On behalf of the Victim Assistance Service of beider Basel, you conduct so-called cell phone security assessments for victims of domestic violence and stalking. What exactly do you do during these assessments?
Rachid Dahjaoui: We conduct a comprehensive assessment of the individuals involved to identify digital security risks. The goal is to determine whether their device is being monitored—for example, by so-called “stalkerware,” or hidden surveillance apps—or whether there are other vulnerabilities that pose a threat. At the end, the affected person receives a concrete action plan with clear recommendations for action. In addition, those affected can ask further questions throughout the entire assessment.
How does this kind of exam work?
Rachid Dahjaoui: In the first phase, we explain the process and purpose of the assessment to the person involved. They also receive a guide to digital self-defense with practical tips on how to use their smartphone safely, manage passwords, and configure important settings in social media apps—especially regarding location sharing. In the second phase, we work through a questionnaire we’ve developed together, which allows us to systematically assess all relevant risk areas. If we encounter any red flags during this process, we follow up specifically to evaluate the specific threat. We’ll identify appropriate countermeasures right during the conversation.
So what happens next?
In the third phase, things get technical: We analyze the smartphone’s network traffic—that is, the connections the device establishes in the background. This allows us to determine whether the phone is secretly sending data to suspicious services, as would be the case with stalkerware. To do this, we use a specially configured device to which the affected person connects. After the assessment, they receive an action plan detailing all identified risks and the recommended steps.
What are the most common vulnerabilities you’ve encountered?
Rachid Dahjaoui: By far the biggest vulnerability is the failure to handle one’s own accounts and passwords securely. Victims have often shared their login credentials with their partner or had their partner set up their accounts for them. This results in the partner having full access—and thus full control and the ability to monitor the account. On top of that, the same password is often used for multiple accounts. If one of them is compromised, it opens the door to several others at once.
Francis Fink: In this context, the individuals affected often lack a clear understanding of which of their accounts are secure and to what extent. When they then hear that all their accounts must be considered at risk or even compromised, it’s a huge burden for them.
The pilot phase is now complete. What insights have you gained? What are your preliminary conclusions?
Rachid Dahjaoui: An important finding: With the exception of one case, we did not find any stalkerware or spyware on the devices. But that does not mean that no surveillance is taking place—quite the contrary. The risk usually arises not from technical attacks, but from the fact that login credentials were voluntarily shared or set up by the partner. In technical terms, this is called social engineering—that is, the targeted manipulation of people to gain access to accounts or information. Another key finding: A questionnaire alone is not enough. In-depth knowledge of cybersecurity is required to accurately assess the actual risk potential.
Francis Fink: One of the most important insights for me personally is that perpetrators of domestic and psychological violence extend their control over their victims into the digital realm as well. This means that victims—who, prior to the incidents, had been just as careless about their own account security as the majority of people—must absolutely adapt their security measures to the increased level of risk. Such a change cannot happen overnight, and often a significant risk is already present at that point. Our cyber assessments serve as a starting point for practicing what we call “digital hygiene” and, if necessary, beginning to regain control over one’s own accounts and connections.
How can you ensure that the people involved follow your recommendations?
Rachid Dahjaoui: Ideally, a program should be created that directly guides those affected through the implementation of these measures—one that doesn’t just leave them with a list, but supports them step by step. At the same time, it’s important to raise awareness among those affected: What is technically possible? What specific risks exist? And how could the person have protected themselves? This awareness is key to ensuring that the recommendations are implemented in everyday life over the long term.
Francis Fink: Unfortunately, at this time we are unable to provide ongoing support to the individuals concerned after the assessment. This means that we cannot ensure they will be able to adequately implement our recommendations. In my view, it would be crucial to regain digital sovereignty—that is, a state in which a person can independently decide and control how much access they wish to grant to others and, if necessary, revoke that access. Expanding the services offered by victim assistance centers to include counseling on how people can navigate the digital space safely and how they can implement the measures we recommend would undoubtedly round out our efforts.
You’ve shared your experiences with victim support centers, and you lead a weekly consultation session for professionals on behalf of tech against violence. What do you attribute the high level of interest in your work to?
Rachid Dahjaoui: These days, it’s alarmingly easy to digitally monitor other people. It requires neither hacking skills nor extensive technical knowledge. As a result, digital surveillance is becoming increasingly common in abusive relationships, and counseling centers are increasingly confronted with this very issue. At the same time, these centers often lack the necessary expertise to accurately assess the risks. Here’s a concrete example: If a victim flees to a women’s or girls’ shelter and is carrying a smartphone that is currently being actively tracked, the safety of the entire shelter is at risk. This is exactly where specialized knowledge is needed, and this is precisely why there is such great interest in our work.
Francis Fink: The IT knowledge of staff at specialized agencies in the field of cybersecurity is often insufficient to respond adequately to threats in the digital space. Most of these agencies are aware of this, which is why they make active use of the resources offered by tech against violence.
What advice can you give us all to help us be more mindful of data security?
Rachid Dahjaoui: Four simple basic rules that make a big difference: First, use a unique, strong password for each account. A password manager can help you keep track of them. Second, enable two-factor authentication whenever possible. This means that, in addition to your password, a second verification step is required—for example, a code sent via an app. Even if someone knows your password, they won’t be able to access your account with just that. Third: Regularly review your apps’ permissions: Which apps have access to your location, camera, or microphone? Disable anything that isn’t absolutely necessary. Fourth: Always keep your devices up to date and install updates. And as a general rule: Never share your login credentials with anyone—not even your partner.
Francis Fink: I agree with Rachid: Managing your own accounts and passwords securely is the foundation of your cybersecurity.
How can we tell if there’s a problem with our cell phone’s security? And what should we do if that’s the case?
Rachid Dahjaoui: There are a few typical warning signs: The battery drains noticeably fast, even though you’ve barely used the phone. The camera or microphone turns on for no apparent reason. You receive emails about password resets that you didn’t initiate yourself. Or certain settings suddenly can’t be changed and display error messages. These are just a few examples, but if you notice things like this, you should be on your guard. In this case, contact a specialist service or an advice center that can help you have the device checked.
Francis Fink: It should be added that stalking has been a criminal offense since January 1, 2026. Prison sentences of up to three years may be imposed. Stalking is defined as persistent pursuit, harassment, or threats that severely restrict a person’s ability to live their life freely. Digital surveillance is often part of it.