Skip to main content
NestGrid logoNestGrid

Lock a stalker out of your smart home before adding security

The real exposure in a stalking situation is usually the access the stalker already has — shared accounts, paired devices, Wi-Fi credentials — not a missing camera. This guide walks through the exact order: inventory and document first, revoke and change credentials, then add security devices on a network only you control.

If you are in immediate danger, call 911. If it is safe to reach out, the National Domestic Violence Hotline is 1-800-799-SAFE, and you can text START to 88788. Use a phone, browser, email account, or device that you believe the abusive person cannot access; if you are unsure, ask an advocate or trusted person to sit with you before you begin.[1]

A smart home security setup for stalking protection should not start with a cart full of cameras. It should start with the uncomfortable assumption that the exposure may already be inside the system: a shared Apple ID or Google account, a Nest or Ring login, a router password, a paired phone, a cloud dashboard, a smart lock guest code, or an old tablet still signed in under the couch.

Do not begin by unplugging everything or changing every password in a panic. NNEDV warns that technology-facilitated abuse can escalate when access is cut off, and the FTC’s stalkerware guidance also tells people to consider safety planning and documentation before removing monitoring tools or changing access.[2][3] The first useful move is slower: record what exists, date-stamp it, preserve evidence, and then lock control down in the right order.

A smart home controlled from a phone with one unrecognized connection highlighted

This is not a niche smart-home problem. Reviews.com cites an NNEDV survey in which 97% of U.S. domestic-violence programs reported that abusers used technology to stalk, harass, or control victims.[4] That number matters because it keeps the setup honest: the work is not to make a home look more secure. The work is to prove who has access, remove the wrong people, and rebuild only what can be owned and checked.

PhaseDo this before moving onWhat “done” looks like
DocumentCreate a dated log, take screenshots, photograph devices, and save account/access evidence before changing settings.You have a record that can be shared with an advocate, attorney, police report, or trusted helper if needed.
InventoryList router-connected devices, smart-home accounts, users, paired phones, guest codes, automations, and apps that reveal presence or routines.Each item is marked verified, unknown, shared, removed, reset, or needs help.
Revoke and resetRemove users, sign out sessions, change passwords, enable stronger MFA, change Wi-Fi credentials, and factory-reset devices whose access cannot be proven.Old accounts, devices, sessions, and codes no longer control the home.
DeployAdd cameras, locks, doorbells, and sensors only under a fresh account and network the survivor controls.New devices are not attached to old shared accounts, old Wi-Fi, or shared credentials.
MaintainRe-check device lists, account sessions, activity logs, batteries, and false-alarm patterns on a schedule.Control is not assumed; it is repeatedly verified.

Before touching settings, build the evidence folder

Use a notebook, a printed worksheet, a new cloud folder, or a USB drive kept somewhere safe. The tool matters less than the date. Every entry should show what you saw, when you saw it, and where you saw it. If a trusted friend or advocate is helping, have them add their initials to the log or keep a parallel copy.

  • Write the date, time, address, and who is present while you are checking.
  • Photograph each smart device in place before unplugging or moving it.
  • Screenshot user lists, shared-home members, invited users, device names, account email addresses, activity logs, lock-code lists, camera event histories, router device lists, and app settings.
  • Record exact names as they appear, even if they look silly or generic: “iPhone,” “ESP_32,” “Living Room,” “Unknown,” “Amazon-123,” or “Private Address.”
  • Mark each item with a status: verified mine, verified trusted, unknown, shared with abuser, removed, reset, or needs advocate/legal advice.

Do this before making the system cleaner. A clean app screen is comforting, but it can also erase the very thing you may later need to show: that another person had access, that an unknown device was connected, that a lock code existed, or that a camera was being viewed from an account you did not control.

If a protection order, custody dispute, lease dispute, police report, workplace safety plan, or school safety plan is involved, pause before deleting users or wiping devices and ask an advocate or attorney what they want preserved. These steps can help you get the home under control; they are not a substitute for legal advice.

