Founder's story
Why I started DSRA
I have worked in IT for most of my adult life. It still took me years to work out what had happened to my own accounts, and years more to build something that held. I had the training and the tools already in hand. Most people start without either.
It started with a business
In 2019 I ran an IT business. Over about a week, a person I had worked alongside for two years took it.
It was not a break-in. He already had the keys, because I had handed them to him over those two years. I built that access as trust, one login at a time, and he spent all of it in a week.
By the end of that week my domains were gone, I could not get into my own email, and my clients were being told I had sold the business.
I did not feel my devices were safe
After that I did not feel that my devices were safe. Not the phone, not the laptop, not any of it.
In 2022 I wrote to someone I was hoping to work for and said so plainly. This phone and this laptop are not secure. Your cameras are not secure. The computers are not secure. I was not trying to alarm him. I was telling him what I believed, because I could not promise it would stop at me. It was also the reason I had already walked away from my own company.
So I checked things, and then I checked them again. Checking never once told me a device was clean. It only told me I had not found anything that time, and there is no way to tell that apart from not having looked hard enough.
It was not only work
I have also been a victim of domestic violence. I am not going to set out the detail of that here. What belongs on this page is the overlap, and it took me a long time to see it.
Abuse of someone's phone and accounts usually begins with no hacking at all. The person already holds the access, because at some point they were meant to be safe. They set your phone up. They are on your family plan. They know your password from a time when telling them was ordinary, and years ago you added them as your recovery contact. When the relationship turns, every one of those is still live. Changing your password fixes none of it, and none of it shows up on a security checklist.
That is the same problem I had at work, arriving through a different door. It is why the first thing DSRA published was a set of free guides for people who think a partner, an ex-partner or a family member is watching their phone, and why those guides ask you to think about your safety before you delete anything.
If any of this is happening to you now: in immediate danger, call 000. 1800RESPECT, on 1800 737 732, is free, confidential and open 24 hours, for anyone affected by domestic, family or sexual violence.
I did not understand what the cloud was doing
Something else was going on the whole time and I did not see it for years.
Every device I owned kept asking me to turn more of it on. Photos backed up by default. Notes synced without my choosing it. Contacts, messages, files and backups, all of it moving off the thing in my hand and into an account. Each prompt looked like a convenience and I said yes to nearly all of them. Nobody sat me down and explained that I was putting my whole life behind one login.
Then things began going missing, one at a time. A note I knew I had written. Photos I could not find. Bitcoin I had held since early on. At the time I guessed they had been through my email and worked out I had it. I was right about the email, and I still did not draw the conclusion.
Losses that small are easy to argue yourself out of. You assume you deleted it. You assume you are misremembering which phone it was on. What I could not see was that they were not separate events.
Two terabytes, and the people who helped
In 2025 my cloud storage emptied. Around two terabytes: thirty years of personal files and sixteen years of work. Photos, notes, contacts, documents, and every backup along with them.
The physical copies I still had were encrypted with keys tied to an account I could no longer get into. Holding the disk in my hand meant nothing, and I took it for the end of it.
I still cannot prove what emptied the account. I attribute it to people with a documented history of getting into my accounts, and I am not going to pretend I can show the mechanism.
For a long time I believed the whole two terabytes had been destroyed. It turned out not to be all of it. Apple helped me recover the account, and part of what had been on it came back. Not everything, and I have had to make my peace with what did not. But I had assumed that data gone from a cloud service was gone for good, and that the help line would tell me so politely. That is not what happened, and it was the one part of all this where I asked for help and got it.
So ask. Go to the platform directly, tell them plainly what happened, and keep asking past the first answer. They could do more than I expected, and getting part of it back mattered more than I would have guessed.
I did not think to look close to home
I did not think anyone was going to go through my things. It never occurred to me. And when things did start going wrong, I did not suspect the person closest to me, because that was not a thought I was willing to have.
Every security measure I knew about assumed a stranger. A stranger guessing a password. A stranger sending a fake email from somewhere far away. None of it was built for someone already inside, who I had given the access to on purpose, and who I would have defended to your face if you had accused them.
By the time I understood, it was far too late for most of what I had already lost.
I am not telling you to go and suspect the people you love. That is a miserable way to live and it would not have saved me anyway. I am saying the opposite. Set your accounts up so that you never have to make that call. If one relationship going wrong cannot take your email, your photos and your money with it, then there is no call to make, and you can go on trusting people.
What I had wrong
I had spent six years looking at the wrong thing. The problem was the accounts.
One email address is the master key to everything else. Every password reset link, every request to add a new recovery method, every login code goes there. Whoever can read that inbox owns every account that points at it.
A device that signed in years ago stays signed in, and a phone number or backup email you added once is still a way in. It will not occur to you to go and look at either.
Wiping a phone does nothing about any of that. I wiped phones. The problem was never on the phone.
And every prompt I had said yes to over the years, every sync I turned on without thinking, had been pointing one more part of my life at that same account.
The question I ask now is who can get into this account, and what that account unlocks. Whether a device is clean barely comes into it.
What actually helped
Three things helped.
Separation. I stopped letting one account be the master key for everything. I now run a dedicated Google account for one specific set of services, kept apart from the rest of what I do, so that losing one account does not lose the lot. Blast radius is the term for this. I plan on the assumption that I can be compromised, and I work on limiting how much goes with me.
A hardware key, and nothing else. I use a physical FIDO2 security key with the fingerprint reader built into the key itself, set as the only way in. No SMS codes. No email recovery. No approve-this-prompt notification. If it is not the physical key plus my finger, the account does not open, and that holds for me as much as for anyone who has my password. It works where everything else failed because it removes the channels they used against me, rather than adding one more thing for me to watch.
Watching the recovery channel itself. The resets that cost me happened while I was asleep. A reset email lands at three in the morning, gets used, and is deleted before you wake up, so there is nothing to find by breakfast. So I built a service for that, called SAFE2RECOVER. It texts you a login code the moment one arrives, so you are not locked out waiting on slow email. It holds password reset and account recovery emails and does not release them until you approve them with a one time link. It keeps every message in an archive that survives deletion from your own mailbox, so there is still a record after someone cleans out the inbox. I built it for the failure that had already happened to me.
A disclosure, because it matters here. SAFE2RECOVER is a paid commercial service run by my own business. It is not a DSRA program, DSRA receives nothing from it, and it appears on this page only because it is part of what happened. DSRA has nothing to sell you, and that includes this.
Why this is a charity and not a business
I do this for a living. I had the skills, the tooling and the vocabulary, and it still took me years to see what was happening, and years more to build something that held.
Most people have none of that. They get told to change their password and turn on two factor authentication, and nobody tells them that the recovery email is the door, or that the old phone in the drawer is still signed in to everything.
DSRA closes that gap. We write it in plain English, for people who do not work in IT, and we give it away. There is nothing to sell and nobody to sell it to.
None of it was obvious to me at the time, and I already worked in the field.