When the threat actor lives under your roof: Fighting Technological Violence in Domestic Abuse Cases

CatherineDG

NorthSec 2025 · Day 2 · Ville-Marie · Conference

Overview

Catherine Duborg-Agnon, co-founder of the association Cybercitoyen, presents a sobering intersection of cybersecurity and intimate partner violence (IPV). Drawing on real case work, she documents how domestic abusers weaponize smart-home devices, commercial spyware, AirTags, and dual-use consumer technology to surveil victims even after physical separation — and calls on the security community to recognise this threat model and get involved. ---

Watch on YouTube

Visual summary for When the threat actor lives under your roof: Fighting Technological Violence in Domestic Abuse Cases by CatherineDG
Visual summary for When the threat actor lives under your roof: Fighting Technological Violence in Domestic Abuse Cases by CatherineDG

Key moments

  1. 1:30 70% of DV victims report tech surveillance; 40% have spyware
  2. 3:00 Smart home abuse: abuser controlled IoT devices after removal
  3. 6:00 Alexa found hidden inside wall for covert surveillance by abuser
  4. 7:30 Spyfluencer problem: YouTube guides teaching domestic stalking tech
  5. 13:31 Deleting spyware triggers abuser alert: standard advice is dangerous
  6. 15:01 All standard security advice fails with physical access and shared accounts
  7. 18:01 Secret question technique detects identity spoofing in communications
  8. 21:01 Civil court: journal plus expert sufficient; criminal proof near impossible

When the Threat Actor Lives Under Your Roof: Fighting Technological Violence in Domestic Abuse Cases

Speaker: CatherineDG (Catherine Duborg-Agnon) — Cybercitoyen

Conference: NorthSec 2025 — May 15–16, 2025, Marché Bonsecours, Montreal

Watch on YouTube: https://www.youtube.com/watch?v=331exnpDyow

Reading time: ~7 minutes

TL;DR

Catherine Duborg-Agnon, co-founder of the association Cybercitoyen, presents a sobering intersection of cybersecurity and intimate partner violence (IPV). Drawing on real case work, she documents how domestic abusers weaponize smart-home devices, commercial spyware, AirTags, and dual-use consumer technology to surveil victims even after physical separation — and calls on the security community to recognise this threat model and get involved.

Introduction

Seventy percent of domestic abuse victims report being spied on, followed, or tormented through technology. That statistic opens CatherineDG's NorthSec 2025 talk, and it anchors an argument that the cybersecurity field has, largely, failed to reckon with: when the threat actor lives inside the same household as the target, nearly every standard security recommendation breaks down.

CatherineDG brings this framing from direct practice. As co-founder of Cybercitoyen — a Quebec-based association that runs a cybersecurity and privacy podcast and provides hands-on support to victims of cybercrime — she has worked personally with domestic abuse survivors navigating technological surveillance. The cases she presents, lightly anonymised with consent, are not hypothetical attack scenarios; they are live incident responses conducted under the constraint that one wrong step could alert a dangerous abuser.

This talk was originally designed as a 90-minute presentation. Compressed into 26 minutes for NorthSec's conference track, it necessarily shortcuts some nuance — but the core argument comes through clearly: the threat model of technological domestic violence is distinct enough from conventional cybersecurity scenarios that it requires its own frameworks, tools, and community engagement.

The Case That Set the Baseline: Smart Homes as Control Infrastructure

The most striking case in the talk involves a fully connected home — lights, heating, audio, and entertainment systems all networked and previously administered by the abusive partner. After a violent incident and a court-ordered no-contact arrangement, the man retained remote access to every device. Music would start in the middle of the night. Heating would spike to unbearable temperatures without warning. During a video call with a lawyer, a television behind the victim began playing pornography at high volume — a deliberate attempt to sabotage her employment relationship.

▶ Watch: The smart-home control case (2:00)

The incident that finally created actionable evidence came when the victim, at her lawyer's suggestion, switched to a work device for privileged communications. The abuser attempted to hack the corporate system, triggering alerts in the employer's security department. That intrusion attempt became the pivot point: for the first time, there was technical proof rather than a victim's account that was being dismissed.

Cybercitoyen was brought in to remediate. The team conducted a device audit, changed credentials, and took ownership of the telecom accounts that had been co-subscribed and were being used for SIM-swapping attacks. Even after two rounds of investigation, something remained wrong. On a second pass through the network, CatherineDG spotted an Alexa device that had not been there before. The victim had no Alexa. No one in the household had placed one there. After a physical search — conducted over FaceTime for safety reasons, with the victim holding the phone — the device was found embedded behind a wall, powered through the wall cavity, and presumably installed by the abuser.

The Spyfluencer Ecosystem and the Normalisation of Surveillance

The embedded Alexa was not an isolated improvisation. It reflected a systematic body of knowledge that circulates openly online. CatherineDG introduces the term "spyfluencer" to describe the ecosystem of YouTube channels, Reddit communities, and forum threads that provide step-by-step guides for covert surveillance of intimate partners.