Inventory the home wider than cameras

Cameras draw attention because they feel invasive, but presence can leak through quieter devices: a thermostat schedule, a smart speaker history, a garage-door app, a lock notification, a motion sensor, a shared location setting, a Wi-Fi router, or a smart light that shows when someone is home. NNEDV’s smart-home guidance tells survivors to look at the router’s administrative page and connected-device list, often reachable through a local address such as 192.168.1.1, and to use device details such as MAC addresses to help identify manufacturers.[5]

A router surrounded by smart-home device icons with one unverified device highlighted

The aggravating part is that many products do not make this easy. Brown, Harkin, and Tanczer’s 2024 study of 13 consumer IoT products found that most did not provide a clear visual indication of which users or devices could access them, and most did not log which devices had signed into an account.[6] That finding is exactly why “I checked the app” is not enough. The app may not be designed to answer the question a survivor actually needs answered: who else can still see, change, unlock, listen, or receive alerts?

Start at the network, then move outward to accounts and devices. If the router is owned by the abusive person, managed through their ISP login, or located somewhere they can still access, treat the network as shared until you can replace or re-administer it safely.

Router and Wi-Fi inventory

  • Router make, model, serial number, and who owns the ISP account.
  • Router admin username, if known, without writing passwords in a place the stalker might access.
  • Wi-Fi network names, including guest networks and any hidden or extender networks.
  • Connected-device list from the router admin page, with device name, MAC address, IP address, and last-seen time if available.
  • Mesh nodes, range extenders, powerline adapters, and old routers that may still broadcast a known password.
  • Unknown devices photographed or screenshotted before blocking or deleting them.

If the router is unstable or the internet is down, do not confuse ordinary recovery work with stalking cleanup. In a normal outage, our smart-home recovery ladder avoids premature factory resets. Here, factory resets may become intentional later, but only after the evidence and inventory are captured.

Account inventory

Shared identity accounts are often the real control panel. Check the accounts that can create homes, invite members, restore backups, approve logins, or receive password-reset codes.

  • Apple ID, Google account, Amazon account, Samsung account, Microsoft account, and any family-sharing group.
  • Smart-home platforms such as Apple Home, Google Home, Amazon Alexa, SmartThings, Ring, Nest, Wyze, Arlo, Eufy, Ecobee, August, Yale, Schlage, SimpliSafe, ADT, or a local hub account.
  • Password managers, backup email addresses, recovery phone numbers, trusted devices, and security keys.
  • Carrier, ISP, and router-cloud accounts.
  • Landlord, property-management, apartment-access, garage, gate, elevator, or package-room apps.
  • Shared calendars, location sharing, photo libraries, family subscriptions, car apps, pet trackers, and fitness wearables that reveal routines.

Device inventory

Walk the home with the router list open. Match every connected item to something physical. If you cannot find the device, mark it unknown; do not rename it to something tidy and move on.

Device typeWhat to recordWhy it matters
Smart locks and garage controllersOwner account, guest users, PINs, physical keys, activity log, bridge or hubThey can reveal arrivals and departures, and in some cases control entry.
Cameras and doorbellsOwner account, shared users, viewing history if available, cloud plan, power source, storage locationThey can expose visitors, routines, conversations near doors, and attempts to get help.
Smart speakers and displaysHousehold members, voice profiles, drop-in/intercom settings, calling settings, history controlsThey may reveal presence, routines, contacts, and household activity.
ThermostatsShared users, schedules, eco/away behavior, geofencingTemperature changes and schedules can signal whether someone is home.
Lights, plugs, and switchesAutomations, remote users, scenes, schedulesLighting patterns can reveal occupancy or be used to intimidate.
SensorsMotion, contact, glass-break, water, smoke, and presence sensors; battery level; assigned roomsSensors can create a map of movement even without cameras.
Hubs and bridgesHub owner, admin account, local IP, cloud account, Z-Wave/Zigbee/Thread devices joined to itA hub can remain a control point even after individual apps look clean.

Camera-detector apps are worth treating as a narrow tool, not a sweep that clears the house. NNEDV notes that apps may help find some wireless cameras, but they may not detect wired cameras.[7] If you suspect hidden cameras, document what you find and consider getting help from an advocate, attorney, law enforcement contact, or qualified professional rather than relying on an app result as proof that the home is clear.

Revoke access in layers, not device by device at random

Once documentation is saved somewhere safe, work from the accounts that can re-create access toward the devices that merely use it. If you reset a camera while the abusive person still controls the Apple ID, Google account, Amazon household, router admin, or recovery email, they may be able to return before you finish the room.

