goJumboGPT

Everyday Helping other people with technology

If somebody is harassing you online: a practical response

What to do first, how to document properly, which platform tools work, and when the situation becomes a police matter rather than a moderation one.

8 min read How we write

The short answer

  • Do it in this order: secure your accounts, capture the evidence with links and timestamps, then report, because reporting first often means the posts are deleted before anyone looks.
  • A dated log of incidents with platform reference numbers is what makes a case credible to a moderator, an employer, a school or a police officer.
  • Block, mute, restrict and report do different jobs, and blocking usually cuts off your own access to the posts you will later be asked to produce.
  • Threats, stalking, doxxing, impersonation for fraud and intimate image abuse are criminal matters in most countries rather than moderation questions, though the details differ by country and by US state.
  • Most doxxing is assembly from public sources, so opting out of people search sites and closing old accounts raises the cost of finding you.
  • None of this is your fault, and the advice to just ignore it works on a passing pile on but not on one determined person.

Secure your accounts, save the evidence, then report. That order matters more than anything else here. People who report first often find the posts deleted before a moderator looks. People who reply first usually get more of it, not less. What follows is the sequence that works in practice, and none of it asks you to be clever or thick skinned in response.

Lock your accounts down first

Harassment often turns into an attempted account takeover, because your own account is the fastest way to humiliate you and to reach people who trust you. Half an hour here removes the worst version of the week.

  • Change your email password first. Email is the reset route for everything else you own.
  • Turn on two factor authentication on email and on every targeted account. An app or a security key is harder to defeat than a text message, for the reasons in how second factors work.
  • Check the recovery phone and email on each account, since anyone who got in briefly may have added their own. Doing account recovery properly once covers every future incident.
  • Review active sessions and connected apps, and sign out everything you do not recognize.
  • Change old security question answers. Mother's maiden name and first school are often sitting on a public profile.
  • Run your main addresses through a breach checker, because a reused password from an old leak is the usual way in, and checking whether a password has leaked takes two minutes.

If someone close to you is involved, or was, check the device too: shared logins, a family plan, location sharing, an old laptop still signed in. Access often survives a relationship ending.

Document before anything disappears

Posts get deleted, accounts get suspended, messages expire. Evidence you did not capture never existed as far as a platform, an employer, a school or a police officer is concerned.

For each item, screenshot the surrounding page rather than a tight crop of the words. Copy the full web address of the post. Note the account name, the handle and, where the platform shows one, the numeric profile identifier, because handles change and that number does not. Screenshot the profile, and record date, time and time zone.

Keep a running log in a spreadsheet: date, platform, account, what was posted, the link, whether you reported it, and the reference number you were given. One ordered list of forty entries is taken seriously in a way that forty loose screenshots in a camera roll are not. Keep a copy off your phone, do not edit the originals, and export the message thread if the platform allows it.

Block, mute and report: what each one does

These tools do different jobs and people reach for the wrong one. Some tip off the other person, and some cost you access to the evidence.

ActionDo they find outWhat it changesBest used when
BlockUsually, when they try to view youYou each disappear from the other, so capture firstOne identified account you want gone
Mute or restrictNoYou stop seeing it, they carry on unawareYou want to stop reading but keep watching for escalation
Report the postNoNothing until a moderator acts on that itemSpecific content that breaks a stated rule
Report the accountNoReviewed as a pattern, usually more slowlyMany posts, with examples attached
Keyword filtersNoHides matching replies from your view onlyA pile on using the same insults
Go private or limit repliesOnly that your account changedCuts off new contact from strangersA wave rather than one person

Reports get acted on more often when they are specific. Report individual items as well as the account, pick the category that genuinely fits (a threat filed as spam lands in the wrong queue), and keep the note factual. Do not organize friends to mass report one post, since platforms watch for coordinated reporting and it can weaken your case. Save the reference, and if the answer is no violation, use the appeal link.

Your leverage depends on where you are. EU platforms must let you flag illegal content, give a reason for the decision and offer a challenge route, and the UK now requires large services to act on illegal content. In the US you are mostly relying on the platform's own rules. If the material sits on an ordinary website, the host and the domain registrar have abuse contacts, and search engines run removal forms for some categories of personal information in results.

When it stops being a moderation problem

Some conduct is a crime rather than a rule violation, and it should go to the police as well as the platform. This is general information rather than legal advice, and the detail differs by country and, in the United States, by state.

Take it to the police for any of these: a credible threat of violence; a sustained course of conduct that fits stalking, including tracking your movements or turning up where you are; publication of your home address, workplace or children's school in a context that invites others to act; intimate images shared or threatened without your consent; impersonation used to defraud or endanger you; blackmail, including sextortion demands; or anything targeting a child.

