My mum visited some suspicious websites on her Samsung phone and followed misleading pop-ups claiming the phone was hacked or running out of storage. She installed several apps advertised as antivirus tools and entered her bank details into one of them. Fortunately, no money was taken, and the compromised account has been closed and replaced. I initially removed the suspicious apps, but some seemed hidden, and the phone became difficult to use until I started it in safe mode, where I found unfamiliar applications that were not visible normally. Is a full factory reset enough to remove the malicious software, or should I take additional steps? Do we need to replace the phone entirely?
4 Answers
Since banking information was entered into a suspicious app or website, changing the relevant passwords and contacting the bank was important even though the account has been closed. Keep monitoring the replacement account and consider enabling transaction alerts and multifactor authentication. The phone itself can normally be safely reused after the reset and updates.
Reset the phone, update it to the newest operating system available for that model, and review its security settings. It is also worth disabling browser notifications or clearing the browser's site permissions, since those fake warnings often come from websites being allowed to send notifications rather than from a real system infection.
A factory reset should remove this kind of app-based malware, so replacing the phone should not be necessary. After resetting it, install all available system updates before restoring anything, and only reinstall apps that are genuinely needed from the official app store. Avoid restoring unknown apps or settings from an old backup.
The bigger risk is that the same thing could happen again. Explain that browser warnings claiming the phone is hacked or out of storage are usually scams, and that legitimate security alerts should not require installing random antivirus apps or handing over bank details. If possible, enable app-install restrictions and make sure sideloading from unknown sources is disabled.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures