Seven stories on electronic abuse — how it happens, when it's a crime, and the resources that can and can't help.
You may think of electronic abuse as stalking or revenge porn. If you have experienced it, you know it's more than that. It's account access, account blocking, financial abuse, isolation from friends and family, the destruction of records, the theft of your identity, and the introduction of total havoc into your life, to name a few.
As technology's presence has increased in our lives, the ways it can be used to abuse have increased as well. There is a term for this sort of abuse — it is “technology-facilitated coercive control” (TFCC).
TFCC is both uniquely destructive and uniquely challenging to stop in the context of marital relationships, or any partnership where both parties live in the same home.
A spouse has access to your electronics in a way that no one else does. They also have access to the information that is routinely used to bypass security measures designed to protect you from strangers — they know, for example, your social security number and your mother's maiden name. They may, indeed, even have your passwords because sharing passwords is a practice that is entirely normal between spouses.
This issue is about the sorts of practices that are used and the harms they can cause, and how, if you find yourself a victim of this sort of abuse, the practices and resources that will help you, and those that will not.
I have experienced electronic abuse and I will not sugarcoat it — the effects can be devastating and leaving your abuser is often your only choice. And even leaving cannot protect you completely. This is one downside of an increasingly connected, technological world.
Hopefully this issue will help you identify abuse, mitigate the harm to your life and find resources that can help you. And, importantly, know that you are not alone.
Before we consider technology at all, the specific nature of the abuse — coercive control — the C's in TFCC — matters. It is often hidden, doesn't always involve physical violence, and grows gradually over time, making it difficult to recognize. The abuse is often inconsistent, mixing controlling actions with loving and conciliatory behavior.
Ultimately, however, TFCC can produce what researchers have described as a sense of “perpetrator omnipresence” — the victim understands the abuser as potentially present everywhere, even when physically absent. Very few, if any, locations are “safe.”
Although the research is still being developed, the existing research on the psychological impacts of electronic abuse shows that they are significant and continue long after the abuse may have ended.
A systematic review of 43 studies on cyberstalking published in 2021 found that the overwhelming majority of adult victims experienced measurable negative mental health outcomes — anxiety, depression, and, specifically, hyper-vigilance and a lasting loss of trust in technology itself. A 2015 study found that self-identified cyberstalking victims showed psychological distress levels exceeding general population norms, with symptoms comparable to PTSD — isolation, irritability, guilt — not just “stress,” but a recognizable trauma response.
“Victims' Voices: Understanding the Emotional Impact of Cyberstalking” was published in SAGE Open in 2017. It is a qualitative study built from victims' own words and thus cannot be used to scientifically establish the effects of electronic abuse. That said, it reflects the real words of real victims, which have the import you choose to give them, no more or no less.
So although this issue is about electronic abuse specifically, the effects of that abuse go far beyond your technology. They go beyond your accounts and your finances. They extend into the psychological well-being of the victim, creating a world where nothing is private and it is felt that the ever-present perpetrator has the ability to control virtually any aspect of their lives at any time.
The psychological effects are real, pervasive, and long-lasting. The more tangible effects are equally so, and will be discussed in Section IV.
First, though, we turn to the tools used by abusers.
There is an ever-increasing list of ways in which TFCC occurs. They include: location tracking; account access; device surveillance; impersonation; password control; monitoring communications; controlling social-media use; smart-home manipulation; financial surveillance; digital economic abuse; nonconsensual distribution or threatened distribution of intimate images; harassment; using children or children's devices as surveillance channels; and manipulating the victim's technological environment so that the victim no longer knows what is private.
The unfortunate truth is that it is extremely challenging to protect yourself against your own spouse. Your spouse does not require particular computer skills or knowledge of complex technology to execute these crimes.
This is true for multiple independent reasons. The first two are fairly obvious; the third is less so, but is also the most unmanageable.
