Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


Cyberstalking is repeated unwanted attention, harassment, or monitoring carried out through digital services or devices. It can involve threatening messages, account access, location tracking, or attempts to contact you after you have asked someone to stop. Your first response should fit your safety situation; immediately blocking accounts or resetting a phone is not always the safest starting point.[1]
Key Takeaways
- Assess immediate danger before changing settings or gathering evidence.
- Suspicious behavior is a reason to investigate carefully, not proof of one particular tracking method.
- Use a safer device for help if your usual device may be monitored.
- Preserve a pattern of events and plan account or location changes around your safety.
A personal privacy review across accounts and devices can identify routine exposures. When harassment is involved, however, the order of actions matters as much as the settings themselves.
Cyberstalking signs can include repeated contact from new accounts, threats referencing private information, impersonation, unwanted publication of personal details, and someone seeming to know where you have been. eSafety describes online stalking as a pattern that can overlap with offline abuse and coercive control.[1]
An isolated unfamiliar sign-in, battery drain, or location coincidence does not identify a stalker or prove surveillance software is installed. These clues may have other explanations. Record what you actually observe, then compare it with account notifications, sharing settings, and the wider pattern of contact.
A person does not need sophisticated software to learn private details. Shared calendars, cloud accounts, family location services, reused passwords, unlocked devices, and public posts can all expose information. The different ways online tracking works help separate advertising tracking from targeted harassment; their purposes and response paths differ.
Risk signals that deserve prompt support include credible threats, unwanted visits, escalating contact after a boundary, account takeover, and references to information that should not be available to the person. Do not wait for a perfect technical explanation before asking for help.
Your uncertainty should stay visible in the evidence. “The message mentioned my appointment” is an observation. “The phone contains spyware” is a conclusion that requires additional evidence. Keeping those statements separate helps a support worker or investigator assess multiple possible exposure routes.
Choose the path that best fits the immediate risk. These paths can overlap, but a technical checklist must not take priority over physical safety.
| Situation | Safer first priority | Avoid treating as an automatic first step |
|---|---|---|
| Immediate danger or credible threat | Reach local emergency help and a safer place if possible | Staying online to finish an evidence collection task |
| Your device may be monitored | Seek help using a device or account the person cannot access | Removing apps, resetting the device, or confronting the person without a plan |
| Repeated online harassment without immediate danger | Preserve a pattern, review reporting options, and plan boundaries | Arguing with every new account or publicly exposing alleged identities |
A safer device might belong to a trusted person or support organization. Avoid signing into an account the suspected person can access merely because the device itself is different. Shared email, cloud storage, and message synchronization can bring the same exposure onto another device.
Private browsing does not make a monitored device safe. It mainly changes local browsing-history behavior, not what installed software or an account holder may observe. If you are unsure, use specialist support to plan a communication method rather than relying on a browser mode.
Consider whether changing access would be noticed. Apple's personal safety guidance explicitly asks readers to consider safety implications before changing or deleting information.[2] A notification, loss of location sharing, or sudden sign-out can reveal that you are taking action even when the setting change itself is technically correct.
Useful cyberstalking evidence shows context and repetition. Keep dates, times, account identifiers, profile addresses, message contents, and relevant incident descriptions. Include the platform and time zone where possible, especially when several services are involved.
Do not collect evidence by provoking the person or arranging an unsafe meeting. Do not download or redistribute sexual content involving minors. Ask the appropriate service how to report that content without creating another copy.
If collecting or storing records would put you at greater risk, safety takes priority. A support organization can help decide whether another person should preserve material, whether a different device is needed, and what can reasonably be recorded now.
Evidence does not have to be technically perfect before you seek support. A short, accurate timeline is often more useful than a large folder of unexplained screenshots. Avoid editing original images to improve readability; make a separate annotated copy if explanation is needed.
Cyberstalking protection requires identifying the actual access route. A password change addresses one route; it does not automatically change a shared calendar, another signed-in device, an app permission, or a family location service.
After planning the safety implications, review recovery email addresses and phone numbers, active sessions, trusted devices, shared content, and location permissions. Check services separately rather than assuming one account's settings govern every device and platform.