A hand removing a key card from a smart door lock as connected-device links break

Move smart-home control to a fresh email account

Create a new email address on a device the abusive person cannot access. Do not use an old shared family email, work email, school email, or address whose password-recovery phone number belongs to the stalker. Reviews.com’s safe-connectivity guidance recommends new passwords, stronger authentication, and a fresh email address for smart-home accounts as part of regaining control.[4]

  • Use a long, unique password stored in a password manager the stalker cannot access.
  • Enable multifactor authentication that is not SMS-only where possible, especially if the stalker has ever had access to the phone plan, SIM, phone backups, or text messages.
  • Remove unknown recovery emails, recovery phone numbers, trusted devices, and delegated access.
  • Sign out other sessions after capturing screenshots of session lists.

Clean up platform accounts before individual gadgets

In Apple Home, Google Home, Alexa, SmartThings, Ring, Nest, and vendor apps, look for home members, shared users, guest users, linked services, family groups, emergency contacts, device sharing, and “works with” integrations. Screenshot first. Then remove anyone who should not have access.

  • Remove shared-home members and guest users.
  • Delete old lock PINs, garage users, alarm codes, and temporary codes.
  • Disable intercom, drop-in, household calling, or shared camera-viewing features until you can confirm each setting.
  • Remove unknown integrations such as voice assistants, IFTTT-style automations, old hubs, or third-party dashboards.
  • Check whether automations send notifications, change lights, unlock doors, adjust thermostats, or announce motion.

Some apps offer “sign out everywhere” or session-management controls; use them after the screenshots are saved. Wirecutter’s domestic-abuse smart-home guidance specifically points to removing users, checking account access, and using factory resets when control cannot be verified.[8]

Change the Wi-Fi password after account control is ready

Changing Wi-Fi too early can knock devices offline before you know what they were. Changing it too late can let an old phone, tablet, camera, speaker, or laptop keep talking to the network while you rebuild. The cleaner order is: document the connected-device list, secure the account you will use to administer the router, then change the router admin password and Wi-Fi password.

  • Rename the main Wi-Fi network if the old name is known to the stalker.
  • Use a new, long Wi-Fi password that is not reused anywhere else.
  • Disable WPS if it is enabled.
  • Remove guest networks unless you intentionally need one.
  • Update router firmware if the admin page offers a current update from the manufacturer or ISP.
  • Rejoin only devices you can identify.

If the ISP account is controlled by the abusive person, do not assume a password change inside the router is enough. You may need a new ISP account, a replacement router, or help from the provider, landlord, advocate, or attorney. The important boundary is ownership: the network carrying the new security setup should not be administered through an account the stalker can reset.

Factory-reset what you cannot verify

A factory reset is not a magic safety button. It is a controlled wipe after the evidence is preserved and after you understand what the device is. NNEDV notes that factory resets, including pinhole resets on some devices, can wipe stored remote access; Wirecutter also recommends resetting devices when access cannot be confirmed.[5][8]

Use this standard: if you cannot prove who owns the account, who is invited, which phone is paired, or which cloud service receives events, reset or replace the device before trusting it. This applies especially to door locks, garage controllers, cameras, hubs, alarm panels, smart displays, and secondhand devices installed by the person who stalked you.

  • Take final photos and screenshots.
  • Remove the device from the old app if you control that app.
  • Perform the manufacturer’s reset procedure.
  • Re-add the device only to the new account and new Wi-Fi.
  • Rename it clearly, such as “Front Door Lock - reset 2026-08-25,” so the next check has a baseline.
  • Record firmware version, app version, account owner, and verification date.

Only now add protective devices

A new doorbell camera installed into an old shared account is not a protective upgrade. It is a better camera for the wrong control structure. Add devices only after the account, network, and recovery paths belong to the survivor or to a clearly chosen trusted helper.

A house protected by a smart-home network connected only to one phone while an open network sits outside

The simplest defensible deployment has one owner account, one recovery email, strong MFA, a router the stalker cannot administer, and devices grouped so they can be reviewed. If practical, put smart-home devices on a separate IoT SSID or VLAN and keep phones, laptops, and sensitive documents on the primary network. That separation does not solve stalking by itself, but it gives you cleaner device lists and a smaller blast radius when a bulb, camera, or plug behaves strangely.

Choose devices by control boundaries before features. Local-control and interoperable systems can reduce dependence on scattered cloud accounts when they are configured well; our interoperable smart home security build is the right place to compare that path after the old access is cleaned up. If you are choosing a hub, the Z-Wave hub selection guide is useful for deciding how much cloud tolerance you want in the rebuilt system.