First, spouses routinely share passwords and electronic devices — this is both normal and routine in a well-functioning relationship. It would be odd, in fact, not to share this sort of information, given that your spouse is ordinarily the person charged with your affairs if for any reason you cannot manage them yourself.
Second, a household almost uniformly uses one source of internet access — a single router that all household devices rely upon. And a substantial number of households go a step further and share a single desktop or laptop for everyone to use.
What happens, though, if a victim begins to suspect what is happening and stops using the home electronic system and stops sharing passwords? Is this enough? Unfortunately, it is not. Which leads us to the third challenge.
The third challenge is that virtually every security system designed to protect us fails in the context of a spouse. Consumer security protections are almost uniformly developed to protect against threats by a stranger. They are ineffective when the perpetrator knows all of your personal information.
One of the world's leading experts in security research, Bruce Schneier of the Harvard Belfer Center, co-authored a paper that identifies this issue explicitly. In “Privacy Threats in Intimate Relationships,” Journal of Cybersecurity (2020), it is called “intimate threats” — a distinct category of privacy and security risk that breaks nearly every assumption built into conventional security design. As Levy and Schneier write, “those closest to us know the answers to our secret questions, have access to our devices, and can exercise coercive power over us.”
In this context, technology that was developed to provide increased security and convenience becomes a tool that can be used to control another's technology and gain access to their online accounts without their knowledge or consent. Take the example of Apple's eSIM Quick Transfer. It lets someone move an eSIM directly between two iPhones over Bluetooth, no phone carrier contact at all, provided both devices are signed into the same Apple ID, the old phone is unlocked with its passcode, and the two phones are physically near each other.
This one act can then lead to an escalating series of harms, while simultaneously eliminating the victim's access to resources precisely when they may most need them:
And then, of course, there are the many applications either explicitly designed to track another person without their knowledge — the “spyware” you have likely heard of — or applications marketed for one legitimate purpose (usually tracking a child, or limiting a child's use of a device) and used for another, illegitimate one: tracking of another adult, namely a spouse.
Given the pervasive nature of electronics in our lives, electronic abuse can lead to a host of harms that are very specific, tangible, and potentially incredibly destructive to the victim's life.
The psychological impacts of electronic abuse leave no mark you can point to. The financial ones do.
Start with the simplest version: someone gets into an account you thought was yours alone. From there, the damage rarely stays contained to that one account. Email is usually the first domino, and most email providers still let a phone number reset a password. Once email falls, everything tied to that inbox falls with it — banking, credit cards, shopping accounts, cloud storage. A 2020 Princeton study of 145 major websites offering phone-based authentication found that 17 of them could be fully taken over with nothing but control of the victim's phone number. No password. No hacking, in any technical sense. Just the number.
Then comes the part with a name most people have never heard, despite how common it's become: coerced debt. The term was coined by law professor Angela Littwin in a 2012 California Law Review article, and it describes something specific — an abuser using force, threats, or fraud to open credit in a partner's name, run up charges on existing accounts, or take out loans the victim never agreed to. Nearly identical research from Rutgers and Michigan State has found the same pattern independently: one widely cited figure puts the share of survivors who experience some form of economic abuse at 94 percent. A UK survey of survivors found that one in four had a partner or ex-partner take out credit in their name, without consent, in the past year alone.
Online banking was supposed to make managing money easier. It also made this easier. Applying for a credit card now takes minutes, from a phone, often without a signature or a branch visit. The same convenience that lets you check your balance from bed lets someone else open an account in your name from the other side of it.
The credit damage that follows doesn't resolve when the relationship ends. It compounds. A ruined credit score doesn't just mean a higher interest rate — researchers at Michigan State, following survivors carrying coerced debt, found it can block the ability to rent an apartment, finance a car, or pass an employment background check. Credit isn't just a number. It's the mechanism by which almost everything else — a lease, a job, a fresh start — gets approved or denied. Damage it, and you don't just lose money. You lose access to the tools you'd need to rebuild.
