Spyware Concerns? Here’s How to Safeguard Your Phone and Computer

A First-Response Guide to Personal Safety, Evidence Preservation and Forensic Scope

By Navid Sobbi, Founder and CEO, NSI Global

ORIGINAL PUBLICATION: 26 September 2023 SUBSTANTIVE REVISION: 9 September 2026 (AEST)

IMPORTANT NOTICE — PERSONAL SAFETY AND EVIDENCE PRESERVATION

If you believe a phone, computer, tablet, smartwatch, vehicle or connected account may be subject to illegal surveillance, pause before changing it. Do not uninstall suspected software, factory reset the device, install consumer removal tools, delete accounts or make unnecessary changes if the device may contain evidence. Those actions may alter or destroy information relevant to a court, police, employment, regulatory or other authorised investigation.

If another person may react dangerously when access is interrupted, personal safety comes first. Use a separate trusted device and safe location to contact emergency services or a recognised support organisation. Do not confront the suspected operator through a potentially monitored device.

Australia: Emergency 000 | 1800RESPECT 1800 737 732 
UAE: Police 999 | Ambulance 998 | Dubai Foundation for Women and Children 800 111 
NSI Global Australia: 1300 000 NSI (674) | UAE: +971 (0)4 409 6824

Suspected spyware creates two risks at once. The surveillance may continue, but an impulsive attempt to stop it can alert the suspected operator, change the device or remove the evidence needed to establish what occurred. The safest response is therefore not a universal sequence of settings changes. It is a controlled decision about the outcome that matters most.

This guide explains what to do before altering a suspected device, how to establish a safe communication channel and what an appropriately scoped forensic response may examine. It applies to phones, computers and associated accounts. Detailed platform controls are covered separately in NSI Global’s Android spyware guide and iPhone Lockdown Mode guide.

First Decide What You Need to Protect

The same action can be sensible in one situation and harmful in another. Before changing the suspected device, identify the primary objective.

Situation Immediate objective Actions to avoid until advice is obtained
Personal safety or coercive control Reach a safe place and trusted support without alerting the suspected operator Confrontation, visible account changes or remediation without a safety plan
Potential evidence for court, police or an authorised investigation Preserve the device, associated records and handling history Uninstalling, resetting, updating, deleting data or extensive self-investigation
Corporate or executive compromise Activate legal, security and incident-response authority Routine support handling or an ungoverned remote-wipe instruction
General prevention with no suspected incident Apply current security controls and account protection Assuming one scan or setting can exclude every surveillance method

 

When more than one objective applies, decisions should be coordinated. A company may need to contain an active incident while preserving evidence. A person experiencing technology-facilitated abuse may need to prioritise immediate safety even though a device could contain valuable evidence.

Use a Separate Trusted Communication Channel

A potentially monitored device may expose calls, messages, searches, location and newly entered passwords. Private-browsing mode does not prevent device-level or account-level surveillance.

Where practicable, communicate from a phone or computer that the suspected person has not accessed and cannot access. Use a safe location and a network that is not controlled by the suspected operator. Depending on the circumstances, contact may appropriately be made with:

  1. Emergency services or a recognised domestic and family violence support organisation;
  2. A lawyer, police officer, case officer or authorised investigator;
  3. An employer’s legal, security or incident-response team;
  4. A government agency, insurer or authorised representative; or
  5. NSI Global for an eligible corporate, legal or otherwise authorised engagement.

Do not assume the suspected device must always be switched off, disconnected or placed in a radio-frequency shielding pouch. Those measures may reduce connectivity in some circumstances, but they can also change device state, interrupt useful observation or cause an operator to react. The handling decision should follow risk triage, lawful authority and the evidentiary objective.

Record the Concern Without Conducting Your Own Investigation

Useful context can be recorded from memory or on a separate trusted device. Note:

  1. Why surveillance is suspected;
  2. Dates, locations and relevant incidents;
  3. Private information another person appeared to know;
  4. Who had physical access to the device or knew its passcode;
  5. Unexpected sign-in, recovery, location-sharing or security alerts;
  6. Unusual applications, permissions or account sessions already observed;
  7. The device model and the principal accounts associated with it;
  8. Whether the device is personally owned, employer-owned or shared;
  9. Actions already taken, including scans, reboots, updates or password changes; and
  10. Whether police action, litigation, employment proceedings or a protection order may be foreseeable.

This information helps define scope. It does not require repeatedly opening suspicious applications, searching through system files or testing whether another person reacts to a change.

What Not to Do When Evidence or Safety May Be Involved

Until an appropriate response pathway has been chosen, avoid:

  1. Uninstalling or disabling a suspicious application, service, administrator or management profile;
  2. Factory resetting, trading in, repairing or discarding the device;
  3. Installing several consumer “spyware detector” or cleaning applications;
  4. Deleting messages, logs, cloud content, accounts or linked sessions;
  5. Changing passwords on the suspected device;
  6. Moving a SIM, restoring a backup or transferring the device’s contents without considering the effects;
  7. Allowing a general repair provider or help desk to make undocumented changes;
  8. Confronting the suspected operator; or
  9. Treating battery drain, heat, unusual behaviour or a clean security scan as proof of compromise or absence.

If a protective action cannot wait, record what was done, when, why and by whom, provided it is safe to do so. Photographs and contemporaneous notes recorded elsewhere can help establish context, but formal preservation remains necessary.