▶ Watch: Spyfluencer problem and social normalisation (6:00)

Some of this content markets itself as child-safety or relationship-transparency advice. Some is blunt: how to spy on a girlfriend, with ranked reviews of the best applications and detailed installation walkthroughs. Several such videos have millions of views. The practical consequence is that conducting a sophisticated surveillance operation against an intimate partner no longer requires any technical skill — it requires only the willingness to follow a tutorial.

More troubling is the normalisation dynamic. Among younger populations in particular, the concept of demonstrating love through mutual surveillance has taken root: sharing passwords, enabling location tracking, and granting access to messages are framed as acts of trust rather than violations of privacy. CatherineDG connects this directly to parental monitoring practices, arguing that children who grow up under location tracking internalise surveillance as a feature of caring relationships — an expectation they carry into adulthood.

Dual-Use Technology and the Limits of Standard Advice

AirTags represent the dual-use problem in miniature. Designed for tracking lost items, they have become a documented vector for stalking. Domestic violence shelters now search every item a victim brings through their doors, because abusers slip AirTags into bags, coat pockets, and children's backpacks before a victim leaves.

▶ Watch: Dual-use tools and what standard advice misses (10:00)

The broader dual-use category is vast: Find My Phone features, infant monitoring apps, Amazon Ring cameras, and connected home sensors all appear in abuse cases. None of these products are illegal. Their manufacturers design them for legitimate purposes. But when controlled by an abuser, they function as a persistent surveillance and harassment infrastructure.

Standard cybersecurity guidance fails this population in specific, structural ways. The first assumption of conventional advice is that the user controls their own device — that no adversary has physical access. In IPV cases, that assumption is false by definition; the abuser may have installed spyware directly on the victim's phone. The second assumption is that the victim has a degree of baseline privacy from which to act. But communications themselves may be monitored, so even reaching out for help is a risk calculation. Cybercitoyen has addressed this by disguising advisory calls as mandatory corporate security training sessions — a measure that illustrates how far outside normal incident-response methodology these cases fall.

A third failure: many spyware applications send an alert to the abuser when the application is uninstalled. Changing a password an abuser expects to have can itself trigger a dangerous confrontation. And underlying all of this is the reality that many victims have low tech literacy, are operating in a second language, and are managing terror simultaneously with learning new concepts.

What the Security Community Can Do

CatherineDG closes by addressing the audience directly. The security community has the technical skills this population needs; what it largely lacks is awareness that the problem exists and channels through which to apply those skills.

▶ Watch: Call to the security community (16:00)

Organisations like Cybercitoyen operate at the intersection of social work and incident response. They need volunteers who can conduct device audits, build accessible French-language resources, assist shelters in developing intake procedures for tracking devices, and help design guidance that accounts for the specific constraints of the IPV threat model — particularly the risk that security-improvement steps themselves can escalate danger.

The first step is recognising that the threat model is real, documented, and growing. When CatherineDG first presented the embedded Alexa case publicly, an attendee from Sécurité Québec immediately replied that they had encountered an identical case the previous week. Independent convergence on the same technique by two unconnected abusers in the same province points to a shared information ecosystem — the spyfluencer content that teaches these tactics at scale.

Notable Quotes

"Seventy percent of all domestic abuse victims report being spied on or followed or tormented by the means of technology."

"Before, if a victim was escaping a domestic abuse situation, she would end up eventually in a safe physical space. Now, with technological [abuse], this kind of physical distance is reduced."

"Some steps can trigger alarm. When you delete one of those spyware apps, usually they send an alarm to the person. If you change your password and your abuser has the expectation that he can connect at any time to your account, that's also going to raise some red flags."

"If experts that spend their day — maybe their weekend like we are today — are overwhelmed with cybersecurity practice at times, how can we expect someone in a life or death situation that never had any kind of time spent learning any of these to suddenly not feel extremely overwhelmed?"

Key Takeaways

  • Technological domestic violence is a distinct threat model. Standard cybersecurity advice does not account for an adversary with physical device access, shared account credentials, and a detailed knowledge of the victim's environment.
  • Smart-home infrastructure is an abuse vector. Devices controlled by an abuser can be weaponized for harassment, manipulation, and psychological torture even after physical separation.
  • Dual-use technology requires industry attention. AirTags, monitoring apps, and connected devices are showing up in abuse cases in ways their manufacturers did not design for but need to address.
  • Spyfluencer content lowers the technical barrier to stalking. Step-by-step surveillance tutorials with millions of views mean that covert partner surveillance no longer requires technical skill.
  • The security community has a role. Organisations working with abuse survivors need technical volunteers for device audits, resource creation, and threat-model-aware security guidance.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Cybercitoyen co-founder presents real case work on technology-facilitated domestic abuse: smart-home control as harassment infrastructure, embedded Alexa hidden in walls, spyfluencer content ecosystems, dual-use stalkerware, and the specific ways standard security advice fails IPV victims.

Heather Calloway (CISO) — MUST SEE

Seventy percent of domestic abuse victims report being surveilled through technology. That number should stop the room. CatherineDG is presenting a threat model the security community largely doesn't serve, and the failure she's documenting — commercially available consumer technology with no abuse-mitigation design — is a market failure with life-safety consequences. This is not a niche topic.

→ Top-rated talks at NorthSec 2025

All talks from NorthSec 2025