And unwinding it is its own second ordeal. Disputing a fraudulent account usually requires proving it wasn't yours — a process built for identity theft by strangers, not for a spouse who had your Social Security number memorized and your signature down cold. A national survey of victim advocates, conducted by the National Consumer Law Center and the Center for Survivor Agency and Justice, found survivors routinely hit walls with credit bureaus and creditors that have no category for “my husband did this,” only categories for classic identity theft — leaving many to fight each fraudulent account one at a time, for years, often without a lawyer.
Then there's what simply disappears. Photographs. Tax documents. Years of email correspondence that might have proven a timeline, a promise, an agreement. When someone else has administrator-level access to your accounts, deletion is not hypothetical — it's a keystroke. Survivors describe realizing, mid-divorce or mid-custody-dispute, that the records they needed to prove their own history no longer exist, without ever being told they'd been removed.
None of this shows up on a body. None of it heals on a timeline a doctor can estimate. A credit score can take years to recover — if it recovers before the next fraudulent account appears. And unlike a broken bone, almost nothing about this process comes with paperwork anyone else recognizes as proof that something happened to you at all.
Every state in the country makes the conduct discussed thus far a crime.
Not some of it. Not the extreme cases. Getting into someone else's phone, computer, or account without their permission is a crime in all fifty states, plus Puerto Rico and the Virgin Islands. It doesn't require a stalking pattern. It doesn't require threats. In most states, one unauthorized login is enough.
The statutes are all similar. New York's is representative: using or accessing a computer, a phone, a network, without authorization, is a misdemeanor. Look up New York Penal Code Section 156.05, and you will discover that the words are unambiguous. Actually get into the material inside — the messages, the photos, the files — and it becomes a felony.
Other states use different names for the same idea: computer trespass, unauthorized computer access, unlawful use. Minnesota calls it what it is: unauthorized computer access, a felony if it creates a grave risk of death. The wording changes. The structure doesn't. Access without permission is the crime. Nothing else has to happen first.
Federal law is consistent. The Computer Fraud and Abuse Act criminalizes unauthorized access to any computer connected to the internet, which by now means nearly everything with a screen. The federal wiretapping statute covers real-time interception — reading messages as they arrive, not just afterward. A separate federal stalking law applies once the conduct becomes a pattern and causes fear or serious emotional distress. None of these statutes carve out an exception for marriage. Courts have said so directly, more than once, after being asked to find one.
So the conduct this issue describes is not a gray area. It is not “toxic” or “unhealthy” or any of the softer words we reach for. It is, on paper, a crime, in every state, and has been for years.
The use of the phrase “on paper” is intentional. Having a law is not the same as having a system that uses it, criminals that are deterred by it, or victims that feel protected by it.
Most states cannot tell you how often these laws are actually charged, because most states do not track it. When Connecticut's legislative researchers tried, in a 2009 study, to get charge and conviction data from every state with a dedicated cyberstalking statute, they found that most of those states simply don't keep the numbers. Two more charge a fee just to produce them. Only one state, North Carolina, could answer the question at all. Since its law took effect in 2000: 1,228 people charged. 172 convicted. No data on what happened to the rest.
That is not a story about North Carolina. North Carolina is the one state that looked.
Ask why, and the same three answers come up everywhere. First: women don't report it. One study of cyberstalking victims found that roughly 86 percent never went to police at all. The single largest reason was not fear of the abuser. It was not knowing the conduct was a crime in the first place. Women were also more likely than men to say they didn't report because they didn't think the police would do anything — a belief that turns out to be well-founded, not paranoid.
Second: proving it is hard, and expensive. Unauthorized access rarely leaves a fingerprint. It leaves a login timestamp, an IP address, a pattern across months of account activity — the kind of evidence that takes a forensic specialist to assemble and a prosecutor's office to pay for. And, of course, you need not be a technology expert to know that applications are easily accessible to disguise your identity on the internet. Many of us use these applications ourselves in the name of privacy, or simply to keep ourselves off marketing databases.
