploit vulnerabilities in system-level processes to gain access silently without any interaction from you whatsoever. Some of the resulting malware lives entirely inside your device's temporary memory, its RAM, rather than being permanently installed onto the storage. That means it disappears the instant the device is fully powered down, simply because RAM can't hold data without a continuous power supply.

A basic restart doesn't reliably achieve the same thing because on a lot of phones, restarting is a comparatively soft process that can leave certain background sessions and cached processes running underneath the surface. A genuine full shutdown, completely off, a short pause, then powering back on forces everything to reload entirely from scratch.

I want to be honest with you here, too. This isn't a complete fix against a sophisticated determined attacker. They have other ways back in regardless. But for the much larger and far more common end category of opportunistic memory-only exploits, it's a free habit that takes about 30 seconds and meaningfully raises the bar against them. Once a week, that's genuinely worth building into your routine.

I know a full shutdown sounds almost too simple to actually matter, especially after everything else we've just gone through, all the menus and toggles and settings buried inside settings. But that's actually part of what makes it worth mentioning. Not every meaningful security habit needs to be complicated. Sometimes, the most effective thing you can do is also the most boring one, the one that doesn't feel like it's doing anything because there's no menu to navigate and no confirmation screen telling you it worked. You just hold the button, watch the screen go dark, wait a moment, and turn it back on. It costs you nothing, it takes less time than making a cup of tea, and unlike a lot of security advice that requires ongoing effort or constant vigilance. This is the kind of thing you can genuinely set into your weekly routine, the same way you'd remember to take the bins out, and then more or less forget about it while still getting the benefit every single time.

So, let's bring it all together quickly one more time. Turn off your advertising ID and personalized ads on both iPhone and Android because that's the setting that lets different apps stitch your activity together into a single combined profile of you. Check Significant Locations on iPhone or Location History on Android because that's the running log of everywhere you've been, and most people have simply never opened it to look. Turn off Wi-Fi and Bluetooth scanning even when those radios look switched off from the outside because that's what allows retailers and public spaces to quietly track your movement through beacons. Go through your app permissions properly, either app by app or permission by permission, and revoke anything that isn't clearly earning its place because that's the step that actually protects you if an app you currently trust turns out not to deserve that trust down the line. And finally, fully power off your phone completely at least once a week because that's the habit that clears out the threats that only ever live in memory and nowhere else.

None of these individually take more than a minute, and together they close off the overwhelming majority of the ways your phone has been quietly collecting and exposing information about you, often without you ever agreeing to it in any meaningful sense. If any part of this is useful to you, the single best thing you can do right now is send it to one person in your life who has genuinely never touched a single privacy setting on their phone because if you think about it, honestly, that describes most people you know. And if you want a future video that goes even deeper into one of these, especially how data brokers actually use this information once they have it, or how scammers specifically exploit it, let me know because that's exactly the kind of follow-up worth making next.

At the end of the day, none of this is really about paranoia. It's about the simple fact that most of these systems were built to default toward convenience and toward data collection, not because anyone was trying to trick you specifically, but because that's what made the products easier to build and easier to monetize. You're not doing anything unusual or overly cautious by going in and adjusting these five things. You're just finally being asked, in plain language, the question your phone should have asked you honestly on day one and answering it the way you actually would have answered it if anyone had bothered to ask.