
When someone gains access to a personal account without clear, ongoing permission, it can feel like a major violation. Whether it happens through password-sharing, hacking, spyware, or guesswork, unauthorised access can lead to emotional harm, identity theft, or further control.
When someone gains access to a personal account without clear, ongoing permission, it can feel like a major violation. Whether it happens through password-sharing, hacking, spyware, or guesswork, unauthorised access can lead to emotional harm, identity theft, or further control.

This type of abuse may involve reading private messages, deleting content, impersonating us, or changing account settings to limit access. In some cases, it’s part of a larger pattern of digital surveillance or coercive control.
Even if the person accessing the account is someone familiar—a partner, family member, roommate, or friend—it’s still a form of digital abuse. No one should have to give up privacy to stay safe, loved, or connected.
This section is for you if you’ve been pressured or forced into sharing your account passwords with someone, or been locked out of your own accounts. You might have found passwords or settings changed without your knowledge, seen unexpected changes to saved files or account recovery information, or had strange login alerts or security warnings you don’t recognise.
You might be feeling like your identity isn’t your own, and powerless to stop someone who always seems to be ahead. You might be ashamed—even though you didn’t do anything wrong—or confused about whether it’s really happening. The information in this section can help.
There are many ways someone can gain access to an account without permission. The most common methods involve emotional manipulation—like pressuring us to share passwords or pretending to act in our best interest. Other less common methods are technical, like hacking or installing spyware.
Having an account accessed without consent can feel like a loss of control—but unfortunately, it’s also incredibly common. Even if it feels personal or targeted, many tactics are widespread and used against countless people. There is no shame in being caught off guard by someone else’s intrusion. Here are some of the ways it can take place.
Accessing our accounts on a phone, laptop, or tablet we once had access to—or that was set up while in a relationship.
Someone resetting our passwords, changing recovery emails or phone numbers, or enabling 2FA using their own device.
Using apps or software that secretly record keystrokes, take screenshots, or capture login details. These tools generally run invisibly in the background, but although they do exist and it’s important to be aware of them, this approach is much less common.
Unauthorised access doesn’t always start with hacking. Sometimes it’s a password shared in trust, that’s later used to control or monitor. Sometimes it’s someone staying logged in on a shared device, guessing a password, or resetting one without our knowledge. And sometimes, it’s not clear how it’s happening—just that someone keeps showing up in places they shouldn’t.
It’s normal to feel unsure, especially when the access comes from someone close. And it’s normal to feel upset, confused, angry, or anxious, even if we don’t have proof. If something doesn’t feel quite right, that’s reason enough to start looking into it.
We don’t need to have everything figured out to take action. Even small changes can help rebuild privacy and control. And no matter who accessed our account, or how—it’s not our fault.
AI is changing the way accounts are accessed and abused. In the past, someone might have needed passwords or direct access to a device. Now, AI tools can help people guess login details, impersonate others, or even bypass security checks—sometimes without needing much technical skill at all.
AI can make these tactics feel more advanced—and the pace of change can be overwhelming. It’s natural to feel confused or unsure how to keep up. We’ve listed out some of the ways AI is making unauthorised access easier, but remember: while the tools may be new, the behaviours are often familiar. At their core, these tactics are still about control, surveillance, and broken trust.
And just like before, survivors deserve support, autonomy, and digital safety—no matter how the technology evolves.
AI models can now rapidly guess common passwords or security question answers based on personal information scraped from social media, data breaches, or public profiles. This makes weak or reused passwords far easier to exploit.
AI-generated voice clones or deepfake videos can be used to trick others—or even automated systems—into granting access. For example, someone might fake a voice to bypass a phone verification step, or send a deepfake video asking a contact to share a login.
AI can write convincing messages that sound like they’re from someone familiar. These can be used to pressure people into sharing login info, clicking unsafe links, or giving up two-factor authentication codes.
AI helps attackers quickly search through leaked databases to find old login details—then test them across different platforms. If the same password is used more than once, it only takes one breach to open many doors.
Some stalkerware and spyware apps are now using AI to sort through captured data—flagging messages with specific keywords, recognising patterns, or sending alerts when certain content appears. This makes the digital abuse more targeted and harder to notice.
Some impersonators or scam accounts use AI to sound convincing—mimicking trusted contacts, copying writing styles, or creating urgent messages designed to steal login details.
The clues that once helped us spot AI-generated content aren’t always reliable any more. Things like extra fingers in photos or blurry edges around objects were once common signs, but new tools are improving fast.
Instead of relying on those glitches, it’s more helpful to look at the bigger picture. These are some helpful questions to ask:
Trusting your instincts, asking questions, and slowing down can all help make sense of what you’re seeing or hearing.