It is not impossible to defeat these attempts to hide one's identity online. But doing so generally requires an experienced digital investigator. Most district attorneys don't have one on staff. Most victims can't afford to hire one themselves.
Third: police often don't know what they're looking at. A study of investigators handling cyberstalking cases found that officers frequently didn't recognize the conduct as criminal, and a British survey of more than a hundred police officers found their willingness to treat a case seriously actually declined the longer a victim took to report — which penalizes exactly the delay that fear, confusion, and a controlling partner routinely cause.
Put these together and the law's plain language stops mattering very much. New York's statute lets someone charged with unauthorized access argue they reasonably believed they still had permission — a defense written into the law itself, and one a spouse can often meet without much effort, given how ordinary it is to share a password with someone you married. Proving that belief was unreasonable requires the same specialized evidence most departments don't have and most survivors can't afford.
The crime is real. The statute is real. What happens after someone calls the police is, for most victims, in most states, still an open question — and not because anyone has answered it and found the system works. Because almost no one has kept score.
The current system is not as effective as it could be at addressing domestic abuse generally, and it is even less effective at addressing electronic abuse specifically. For most departments, this likely reflects limited resources and the genuine complexity of these cases, not deliberate indifference. But not always: the Department of Justice has conducted multiple federal civil-rights investigations — in New Orleans, Puerto Rico, Missoula, and, more recently, into the NYPD's own Special Victims Division — that found documented patterns of gender-biased policing, including the routine misclassification and dismissal of domestic violence complaints. Resource limits and bias are not mutually exclusive explanations, and in at least some departments, both have been true at once.
Knowing the law is on your side does not make it easy to use. But there are things you can do, starting now, that make it more likely to work for you if you ever need it to.
Start with the paper trail. Screenshot everything — not just the alarming messages, but the mundane ones too, since a pattern is what eventually convinces a prosecutor, not a single incident. Include timestamps, usernames, and URLs in the frame, not just the message itself; a cropped screenshot is weaker evidence than one that shows where it came from. Keep a simple log: date, time, what happened. The Stalking Prevention, Awareness, and Resource Center publishes a free template built for exactly this — a Stalking Incident and Behavior Log — and using a standardized format is more useful to an investigator than a private journal, however thorough. Save password-reset emails and unfamiliar-login notifications even when they seem like background noise; they are often better evidence of intrusion than the intrusion itself, since a platform generated them, not your abuser. Do not delete anything, including things that feel too small or embarrassing to matter. And do not keep any of this only in a place your abuser can also reach. A cloud folder tied to a shared account is not a safe or a diary. Back everything up somewhere separate — a new account, a trusted friend, a device your abuser has never touched.
Revoke consent, in writing, even if it feels unnecessary. This is the single most consequential thing on this list, and the least intuitive. The law's authorization defenses exist because sharing passwords between spouses is normal, and courts have generally required something more than a soured relationship to prove that access was no longer allowed. A dated message — even a text, even one sentence — saying “please do not access my accounts, devices, or email going forward” closes that gap. It converts an ambiguous situation into a documented one. Send it before you change a single password, if you can do so safely, because it is the revocation itself, not just the changed password, that a prosecutor or a judge will eventually want to see.
On recording calls or conversations: whether you can legally record someone without telling them depends entirely on your state. Some states require only your own consent to record a conversation you're part of; others require everyone's. Recording without the required consent can create legal exposure for you, not just evidence against someone else — confirm your state's rule, ideally with a lawyer, before relying on a recording as evidence.
Know that “who do I call” does not have one clean answer, and plan around that rather than being surprised by it. No single agency owns this problem. A Special Victims Unit will understand the relationship and may not understand the technology. A computer crime unit will understand the technology and may not be set up to take your specific complaint. The FBI's Internet Crime Complaint Center accepts reports but does not investigate them itself, and does not promise to follow up — it is a mailbox, not a caseworker. If you're in an area with a specialized resource — Cornell Tech's Clinic to End Tech Abuse serves the New York City area directly, sitting with survivors and their actual devices rather than only offering information — start there if you can. Otherwise, expect to tell your story more than once, to more than one office, and don't take the retelling as a sign you're being dismissed. It is often just what a fragmented system requires.
