A safety-first guide to stalkerware, covert tracking, hidden surveillance, evidence preservation and authorised forensic investigation.
ORIGINAL PUBLICATION: 24 September 2019 REVISION COMPLETED: 21 September 2026 AEST
By: Claude Khoury, Chief Operating Officer, NSI Global
|
IMPORTANT SAFETY NOTICE |
Technology-facilitated abuse is no longer limited to threatening messages or obvious phone monitoring. A partner or former partner can misuse ordinary accounts, location-sharing features and connected devices, or introduce dedicated surveillance technology such as stalkerware, GPS trackers, Bluetooth tags, hidden cameras, covert audio recorders or other monitoring devices. The safest response depends on what is happening, who may be involved and whether changing the technology could increase risk.
The eSafety Commissioner uses the term technology-facilitated abuse, or tech-based abuse, for harmful behaviour carried out through digital technology, including stalking, threats, harassment and coercive or controlling behaviour. In domestic and family violence, technology may be used before, during or after separation to monitor movement, control communications, obtain private information or maintain a sense of constant presence.
This article is not a guide to locating or disabling surveillance equipment on your own. It explains the threat landscape, the warning signs that may justify professional investigation, the safety and evidence issues to consider, and the authorised pathways through which NSI Global may assist lawyers, police, government agencies, recognised support organisations, investigators and case officers.
Technology-Facilitated Abuse Is a Real and Documented Surveillance Risk
The use of tracking technology in domestic and family violence is not hypothetical. In Project Hakea, the NSW Crime Commission reported that 79 of 96 offenders charged with unlawful use of tracking devices between 2010 and 2023 – 82 per cent – were charged in relation to a domestic violence event. The Commission also identified that nearly 25 per cent of known individuals who purchased tracking devices since 2023 had a history of domestic violence.
The post-separation period was particularly significant. The Commission found that 75 per cent of offenders charged with DFV-related tracking-device offences in its dataset began tracking the victim following separation, and for nearly two-thirds of that subset the tracking began within three months of separation.
Those findings reinforce an important investigative principle: unexplained location knowledge after separation should not automatically be attributed to spyware on a phone. The source may be an account setting, a location-sharing service, a Bluetooth tag, a dedicated GPS tracker, a vehicle system, a connected device or information obtained through another person.
How Technology Can Be Used to Monitor, Track or Control Someone
The modern threat model is broader than a single hidden bug or malicious app. Consumer-accessible surveillance technology and legitimate digital services can be misused in several different ways.
| Threat Pathway | Examples of What May Be Misused | What an Investigation May Need to Examine |
| Phone or computer compromise | Spyware, stalkerware, remote-access tools, malicious apps, unauthorised profiles or other compromise. | Device artefacts, installed software, persistence, account activity, logs, indicators of compromise and relevant timelines. |
| Account and cloud access | Apple, Google, email, social media, cloud storage, password recovery, family-sharing or linked-device access. | Sign-in history, trusted devices, recovery details, sharing settings, sessions, cloud data and account changes. |
| Location sharing | Legitimate location-sharing features, family apps, maps, ride-share accounts, calendars or other services. | Which people, apps and devices receive location information and when sharing changed. |
| Bluetooth / location-network trackers | AirTags and compatible network-connected tags or accessories travelling with a person, bag or vehicle. | Tracker alerts, identifying information, associated chronology, physical examination and lawful preservation. |
| Dedicated GPS tracking | Standalone, vehicle-connected or cellular location trackers. | Vehicle or property inspection, device identification, power/connectivity source, lawful handling and evidentiary documentation. |
| Hidden video surveillance | Miniature or disguised cameras, locally recording devices and internet or cellular-connected cameras. | Physical TSCM inspection, optical/physical assessment, network and RF analysis where relevant, and evidence-aware recovery. |
| Covert audio surveillance | Small recorders, microphones, locally storing devices or transmitting listening equipment. | Physical inspection, electronic/RF analysis, examination of suspect items and related digital evidence. |
| Smart home and connected systems | Cameras, doorbells, speakers, access systems, lights, thermostats, alarms or other connected-home accounts. | Account ownership, shared access, device administration, cloud logs, permissions and physical equipment. |
| Vehicle and wearable ecosystems | Vehicle apps, telematics, smart watches, family accounts or companion applications. | Authorised account access, paired devices, location records, vehicle systems and physical inspection. |
Covert Devices No Longer Need to Look Like Surveillance Equipment
A practical investigation must also account for the fact that covert hardware is now sold in forms designed to blend into normal environments. Consumer-accessible products can include disguised cameras and audio recorders, compact GPS trackers, Bluetooth or location-network tags, pinhole camera modules and devices that communicate over mobile networks rather than relying on the local Wi-Fi network.