Go in with the log printed in date order, worst items flagged, reference numbers listed. Ask for a crime reference number and the officer's name. If the answer is that it is a civil matter, ask for it to be recorded anyway, then ask about the specific offense: many places have separate laws on harassment, malicious communications, stalking and image based abuse, and the right label changes the answer. A civil protective order is often available as a separate route.

For intimate images, free services exist that make a digital fingerprint of the picture so participating platforms can block it without you sending the image anywhere. StopNCII covers adults, Take It Down covers anyone under eighteen when the image was made. Do not pay a sextortion demand, and if you already paid, follow the first hour after sending money to a scammer.

Shrink what a stranger can find

Most doxxing is assembly rather than hacking. Someone collects an old forum handle, a race result, a property record, a relative's public friend list and a photo with a recognizable window, and produces an address. You cannot remove everything, but you can raise the cost.

Start with people search and data broker sites, which republish public records and marketing data. Each has an opt out form, they are slow, and listings reappear, so recheck every few months. Then close old accounts, properly: an abandoned profile with your real photo and an old username links two identities, and deleting an account properly rather than just logging out covers what gets removed. Tighten who can see friend lists, tags and old posts, and keep your public handle separate from the email tied to your real name.

Some of this you can demand. In the EU and UK you can ask a company what it holds about you and require deletion, and several US states now give similar rights: what you can ask a company to do with your data covers how to send the request. If identity documents or a national identity number were exposed, also work through the early signs and first moves for identity theft.

The people around you

Harassment rarely stays between two accounts. It runs through a group chat, a class, a team or a workplace, and the people in the middle make it better or worse. Ask one trusted friend to be your filter: they read your mentions, add to the log, and tell you only what is new or serious. Send the well meaning screenshot forwarders to that person instead.

Do not counter attack, however deserved it feels. The moment you post something that breaks the same rules, it becomes a two sided dispute, and moderators and police treat those differently. Keep your side of the record boring.

If a young person is being targeted, say first that you will not take the device away, because losing contact with friends is the main reason children do not tell an adult. Then capture, report and involve the school, which usually has a duty to act even when the conduct happened outside school hours. Agreeing a family tech setup in advance makes that talk easier. If the target is an older relative, use the approach in helping an older relative without taking over, so they keep control and know what changed.

What to do next

Today: email password changed, two factor on, sessions cleared, the last ten items captured with links, the log started. This week: reports filed with reference numbers, privacy settings tightened, one trusted person briefed, and a police report if any line above was crossed. Ongoing: opt outs repeated, log kept current, mentions checked weekly rather than hourly.

Be honest about the toll. Broken sleep, a jumpy reaction to notifications and avoiding your own accounts are normal responses to being targeted, not signs that you are overreacting. Many countries run a helpline for harassment or image based abuse, and employee assistance programs usually cover it. The advice to just ignore it is half right: not feeding a pile on drains it, but it does nothing about one determined person, and that needs the record, the reports and sometimes the police.

Common questions

Should I reply to someone harassing me online?

No, and not because you would lose the argument. A reply gives the account the reaction it wants, it pushes the exchange to more people through the platform's own recommendations, and anything you write in anger becomes part of the record a moderator or officer reads later. Capture what was said, report it, and let your side of the log stay dull and factual.

Does blocking someone destroy the evidence?

It can remove your access to it. On many platforms a blocked account becomes invisible to you, so posts you never captured are effectively gone. Screenshot everything first, save the links and profile identifiers, then block. The material still exists on the platform's servers, but you no longer have a way to show anyone what it was.

Can I find out who is behind an anonymous account?

Usually not by yourself, and trying can backfire. Platforms only disclose account details to police or under a court order, and the amateur methods that circulate online often identify the wrong person. Your effort is better spent on evidence and reports. If police take the case, they have a legal route to the account data that you do not.

The police told me it was a civil matter, what do I do now?

Ask for the report to be recorded and get a reference number anyway, then go back with specifics. Name the pattern rather than a single message: repeated contact after you asked them to stop, threats, publication of your address, or intimate images. Many places also allow a civil protective order, and some have a dedicated cybercrime unit that takes a different view from a front desk.

Someone posted a fake or edited image of me, can I get it taken down?

Yes, in most cases. Report it under the platform's rules on impersonation, non consensual imagery or synthetic media, and say clearly that the image is fabricated. If it is sexual in nature, the hashing services for image based abuse accept it. You may also have a copyright claim if the original photo was one you took yourself.