Spyware May Not Be Located on the Suspected Device

“Spyware” is often used as shorthand for any unexplained surveillance. The actual pathway may instead involve:

  1. A compromised Google, Apple, Microsoft, email or messaging account;
  2. An active session on another device;
  3. Shared passwords, recovery methods or cloud backups;
  4. Legitimate family, workplace or device-management tools used without authority;
  5. Location sharing, Bluetooth trackers, vehicle systems or smart-home devices;
  6. Malicious applications or abused accessibility and administrator permissions;
  7. Remote support software, browser extensions or altered network settings; or
  8. Sophisticated exploitation that leaves few user-visible indicators.

A narrow scan of one handset can therefore miss the relevant channel. The scope should follow the credible risk profile: devices, accounts, cloud services, enterprise records, connected systems, relevant people and the period under examination.

What an Authorised Forensic Response May Involve

1. Authority and Purpose

Establish who owns the device and accounts, who can lawfully authorise examination and what decision the findings must support. Authority may differ for a personal device, employer-owned system, mixed-use handset, deceased estate, criminal matter or civil dispute.

2. Risk Triage

Assess danger to people, indications of continuing access, exposure to remote deletion, commercial impact, legally privileged material and time sensitivity. Select whether the device should remain operational, be isolated or move into controlled handling.

3. Preservation and Custody

Document the device’s condition, identifiers, date and time, visible state, actions already taken and transfer of custody. Relevant cloud, identity, email, mobile-device-management or network records may also require preservation.

4. Proportionate Acquisition and Examination

Available methods depend on the device, operating-system version, security state, encryption, condition and lawful authority. Examination may address installed software, permissions, configuration, accounts, sessions, logs, application data, network indicators and timeline relationships.

5. Validation and Reporting

Findings should distinguish observed facts, technical inference and unresolved uncertainty. A useful report explains the commissioned scope, methods, relevant findings and limitations. It should not convert “nothing identified within scope” into a guarantee that a device is clean.

6. Containment and Recovery

After safety and preservation requirements are addressed, recovery may include trusted-device credential changes, session revocation, application removal, security updates, device replacement, factory reset or monitoring. The appropriate combination depends on the findings and risk.

What a Forensic Examination Can and Cannot Establish

Depending on the available evidence, an examination may identify suspicious software or configuration, relevant permissions, installation or activity artefacts, account indicators and evidence supporting a timeline. It may also show that the most credible surveillance pathway sits outside the device originally suspected.

No examiner should promise detection of every surveillance method, complete recovery, definitive attribution or a particular legal outcome. Results remain limited by the agreed scope, device state, available records, elapsed time and the capabilities of the surveillance method involved.

For corporate, legal and authorised matters, NSI Global’s Forensic Spyware and Malware Detection service can examine relevant devices and indicators within an agreed scope. Where mobile-device concerns form part of a broader compromise, Digital Forensic Incident Response can correlate device evidence with identity, email, cloud, endpoint and other incident artefacts. Matters involving anticipated proceedings may also require coordinated Litigation Support.

Before Contacting NSI Global

Use a separate trusted device or communication channel. Be ready to explain:

  1. The type and ownership of each relevant device;
  2. The suspected surveillance behaviour and timeframe;
  3. Who may have had physical or account access;
  4. Whether personal safety is at risk;
  5. Whether legal proceedings, police involvement or workplace action are foreseeable;
  6. What changes have already been made; and
  7. Which devices, accounts, cloud services or organisational records may require examination.

NSI Global’s current engagement conditions and lawful-authority requirements apply. For sensitive private matters—including domestic violence, child safety, alleged criminal conduct, civil disputes or protection orders—NSI may require the instruction or referral to come from a lawyer, police officer, case officer, government body, insurer, recognised support service or another authorised representative.

Frequently Asked Questions

Should I Turn Off the Suspected Device?

Not automatically. Disconnection may reduce exposure in some cases, but it can also change device state, interrupt evidence sources or alert an operator. Obtain incident-specific advice where practicable. Personal safety takes priority.

Should I Change My Passwords Immediately?

If the suspected device may capture activity, do not enter replacement credentials on it. Use a separate trusted device and consider associated recovery methods and active sessions. Where evidence or organisational response is involved, coordinate the timing of account changes.

Does a Clean Security Scan Mean There Is No Spyware?

No. A clean result is limited to the control, signatures, device state and activity it could assess. It does not exclude account compromise, linked sessions, surveillance outside the device or every sophisticated technique.

Can NSI Global Guarantee Who Installed Spyware?

No. Artefacts may support findings about software, accounts, activity and timing, but attribution can remain uncertain. Conclusions must reflect the strength and limitations of the evidence.

Safeguard the Person, the Device and the Evidence

The first response to suspected spyware should be controlled rather than reactive. Establish a safe channel, identify the objective, preserve what may matter and ensure the examination scope covers the credible surveillance pathways. Remediation should follow the safety and evidentiary decision—not erase the opportunity to understand what occurred.

For an eligible corporate, legal or authorised matter, contact NSI Global from a separate trusted device.

Sources and Further Reading

  1. 1800RESPECT: Device safety
  2. Australian eSafety Commissioner: Domestic and family violence and technology safety
  3. Google: Secure a hacked or compromised Google Account
  4. Apple: If you think your Apple Account has been compromised
  5. UAE Government: Handling emergencies

Secure your peace of mind