Some devices may transmit continuously, but others can record locally, activate only under certain conditions or communicate intermittently. That is why a meaningful TSCM assessment is not simply a one-time scan for a strong radio signal. Depending on the circumstances, it can require physical inspection, RF and spectrum analysis, cellular and network assessment, optical inspection and device-specific examination.
For safety reasons, this article does not identify retailers, product models, prices, concealment methods or instructions for deploying covert surveillance devices.
Warning Signs That May Justify Investigation
Warning signs are contextual. One event rarely proves that a phone, home or vehicle is compromised. A pattern, especially when combined with known access or prior abusive behaviour, may justify a structured assessment.
- A person repeatedly knows your location when you have not told them where you are;
- Private conversations, plans or communications appear to be known unexpectedly;
- Unknown devices, sessions or recovery details appear in important accounts;
- Location sharing or family-account settings do not match what you expected;
- Your phone, computer or account shows unexplained access, configuration changes or unusual permissions;
- An iPhone or Android device produces an unwanted-tracker alert;
- A vehicle, home or personal item contains an unfamiliar electronic device or component;
- A former partner appears soon after you arrive at locations they should not reasonably know about;
- Smart-home devices, cameras, alarms or other connected systems are being controlled by someone else; or
- A person appears to know information that could plausibly come from a linked device, account or surveillance source.
Warning Signs Are Not Proof of Spyware or a Hidden Bug
A person knowing private information does not, by itself, prove that spyware is installed or that a hidden listening device exists. The information may be coming from a shared account, a cloud session, location-sharing feature, another logged-in device, a family mobile plan, social-media activity, a vehicle account, a Bluetooth tracker, another person or a completely non-technical source.
This distinction matters because responding to the wrong hypothesis can both increase risk and destroy evidence. Resetting a phone may remove useful forensic artefacts while leaving the actual account or physical-tracking pathway untouched. Similarly, sweeping a residence will not identify a compromised cloud account unless the digital investigation is scoped to include it.
Three Layers of a Technology-Facilitated Abuse Investigation
1. Device and Account Investigation
This layer addresses smartphones, tablets, computers, cloud accounts, linked devices, messaging platforms, email, location-sharing settings and suspected stalkerware or spyware. Depending on lawful authority and scope, examination may include forensic acquisition, account-session review, timeline reconstruction, indicators of compromise and correlation across multiple devices or services.
See NSI Global Forensic Spyware and Malware Detection and Digital Forensics.
2. Physical Surveillance and Tracking Assessment
This layer addresses hidden cameras, covert microphones, listening devices, GPS trackers, Bluetooth/location-network tags, unauthorised transmitters and other surveillance risks in a home, vehicle or other environment. It may require TSCM methods that go beyond ordinary RF scanning, particularly where a device stores locally, is dormant or communicates intermittently.
See NSI Global Technical Surveillance Counter Measures (TSCM) and Bug Sweeping Services.
3. Evidence, Chronology and Wider Context
The technical findings often need to be interpreted alongside a chronology: protection orders, separation dates, unexpected encounters, tracker alerts, suspicious logins, account changes, photographs, messages, police reports and other evidence. The objective is not simply to find a device; it is to establish what can be supported factually and how the available technical evidence fits the broader matter.
What to Do If You Think You Are Being Monitored
A safe response is more important than a fast response. eSafety and 1800RESPECT both recommend safety planning because changes to technology can be noticed by another person. If it is safe to do so:
- Use a safer device or environment that the person of concern has not had access to when seeking help;
- Write down a chronology of unexplained events, alerts, locations, account changes and relevant dates;
- Preserve screenshots, photographs and identifying information where doing so does not increase risk;
- Avoid factory-resetting, reinstalling apps, deleting suspected spyware or dismantling suspicious devices solely to test a theory;
- Do not confront a person about suspected surveillance if doing so may increase danger;
- If the matter may be evidential, seek police, legal, case-worker or forensic advice before making major changes where that can be done safely; and
- If personal safety requires immediate action, follow police or support-service advice even if that means evidence cannot be perfectly preserved.
| PERSONAL SAFETY OVERRIDES EVIDENCE PRESERVATION Digital evidence can sometimes be reconstructed or corroborated from other sources. Personal safety cannot be replaced. If preserving a device, tracker, account state or suspicious object would expose someone to immediate harm, prioritise safety and follow police or specialist support advice. |
If You Receive an Unknown Tracker or AirTag Alert
Apple and Android now provide unwanted-tracking protections for supported devices. An alert can be important evidence, but it should be interpreted in context. Google notes that turning off Bluetooth, location services or enabling Airplane Mode does not stop the physical tracker itself from reporting its location through the wider tracking network.