On supported iPhones, Apple offers Safety Check to review sharing with people and apps, connected devices, and account security. It requires iOS 16 or later and an Apple Account using two-factor authentication; some restrictions can limit available options. Consult the official instructions for your device rather than assume every phone has the same control.[2]
Safety Check also has limits: it does not review all non-Apple accounts, social-media sharing, or every other device.[2] If a person knew your location from a separate messaging app, changing an Apple setting alone may not close that route.
If you suspect surveillance software, explain the concern to a qualified support service before uninstalling or resetting. Removing something can change what the other person sees and may erase evidence. A clean scan is not proof that all account-based monitoring or shared access has ended.
Families should apply the same care to children's shared accounts and location settings. The family framework for safer internet use addresses communication and account ownership without assuming that constant monitoring is always protective.
An IP address is one exposure route, not a complete picture of location or identity. Websites you contact can receive a connection's public IP, while a harasser may obtain location information through an entirely different source such as a shared account, a post, or device access.
For the narrow question of reducing public IP exposure to websites, AethoVPN's global mode encrypts and forwards application traffic through the VPN. That network role does not turn off GPS sharing, remove surveillance software, revoke another person's account access, or guarantee protection from stalking.
Do not let a change in the visible IP create false reassurance. Verify the specific sharing or access route you identified, and keep any VPN use within local law and service rules. Installing a network tool on a device the person monitors may itself be visible, so the earlier safety assessment still applies.
This boundary also prevents misdiagnosis. A person knowing your neighborhood does not prove they obtained your IP, and an unfamiliar sign-in location does not prove they are physically nearby. Treat IP-related information as one clue within the broader incident record.
Use the platform's reporting tools and preserve report references, but assess whether blocking or reporting could change the person's behavior. A specialist in technology-facilitated abuse can help plan the timing when a current or former partner is involved.
Contact local police or a victim-support service where threats, stalking, or other harm warrant it. Laws, evidence requirements, and reporting routes differ by jurisdiction. eSafety's formal complaint pathways are Australian; readers elsewhere should use the relevant local equivalent rather than assume the same eligibility.[1]
Choose a trusted person who can help with practical tasks, such as keeping a record or accompanying you to an appointment. Agree on a communication method that does not expose the plan. Do not publicly accuse someone based solely on a technical clue or recruit strangers to investigate them.
Follow up on the routes you changed: whether a session remains revoked, whether location sharing stopped where intended, and whether a recovery contact is still yours. Review after meaningful account or device changes. A safer setup is maintained through specific checks, not through a claim that one tool has made you untraceable.
If you suspect physical tracking, follow the steps to detect an AirTag or Bluetooth tracker; if personal details are being published, see how doxxing works and how to respond.
No. A repeated pattern, context, threats, and monitoring behavior matter. An isolated message may still warrant a platform report, but the legal definition of stalking depends on your jurisdiction. Seek help without waiting to settle the legal label yourself.
No. Battery drain has many ordinary causes. Record it alongside other observations, but do not identify a person or a surveillance tool from that symptom alone. Use qualified help if the wider pattern suggests monitoring.
Not automatically. A reset may remove records, fail to address shared accounts, or alert the person to a change. Assess safety and evidence needs first, particularly when abuse or coercive control may be involved.
It is not a guarantee on a monitored device. Device software, shared accounts, and synchronization can expose activity outside ordinary browser history. Consider a safer device and communication channel with specialist support.
No. Blocking can be useful, but the person may switch accounts or escalate offline contact. Preserve what you safely can and consider the context before changing boundaries. Immediate threats require local emergency help.
No. Network IP privacy is separate from GPS permissions, family location services, shared accounts, and surveillance software. Review the route that actually exposes information rather than assuming a network connection controls every form of tracking.
Yes. An accurate description of what happened and your immediate concerns can start a support conversation. Do not remain in danger to collect a perfect record. Ask the receiving organization what additional material is useful and safe to preserve.
Disclaimer: This is general safety information, not legal advice or a personalized safety plan. eSafety reporting routes are Australian and Apple controls are platform-specific. Use local emergency and victim-support services appropriate to your country or region; legal definitions and procedures vary.
Sources:
Sources checked 5 October 2026.
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.