Quasa
Use QUASA App
Join the pioneer of Web3 crypto freelancing today!
Open
Work

Women Facing Digital Abuse: Why Resetting a Phone Can Raise the Risk

|Updated: |Author: QUASA Editorial Team|6 min read| 2124
Women Facing Digital Abuse: Why Resetting a Phone Can Raise the Risk

Digital safety for women facing abuse is not simply a matter of choosing stronger passwords. When a partner, ex-partner or stalker may control a phone or account, an immediate reset can reveal that access has been discovered, erase useful evidence and provoke escalation. The FTC’s June 2026 stalkerware guidance therefore recommends considering personal safety, contacting an advocate from another device and documenting abuse before changing the suspected phone.

The threat has also moved beyond conventional account theft. A 2025 survey of women working in journalism, activism, human rights and public communication found online attacks involving surveillance, doxxing, image-based abuse and AI-generated material; 41% of respondents connected online violence with offline harm. The UN Women evidence brief also found that 23.8% of respondents who answered the relevant question reported AI-assisted abuse, though its purposive sample should not be treated as representative of all women.

Begin with the person who may have access

A useful safety plan starts by asking who presents the risk, what they can reach and how they might react. Generic cybersecurity advice assumes an unknown criminal outside the account. Technology-facilitated abuse may instead involve someone who knows recovery answers, shares a mobile plan, has handled the device, can enter the home or receives alerts from connected services.

Look for a pattern rather than treating one symptom as proof of spyware. Unexpected knowledge of private conversations, accurate location information, unfamiliar account sessions, changed recovery details or unexplained access to shared photos can indicate several possible routes. The cause might be a compromised email account, location sharing, a family-plan feature, a connected vehicle, a cloud backup or physical access to an unlocked phone.

If there is an immediate danger, personal safety takes priority over investigating the technology. Move to a place and device the suspected person cannot access, and contact an appropriate local emergency service, domestic-violence organization or trusted advocate. A work computer is not automatically safe if an employer monitors it or the abuser can reach workplace accounts.

Use a safer device before changing anything

A safer device is one the suspected person has not controlled physically or remotely. It might be a trusted friend’s phone, a library computer or a newly obtained device connected through an account the other person does not know. Do not sign that device into an old cloud profile if doing so would restore shared settings, synchronized credentials or monitored applications.

From the safer device, make a small response plan before taking visible action:

  1. Write down which accounts, devices and services may be exposed, beginning with email and the mobile account because they often control password recovery.
  2. Decide what evidence needs to be preserved and where a protected copy can be stored.
  3. Identify a safe contact method and a trusted person or specialist who can help assess the risk.
  4. Choose the order for account changes, device replacement, platform reports and any contact with authorities.

This sequence matters because changing one password can trigger an email, text message or in-app notification on another device. Removing a tracker, disabling location sharing or closing a shared account may likewise tell the abusive person that access has been detected. There is no universally safe order; it depends on the person’s access and likely response.

Preserve evidence before blocking or reporting

Documentation can establish a pattern that an isolated screenshot cannot. Record the date, time, platform, account name, URL or phone number, what occurred and any related offline event. Where safe and lawful, retain screenshots, original messages, voicemails, emails, call logs and notifications without editing the originals.

Keep copies somewhere the suspected person cannot reach. A new email address created on a safer device, encrypted storage controlled only by the survivor, or a copy held by a lawyer or advocate may be appropriate depending on the circumstances. Avoid storing the only copy in the same phone, shared cloud folder or family account under investigation.

Capture evidence before reporting content to a platform because moderation may remove the post or account. For impersonation, manipulated sexual imagery or other image-based abuse, record both the content and its distribution context: usernames, links, timestamps, search results and messages showing threats or demands. Do not repeatedly download or circulate harmful imagery when a screenshot or specialist-assisted record will suffice, especially if a minor may be depicted.

Secure accounts in a deliberate order

Once a safer access route and response plan are in place, protect the email account used for recovery first, followed by the mobile-provider account, financial services, cloud storage, social platforms and workplace tools. Review recovery addresses, telephone numbers, active sessions, connected applications, forwarding rules and trusted devices. A new password is ineffective if an unknown session remains active or a recovery channel still belongs to the other person.

Authentication advice has advanced since older password-only checklists. In April 2026, the UK’s National Cyber Security Centre made passkeys its preferred consumer sign-in method where supported; the NCSC’s current recommendation is to use a password manager and two-step verification when passkeys are unavailable.

Passkeys reduce exposure to password theft and phishing, but they do not solve every abuse scenario. Before enabling one, confirm which devices will hold or synchronize it and whether the suspected person controls the relevant Apple, Google, Microsoft or other platform account. On services without passkeys, use a unique password generated by a password manager and choose a second factor the other person cannot receive.

Treat the phone as one part of a connected system

A factory reset may remove some malicious software, but restoring the same backup can restore an unwanted application or reconnect compromised settings. If replacement is feasible, set up the new device with protected accounts and freshly downloaded applications. Preserve the old phone only if doing so fits the safety plan and evidence requirements.

Then inspect the wider system: shared tablets, smart-home devices, wireless cameras, Bluetooth accessories, vehicles, wearable devices, family subscriptions and location-sharing services. Check which people and accounts have administrative privileges. Unexpected battery drain or data use can justify further investigation, but neither symptom proves that stalkerware is present.

A compact plan for lower-risk situations

Not every problem involves an abusive person with physical access. For routine harassment, phishing or an exposed password, the response can usually be more direct: preserve abusive messages, block and report the sender, secure the affected account, update the device and reduce unnecessary public information.

  • Use passkeys where they are available and safely controlled.
  • Give every remaining account a unique password and enable two-step verification.
  • Review privacy, location and audience settings after application updates.
  • Remove obsolete connected applications and end unfamiliar sessions.
  • Keep personal and public-facing identities separate when visibility creates a credible risk.

The central distinction is whether the threat is merely technical or tied to coercive control, stalking or offline access. In the latter case, the fastest-looking technical fix may not be the safest first action. Planning on a separate device, preserving evidence and then making coordinated changes gives the woman affected more control over both her digital accounts and the consequences beyond the screen.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0