Where it is safe, preserve the alert, map or identifying information before taking further steps. If the tracker may be connected with stalking, threats, a protection order or immediate safety concerns, contact police or a specialist domestic-violence service. Avoid treating the tracker as a technical puzzle that must be investigated alone.
Apple Safety Check Can Help – But Changes May Be Noticeable
On supported iPhones, Apple Safety Check can review who has access to information such as location, identify devices connected to the Apple Account, reset app privacy permissions and change account or device security settings. Apple specifically warns users to consider the potential safety and privacy effects before making changes or deleting information.
In a coercive-control or domestic-violence situation, abruptly removing access may alert the other person that something has changed. Safety Check is therefore best used with awareness of the wider safety plan, particularly where separation, stalking or escalating behaviour is already present.
Why Removing Spyware or a Tracker Immediately May Not Always Be the Safest First Step
Finding something suspicious can create an understandable urge to remove it immediately. But there are two separate questions: what is safest right now, and what best preserves evidence. In some matters, uninstalling software, resetting a device, disposing of a tracker or pulling apart a suspicious object can remove information that could later assist police, lawyers or a court.
The opposite is also true: leaving a surveillance pathway in place may be unsafe. There is no universal instruction that fits every domestic-violence matter. The correct response depends on immediate risk, whether police or a support worker is involved, what evidence exists and whether a controlled forensic or TSCM examination can be arranged.
TSCM for Domestic Violence, Family Law and Case-Managed Matters
NSI Global may provide residential and vehicle TSCM support in domestic violence, family law, child safety and related sensitive matters, but these engagements are not accepted directly from private individuals. The matter must be referred or instructed through an appropriate lawyer, law enforcement agency, government department, recognised support organisation, authorised investigator or case officer.
Depending on the authorised scope, TSCM support may include technical inspection for hidden surveillance devices, assessment of potential GPS tracking, hidden cameras, listening devices and related interception risks, and evidence-aware documentation for legal, investigative or protective processes.
This referral model is designed to ensure the engagement is coordinated with the wider legal and safety context rather than treating a domestic-violence matter as an ordinary consumer bug sweep.
Forensic Spyware and Digital Evidence Examination
NSI Global can also conduct authorised digital forensic examinations where a device, account or communications pathway may have been compromised. The scope can include spyware, stalkerware, suspicious applications, persistence mechanisms, account access, cloud evidence, deleted data, communications and relevant timelines.
A forensic examination should not begin with a promise that a device is definitely infected or definitely clean. A defensible finding states what was examined, what was identified, what was not identified, the limitations of the available evidence and whether further work is justified.
A negative result does not prove that a device has never previously been compromised, particularly where software was removed, the device was reset, the relevant artefacts are no longer retained or the monitoring pathway existed somewhere else in the account or device ecosystem.
Technology-Facilitated Abuse Can Involve Children and Shared Family Technology
Children can become part of the technology-facilitated abuse pattern through shared phones, family accounts, tablets, location services, social-media platforms or connected devices. eSafety research based on frontline professionals found technology-facilitated abuse of children in more than one quarter of domestic-violence cases studied, with monitoring and stalking among the most common forms reported.
Where children are involved, device changes, account separation and evidence collection should be considered alongside the child-safety and legal plan. NSI Global accepts child-safety and family-law forensic or TSCM matters only through appropriate authorised referral pathways.
Support and Immediate Help in Australia
| Service | When to Use It | Contact / Resource |
| Emergency services | Immediate danger or risk of harm. | Triple Zero (000). |
| 1800RESPECT | Domestic, family and sexual violence counselling, information and support, available 24/7. | Call 1800 737 732; text 0458 737 732; online chat and video call through 1800RESPECT. |
| eSafety Commissioner | Guidance on technology-facilitated abuse, online safety planning and platform/device safety. | eSafety technology-facilitated abuse resources. |
| Staying Home Leaving Violence (NSW) | Case-managed support intended to help women and children remain safely in their homes or a home of their choice. | NSW Department of Communities and Justice program network. |
| Police / legal representative / case officer | Stalking, protection orders, tracking devices, criminal conduct, evidence preservation or coordinated investigation. | Use the appropriate police, lawyer or case-management channel for the matter. |
When using a phone or computer to seek help, consider whether the person of concern may have access to the device, browser history, phone bill, cloud synchronisation or account. 1800RESPECT recommends using a safer device where possible and planning how to seek support without increasing risk.
How NSI Global Can Assist Through an Authorised Referral
NSI Global can support lawyers, law enforcement bodies, government agencies, recognised support organisations, authorised investigators and case officers managing technology-facilitated abuse matters. Depending on the instruction, an integrated response can combine digital forensics, spyware analysis, TSCM, vehicle or residential technical assessment, cloud and account evidence, investigative analysis and court-focused reporting.
