They reply to things you never told them. They reference a private conversation with your sister, or a plan you only discussed with your lawyer. If that sounds familiar, you are asking the right question — and you deserve a better answer than “you’re being paranoid”.

Here is the reassuring and unsettling truth in one sentence: an ex-partner reading your messages after separation is common, and it usually does not involve anything as exotic as hacking or spyware. In most cases it happens through ordinary features of your own accounts — features that were set up, often legitimately, during the relationship, and were never switched off. That matters, because it means the problem is usually findable and fixable. It also matters legally: accessing someone’s accounts or communications without authorisation is unlawful, and the eSafety Commissioner recognises this kind of technology-facilitated abuse as a form of domestic abuse in its own right.

Below are the pathways we see most often, roughly in order of how frequently they explain the “how does he know?” question.

Linked devices: WhatsApp Web and messaging apps

WhatsApp, Signal, Telegram and others let you link additional devices — a laptop browser, a desktop app, a tablet. Every message then appears on every linked device, silently and indefinitely.

The classic scenario: at some point during the relationship, your WhatsApp was linked to the shared home computer, or to their laptop “just to send some photos”. Years later, that session may still be active, mirroring every conversation you have. Nothing about your phone looks or behaves differently.

You can check this yourself: in WhatsApp, Settings → Linked Devices lists every active session. Similar lists exist in Signal and Telegram. Before you log anything out, though, read the section on evidence below — the list of linked devices, and when they were linked, is itself proof.

Old devices still signed into your accounts

An account does not live on one device; it lives wherever it is signed in. An old iPhone in a drawer at your former home, still signed into your Apple ID, continues to receive your iMessages. An iPad the kids used, a spare Android phone, the old laptop — any of them can quietly deliver your messages, email and photos to whoever holds them.

Both Apple and Google let you view every device signed into your account (Apple ID settings on iPhone; Google’s device activity page). Devices you do not recognise, or recognise all too well, are worth photographing before removing.

Backups and shared Apple or Google IDs

Two related pathways here. First, shared IDs: plenty of couples ran one Apple ID or Google account across the household. If any of your apps, backups or messaging still touch a shared ID, the other person has the same access you do — not by intrusion, but by design.

Second, backups: if your phone backs up to an iCloud or Google account the other person can access, they do not need your phone at all. Message histories, photos and more can be read from the backup, or restored onto another device entirely. Backups of your data to their account (or a shared one) are one of the least visible and most complete forms of post-separation access.

Email forwarding rules and mailbox access

Email deserves special attention because it is the master key: whoever reads your email can reset your other passwords. Common set-ups we encounter:

  • a forwarding rule quietly sending copies of every email (or emails from particular senders, such as your lawyer) to another address — rules survive password changes and are easy to miss;
  • filters that forward and then delete, so you never see the message at all;
  • delegate or “send on behalf” access granted long ago;
  • connected apps or mail clients on their devices still syncing your mailbox.

Check your mail settings for rules, filters, forwarding addresses and connected devices. In Gmail, the “Last account activity” details at the bottom of the inbox show recent sessions and locations.

Recovery details still pointing at your ex

The quietest pathway of all: your account’s recovery phone number or recovery email is still theirs. It gives them nothing day-to-day — until they use “forgot password” and receive the reset code. Recovery details also explain the frustrating pattern where you change your password and are locked out or compromised again weeks later. When you audit accounts, recovery settings matter more than the password itself.

Signs of compromise worth noting

No single sign is conclusive, but patterns are:

  • they know the contents of conversations or emails, not just facts they could guess;
  • security emails about logins, password resets or new devices you did not trigger;
  • emails appearing as read that you never opened, or missing entirely;
  • messages marked as delivered on devices you no longer use;
  • sudden lockouts, or settings that change themselves;
  • the timing tell: they react to something within hours of you writing it.

Keep a simple, dated note of these incidents on a safe device — a friend’s phone or a library computer, not the account or device in question. Patterns documented over weeks are far more persuasive than a single strange event.

Before you change everything: evidence, then lockout

The instinct on realising what is happening is to change every password tonight. Two cautions first.

Locking them out announces that you know. Sessions ending and passwords changing are visible to someone with access, and discovery can affect your safety. If there is any history of abuse or volatility, time this step as part of a safety plan — 1800RESPECT (1800 737 732) can help you think it through, and if you are ever in immediate danger, call 000.

Logging out destroys the record. Active sessions, linked devices, forwarding rules and access logs are evidence of unauthorised access — evidence that can support a protection order or family law position. Once you remove them, that record may be unrecoverable. Screenshot what you safely can, but be aware that screenshots are the weakest form of this evidence; a forensic preservation of the account data captures sessions, rules and access history in a verifiable, court-ready form (we explain the difference in Screenshots vs Forensic Extraction).

There is also the question of certainty. Guessing “I think he’s in my email” is stressful and legally weak. A forensic examination of your phone and accounts can establish what was accessed, from where, and when — or give you the equally valuable answer that the accounts are clean and the explanation lies elsewhere. Either way, you stop guessing.

Once evidence is preserved (or you have decided it is not needed), work through a full clean-up in the right order — new passwords, recovery details, sessions, two-factor authentication. Our companion article, Securing Your Phone and Accounts After Separation, is a step-by-step sequence for exactly that.

Digital Forensics Group helps people across Australia and New Zealand confirm or rule out account compromise discreetly, and preserves what is found so it stands up in court. See how we assist on our domestic violence page, or contact us confidentially on +61 499 475 408 from a safe device.