When a Tracking Device Becomes a Stalking Tool
A device designed to help someone find a lost suitcase can, in the wrong hands, do the opposite of what it was built for. This case is about exactly that reversal and what it means for anyone whose safety depends on their location staying private.
What Happened
In December 2022, two women filed a lawsuit against Apple alleging their former partners had used AirTags, Apple's coin-sized location tracking devices designed to help people find lost keys or luggage, to track their whereabouts without consent. One plaintiff found an AirTag hidden in her child's backpack after her divorce. When she removed it, another appeared later. The second, Lauren Hughes, discovered her ex-partner had placed one in her car's wheel well while she was staying at a hotel specifically to stay safe from him.
The Damage Caused
Hughes ultimately felt she had no choice but to relocate her home entirely. Her former partner had posted publicly about knowing her location, evidence that the tracking was working exactly as he intended. The lawsuit argues the underlying risk extends well beyond inconvenience. A device that reveals a person's real-time location to an abuser is a physical safety risk, not just a privacy one.
What Caused the Breach
Nothing was hacked in the technical sense. AirTags work exactly as designed: cheap, small and precise, built for a legitimate purpose and repurposed for an illegitimate one. Apple did build in a safeguard, an alert that notifies an iPhone user when an unfamiliar AirTag has been travelling with them for a period of time. That protection depended on the victim owning a recent iPhone running iOS 14.5 or later. It was also not instantaneous. Both left a window for a determined stalker to exploit.
What Could Have Been Done to Avoid the Issue
For anyone concerned about covert tracking (a risk that extends to any Bluetooth tracker, not just Apple's), a periodic physical check of vehicles, bags and outerwear for hidden devices is a simple, effective habit, particularly after a relationship ends under difficult circumstances. Apple and Android have both since improved cross-platform unknown-tracker detection. Detection still means a device already had time to log a victim's movements before it was found.
Family offices and executive protection arrangements that account for physical security should treat this as a standing item, not a one-time check: vehicles serviced by third parties, bags handled by staff or contractors, any period where personal items are out of a client's direct control, all of it is an opportunity for a tracker to be placed unnoticed.
Every security measure involves a trade-off between protection and convenience. Where that balance should sit depends on the resources a realistic attacker would bring to bear against you specifically. For most people, a handful of consistent habits closes the majority of that gap. For those whose assets or profile make a determined, well-funded attacker plausible, a more considered approach becomes worth the investment.
At Executive Privacy Advisors, we build that approach around your specific threat profile rather than a generic checklist. We extend the same thinking to your whole household, not just one set of accounts.
Ready to Understand your families risks?
Request an AuditPublished by Executive Privacy Advisors.
This article is for general informational purposes only and does not constitute security, legal or risk advice. Services described are subject to assessment, licensing and availability in your area. Your circumstances may differ and you should seek a professional assessment before making decisions.