Discovering that someone has accessed a personal account without permission can feel violating, disorienting, or frightening. Some people describe a deep sense of exposure—like their private thoughts or identity were no longer theirs. Others feel anxious, betrayed, or unsure who to trust.
We all respond in different ways, and that’s okay. Here are some reflections and questions survivors often share.
No. Consent is not permanent. Even if access was once given freely, it can be withdrawn at any time. Continuing to access an account after consent is withdrawn is still a violation.
Reading private content without permission can be just as harmful as deleting or altering it. It’s a form of surveillance, and it can affect a person’s sense of safety and autonomy—even if nothing was visibly changed.
Abusers often justify digital control by claiming it’s about safety, love, or concern. But real care respects boundaries and privacy. No one should have to give up their digital autonomy to feel secure in a relationship.
It’s okay to trust that instinct. Digital access can be subtle—someone might know things they shouldn’t, or mention private details without explanation. You don’t need concrete proof to seek support or start setting boundaries.
It’s common for people to stay logged in on shared or previously used devices, especially in relationships where trust was expected. Realising someone is using that access without consent can feel like a betrayal—but it’s not your fault.
That fear is valid. If someone has accessed accounts once, it’s natural to worry about future breaches. Taking steps like updating recovery info, checking device logins, and enabling two-factor authentication can help rebuild a sense of control—and support is available to walk through those steps.
No one can fully control whether someone tries to access their accounts—but small steps can help limit opportunities for intrusion, make accounts harder to compromise, and support a greater sense of digital control.
Taking these steps can be exhausting—both emotionally and practically. It’s okay to move at your own pace and choose only the steps that feel manageable right now. No one should have to manage this alone. Support is available, and you deserve safety, privacy, and peace of mind.
It’s okay to say no to sharing accounts, passwords, or devices—even with someone you trust. Questions like “Who will be able to see this?”, “What happens if we stop sharing this account?”, or “Can I remove access later?” can help clarify expectations. If someone pressures, guilts, or threatens you into giving access—that’s not about trust. That’s a form of control.
Finding out that someone has accessed a personal account without consent can be upsetting, confusing, and difficult to trace. Whether the access happened recently or over time, support is available—and there are steps that can help us regain control.
Most websites and apps allow users to report unauthorised access, impersonation, or harassment. Look for ‘security’ or ‘privacy’ options in settings.
If unauthorised access to your accounts is part of a larger pattern of abuse, stalking, or coercive control, it may be considered a criminal offence. In many places, you can report it to your local police or a national cybercrime or online harm reporting service, depending on the laws in your area.
If someone is using account access to harass or impersonate a person at work or school, then internal safeguarding or HR teams may be able to help.
This section explores someone accessing your accounts without your permission. This might happen through password sharing, guesswork, spyware, or emotional manipulation. It explains how account intrusion can feel like a loss of control, even when there’s no evidence we can see. It also includes practical prevention strategies, documentation tips, and ways to reset access and rebuild digital boundaries.
Account access without ongoing consent is a form of digital abuse.
The most common methods for unauthorised account access involve emotional manipulation.
Shared logins and saved devices are common ways someone can access your accounts.
AI tools can also be used to guess passwords or to pretend to be a person or organisation you trust.
We can take back control of our accounts by adjusting settings, protecting private information, and setting boundaries.
There are steps we can take if we decide to report.
Taking back control over digital accounts can feel intimidating—no one should have to do it alone. If the situation feels unclear or overwhelming right now, then this guide, and the support options listed on the previous page are here to return to at any time.
PimEyes is a face search engine that lets you upload a photo to see where else that face appears online. It can help check whether someone’s image is being used on other websites or profiles—but note that it may not find everything, and the results can be mixed.
Try PimEyes for yourself
You can learn more about an image or an object with Google Lens. For example, you can take a photo of a plant and use it to search for information or similar images.
Find out more about Google Lens
A password manager is a secure app that stores all your login details in one place, so you don’t have to remember them yourself. It can create strong, unique passwords for each account, and automatically fill them in for you when needed.
Find out more about password managers
Two-factor authentication (2FA) adds an extra layer of security by asking for two things before leting you into an account. The first is something you know (like a password), and the second is something you receive (like a code sent to your mobile phone). Even if someone guesses your password, they won’t be able to log in without that second step.
A hash is a digital fingerprint of an image—a unique code created from the image’s data. Once an image is hashed, platforms can use that code to detect and block exact matches, even if the image’s file name or location changes.
Autofill is a browser or app feature that automatically fills in saved information (like names, addresses, or passwords) when you visit a website or log into an account. While convenient, it can also give others access to your personal details if they use the same device.