Retina-X Hackers
Attribution profile
- Type
- Activist
- Location
- United States of America
- Known incidents
- 2 incidents
- Sources
- 2 sources
- First seen
- 2017-04-17
- Last seen
- 2017-04-18
- Updated
- 2026-08-01 01:40
- Aliases
- 4 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Retina-X Hackers, also known as the Retina-X Hacker Group, Hackers of Retina-X, or Retina-X Hacker, is a threat actor identified as operating from the United States of America. The group came to public attention through a series of breaches that exposed internal data from companies producing consumer surveillance software. Their activity is primarily associated with the unauthorized acquisition and release of proprietary information from firms that market spyware tools to private individuals.
The actors specifically targeted the consumer surveillance vendors FlexiSpy and Retina-X, gaining access to internal databases and customer information. The disclosed data demonstrated that the spyware products, such as PhoneSheriff and related applications, were being used by ordinary individuals to covertly monitor the communications, locations, and personal media of others without consent. This exposure revealed widespread misuse of the technology in domestic contexts, including cases involving law enforcement personnel and private citizens, and highlighted how the software facilitated privacy violations and potential abuse. The group’s actions brought to light the extent to which commercially available surveillance tools were being employed for interpersonal monitoring rather than state‑directed espionage.
In terms of tactics, the breach involved unauthorized intrusion into the networks of the targeted companies, followed by the exfiltration of sensitive datasets that were subsequently published online. The source material does not detail specific malware families, phishing techniques, or other technical vectors used to gain initial access; it only confirms that the actors succeeded in obtaining and disseminating internal information. Consequently, the described TTPs are limited to the act of hacking the companies and leaking the stolen data.
The most prominently documented operation is the April 2017 compromise of FlexiSpy and Retina-X, which resulted in the public revelation of stalkerware usage on a global scale. Additional reporting from mid‑2021 references another incident involving Retina‑X, although the supplied sources do not provide further specifics about that event. Through these disclosures, the actor has contributed to broader awareness of the risks posed by readily available surveillance software and its potential to enable harassment and privacy intrusions.
Incidents
Attributed incidents are available to members.
2 incidentsSources
Sources available to members: 2 sources.