A few practical steps worth taking before you think you need them:
None of this is a guarantee. It is a way of making sure that if the moment comes when you need proof, proof exists — and that if the system that's supposed to help you is as fragmented as the last section describes, you've already done the part of the work that no one else was going to do for you.
The full Resource Guide accompanying this issue lists the organizations named above, along with hotlines, legal aid directories, and state-specific resources, in one place.
This issue of Il Filo was difficult for me to write because the challenges it describes are ones I experienced over years. In 2026, I have the requisite information to defend myself far more effectively, albeit still imperfectly. But I knew none of it in 2020, when I was the victim that I now describe. Indeed, most of what I now know is not a function of academic research, but rather an ongoing attempt to identify what tools were being used against me and a desperate and generally unsuccessful effort to protect myself.
In 2020, all I knew was that none of my electronics worked correctly, that my passwords were always wrong and I routinely was unable to access my accounts, settings were constantly changed, photos and documents disappeared. And on and on. Struggles with my electronics were a constant part of my life, with countless hours spent on the phone with customer service representatives.
Electronic abuse rarely happens in isolation, of course, and I was simultaneously living in a cycle of abuse that led to me being not only exhausted but ultimately physically ill. I asked two of my friends to promise to do whatever was necessary to get me out of my marriage if I could not do so myself. That is how worried I was that my physical and emotional wellbeing was so diminished that there was a real chance that I simply would not have the ability to do so myself.
Ultimately I did get out, but the effects of pervasive and continuous abuse are long. This issue was a stepping back into a period of my life that in some respects I wish I could simply erase from my mind.
I cannot — so I hope that this issue helps others protect themselves in ways I was unable to. Perhaps most importantly, I hope it affirms for any abuse victim that their experience is real, that what is happening to you is a crime, and that you are not alone. Seek help in the best way available to you when you can.
I wish I could say differently, but disentangling yourself from electronic abuse may come down to what you are able to do. Resources exist and they should be used. But the damage that results from this sort of abuse — and the fact that it is unquestionably a crime under both federal and state law — is not, in my experience, widely understood.
The Resource Guide accompanying this issue is to help you get to where I got. Eventually. It will not make that process easy or quick. It will not make people understand the level of harm that has been done to you. Some will. Many won't.
But help does exist, and the alternative — to not seek help — isn't how anyone should have to live. The guide is a start, a place to begin the road back to a life that is yours, as you want it to be lived.
There are two questions to consider. First, how do I protect myself? The second question, to my mind, is more fundamental: do I want to be with someone that I have to protect myself from?
Karen Levy and Bruce Schneier's “Privacy Threats in Intimate Relationships” (Journal of Cybersecurity, 2020) is the paper that named this category of risk. It's academic, but readable — and it may be the most validating thing you read all week.
The Stalking Prevention, Awareness, and Resource Center publishes a free Stalking Incident and Behavior Log at stalkingawareness.org. NNEDV's Safety Net Project has a companion set of documentation guides at techsafety.org.
Cornell Tech's Clinic to End Tech Abuse works directly with survivors, not just information — an increasingly rare thing in this space.
The National Conference of State Legislatures maintains an up-to-date, state-by-state survey of computer crime statutes at ncsl.org. WomensLaw.org has plain-language legal information organized by state.
Start at identitytheft.gov — the FTC's site will build you a personalized recovery plan and generate the affidavit you'll need for creditors. The National Consumer Law Center's resources on coerced debt (nclc.org) explain a pattern most people have never heard named, despite how common it is.
The National Domestic Violence Hotline: 1-800-799-7233, or thehotline.org, 24 hours a day.