The engagement should be driven by the risk hypothesis rather than by a single product or test. If the concern is unexplained location knowledge, the investigation may need to consider account sharing, phone settings, connected devices, Bluetooth trackers, dedicated GPS devices and vehicle systems. If private conversations appear to be known, the scope may extend across device compromise, account sessions, hidden audio surveillance, smart-home access and other evidence sources.
In domestic violence, family law, child safety, criminal, civil, AVO/protection order or other sensitive legal matters, NSI Global must deal directly with the lawyer, case officer, investigator, insurer, law enforcement body, government agency, recognised support organisation or authorised representative managing the matter.
Frequently Asked Questions
How can I tell if my partner or ex-partner is tracking my phone?
There is no single reliable symptom. Tracking may come from spyware, account access, location sharing, another linked device, a family app, Bluetooth tracker, dedicated GPS device or another source. A safe assessment should begin with the threat model rather than assuming the phone itself is compromised.
Can spyware be installed without me knowing?
Yes. Some spyware or stalkerware is designed to operate covertly, and a person who has had physical or account access may also change settings or install software without obvious signs. However, suspicious behaviour alone does not prove spyware is present.
Can an AirTag or Bluetooth tracker be used to track a person?
Yes. Tracking tags can be misused for unwanted location tracking. Apple and Android provide unwanted-tracking alerts for supported devices, but an alert should be preserved and handled in the context of personal safety and, where relevant, police or legal involvement.
How can I tell if there is a GPS tracker on my car?
A vehicle can potentially be tracked through a dedicated physical device, a vehicle or manufacturer account, a Bluetooth/location-network tag, or another connected service. A professional assessment may therefore need both physical TSCM inspection and digital/account review.
Can someone see my location through my Apple or Google account?
Potentially, if location sharing, family features, a linked device or unauthorised account access gives that person visibility. Account and sharing configuration should be reviewed carefully, with safety planning where changes may be noticed.
Should I uninstall spyware if I find it?
Not automatically. Removal may be appropriate for safety, but it can also destroy evidence or alert another person. If there is immediate danger, prioritise safety and follow police or specialist support advice. If safe, seek forensic or legal guidance before making major changes.
Can a forensic examination prove that spyware was installed?
Sometimes it can identify the spyware itself or supporting artefacts, persistence mechanisms and indicators of compromise. A negative examination does not prove that a device has never been compromised, particularly if relevant evidence has been removed or aged out.
Can NSI Global sweep a home or vehicle for hidden surveillance devices?
NSI Global may provide residential or vehicle TSCM in domestic violence, family law, child safety and other case-managed matters, but not as a direct private consumer service. These matters must be referred or instructed through an appropriate lawyer, law enforcement body, government agency, recognised support organisation, authorised investigator or case officer.
Who can engage NSI Global for a domestic-violence TSCM or forensic matter?
NSI Global requires an authorised instruction pathway. In sensitive personal-safety matters, the organisation deals directly with the lawyer, case officer, investigator, insurer, law enforcement body, government agency, recognised support organisation or other authorised representative.
Can digital evidence be used in family-law or criminal proceedings?
Digital evidence can be relevant in legal proceedings, but its admissibility and weight depend on the circumstances and applicable law. Forensic preservation, documented acquisition, chain of custody, hashing where appropriate and clear reporting can help establish integrity and provenance.
Sources and Further Reading
- eSafety Commissioner – About technology-facilitated abuse – Defines technology-facilitated abuse and identifies warning signs such as cyberstalking, monitoring, account access and unexplained location knowledge.
- eSafety Commissioner – I may be experiencing tech-based abuse – Safety-planning and support guidance for people who may be experiencing technology-facilitated abuse.
- NSW Crime Commission – Project Hakea – Australian evidence on unlawful tracking devices and their use in domestic and family violence, including post-separation tracking.
- 1800RESPECT – Technology and safety – Guidance on safer devices, digital trails, Quick Exit and obtaining support safely.
- Apple Support – Safety Check – Explains Safety Check and warns users to consider safety impacts before changing sharing or access.
- Google Android Help – Find unknown trackers – Guidance on unwanted tracker alerts and the limits of turning off Bluetooth, location or Airplane Mode.
- NSW Government – Staying Home Leaving Violence – NSW case-managed program supporting women and children experiencing domestic and family violence.
- NSI Global – Technical Surveillance Counter Measures – NSI Global TSCM capabilities and authorised referral requirements for residential and domestic matters.
- NSI Global – Forensic Spyware and Malware Detection – NSI Global spyware, stalkerware and malware forensic capability.
- NSI Global – Digital Forensics – NSI Global lawful-authority framework and digital forensic capability for family law and domestic-violence matters.