Header illustration for "What a stranger can learn about an Australian from one email address — and the lockdown that stops it"

"What a stranger can learn about an Australian from one email address — and the lockdown that stops it"

What a stranger can learn about an Australian from one email address — and the lockdown that stops it

Free OSINT tools have changed the economics of stalking. A single Gmail address, pasted into an open-source tool such as Ghunt — which Hackers Arise uses as a teaching case — can reveal a public profile photo, a display name, Google Photos history with rough dates, publicly shared calendars and reviews left across Google services. None of that is a "hack." It is the aggregation of what a platform exposes by default, and aggregation is what makes it dangerous.

Why this matters specifically in Australia

The Office of the Australian Information Commissioner's privacy tips for individuals start from a simple premise: you cannot protect information you do not know is exposed. Most Australians have never audited what their Google, Apple or Microsoft accounts show strangers. Domestic-violence services report the same pattern constantly: a control situation that seemed purely physical turns out to run on digital breadcrumbs — shared calendars showing the weekly schedule, photo libraries exposing home interiors and location clusters, review histories triangulating favourite venues.

The eSafety Commissioner treats cyberstalking as a live, growing harm category and publishes reporting pathways for Australian victims. Where the conduct involves threats, tracking or harassment, it is also a matter for police — OSINT awareness is protection, not prosecution material for private individuals to run against someone else.

The one-hour lockdown audit

Defensive steps, for your own accounts only:

Google. Run a self-hunt first. Check what your calendar shares publicly (Settings → Sharing), scrub shared album history in Photos, review Google Account → Security → Third-party access, and set your profile's public visibility to the minimum. Ghunt works because calendar sharing and public photos persist for years.

Cross-platform hygiene. Use unique email aliases per service so one address cannot join your accounts into a dossier. Our own degoogled phone builds and the OS choice comparison guide cover the hardware end of reducing platform exposure (our own stock — disclosed).

Location minimisation. Turn off timeline/location-history features; review which apps hold always-on location. On iOS and Android both, audit this twice a year.

Detection of active tracking. Check for unfamiliar devices in account security pages, and for Bluetooth trackers in your bag or car — both Android and iOS now have built-in unknown-tracker alerts. The eSafety Commissioner's cyberstalking resources include device-check guidance for people escaping controlling relationships; the safest sequence when leaving an abusive situation is coordinated help, not unilateral account changes that a controlling partner will notice.

The gap the law hasn't closed

Australia's Privacy Act regulates organisations, not individuals scraping public platforms — so a stalker operating on their own behalf is largely outside OAIC enforcement reach. The practical defence is exposure reduction: make the free dossier thin enough that aggregation stops paying. That is an afternoon of settings work, and it needs repeating roughly annually as platforms change defaults.

This article is general information, not legal advice. It is written defensively: for your own accounts and, where relevant, people you are helping with their consent. Investigating another person's accounts may be unlawful in Australia.

Sources: Hackers Arise — Investigating Google Accounts with Ghunt · OAIC — Tips to protect your privacy · eSafety Commissioner — Cyberstalking

Header image: Wikimedia Commons, "Hand holding smartphone with blank white screen" by Santeri Viinamäki, CC BY-SA 4.0.

← All posts