Cameras and doorbells

Install cameras to document entrances, driveways, shared hallways where permitted, or other places tied to a safety plan. Do not place cameras where they create new privacy problems for children, roommates, neighbors, visitors, or the survivor. If audio recording is enabled, check your state’s consent law and the rules for the exact place being recorded; state requirements vary, and broad online summaries should not be treated as legal advice.[9]

  • Use the new owner account only.
  • Turn off public sharing and review every shared-user setting.
  • Set motion zones narrowly so the camera records useful events instead of constant noise.
  • Decide who receives alerts: the survivor, a trusted helper, or both.
  • Check whether event history can be deleted and who has permission to delete it.

Locks, entry sensors, and alarms

Locks and alarms are not just gadgets; they change who can enter and who gets blamed when something goes wrong. Before installing a smart lock, decide how physical keys, landlord access, emergency access, children’s access, and trusted-helper access will work. If the stalker ever had a key, code, garage remote, fob, or building credential, a smart lock alone does not fix the physical side.

  • Use unique codes for each trusted person instead of one shared code.
  • Set expiration dates on temporary codes.
  • Turn on entry notifications only for people who actually need them.
  • Keep a written offline plan for battery failure, phone loss, or internet outage.
  • If an order of protection or lease restriction may apply, ask an advocate or attorney before changing locks, codes, or shared-property access.

Speakers, displays, thermostats, and routines

Do not rebuild only the devices that look like security. Smart speakers can announce motion, displays can show cameras, thermostats can use geofencing, and routines can reveal bedtime, school pickup, work departure, or when someone is alone. After the reset, add back only the automations that help the safety plan.

AutomationKeep, change, or remove
Lights turn on at duskUsually safe if it does not reveal absence or a fixed bedtime.
Door unlocks when phone arrivesRemove unless you fully trust phone security, location settings, and household access.
Camera feed appears on smart displayKeep only if the display is in a private area and no shared users can view it remotely.
Thermostat switches to away modeChange if away status can be seen by another account or used to infer absence.
Speaker announces “front door opened”Keep only if it helps safety and does not expose movement to someone outside the room or account.

Set a re-check schedule while everything is still fresh

The day a system is rebuilt is the easiest day to verify it. Put the next checks on a calendar before the laptop closes. A survivor should not be left with a pile of new devices and no way to tell whether control stayed clean.

WhenWhat to re-check
After the first 24 hoursRouter device list, smart-home users, signed-in sessions, camera events, lock activity, alert delivery, and any unexpected offline devices.
After one weekUnknown devices, repeated false alerts, weak Wi-Fi spots, lock-code use, battery levels, and whether alerts are going to the right people.
MonthlyAccount recovery settings, MFA methods, app users, firmware/app updates, router firmware, IoT network device list, sensor batteries, and automation list.
After any concerning incidentScreenshot logs first, then compare device lists and account sessions against the last clean baseline.
After phone loss, roommate change, breakup, move-out, or protection-order changePasswords, recovery emails, trusted devices, lock codes, shared users, keys, fobs, garage remotes, and ISP/router ownership.

False alarms are not just annoying here. Too many bad alerts train people to ignore the one that matters, and they can create a record that is harder to interpret later. Use our smart-home security false-alarm guide to tune motion zones, placement, and notification rules without turning off the evidence you need.

Batteries deserve the same seriousness. A dead contact sensor on a side door is not a minor maintenance note if that door is part of the safety plan. The security sensor battery-drain fix can help separate normal drain from placement, signal, temperature, or pairing problems.

The end state is not “safe forever.” It is a setup with a defensible paper trail: inventoried, documented, revoked, reset where access could not be proven, rebuilt under one controlled account and network, and scheduled for re-checking.

References

  1. Resources for Survivors — NNEDV Safety Net
  2. Combating Technology-Facilitated Abuse — NNEDV
  3. Stalkerware: What To Know — Federal Trade Commission
  4. Safe Connectivity Tips for Survivors of Domestic Violence — Reviews.com
  5. Smart Home — NNEDV Safety Net
  6. The Role of Smart Home Technology in Domestic Abuse and Stalking — Violence Against Women, 2024
  7. Survivors' Guide to Cameras — NNEDV Safety Net
  8. How to Keep Your Smart Home Secure from Domestic Abusers — Wirecutter
  9. Security Camera Laws, Rights, and Rules — SafeWise

Related reading

Feedback / Question

Did a step not work as written? Let us know so it can be corrected.

Blogarama - Blog Directory