CSIDB logo
Threat actor

Retina-X Hackers

Attribution profile

Type
Activist
Location
United States of America
Known incidents
2 incidents
Sources
2 sources
First seen
2017-04-17
Last seen
2017-04-18
Updated
2026-08-01 01:40
Aliases
4 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Retina-X Hackers, also known as the Retina-X Hacker Group, Hackers of Retina-X, or Retina-X Hacker, is a threat actor identified as operating from the United States of America. The group came to public attention through a series of breaches that exposed internal data from companies producing consumer surveillance software. Their activity is primarily associated with the unauthorized acquisition and release of proprietary information from firms that market spyware tools to private individuals.

The actors specifically targeted the consumer surveillance vendors FlexiSpy and Retina-X, gaining access to internal databases and customer information. The disclosed data demonstrated that the spyware products, such as PhoneSheriff and related applications, were being used by ordinary individuals to covertly monitor the communications, locations, and personal media of others without consent. This exposure revealed widespread misuse of the technology in domestic contexts, including cases involving law enforcement personnel and private citizens, and highlighted how the software facilitated privacy violations and potential abuse. The group’s actions brought to light the extent to which commercially available surveillance tools were being employed for interpersonal monitoring rather than state‑directed espionage.

In terms of tactics, the breach involved unauthorized intrusion into the networks of the targeted companies, followed by the exfiltration of sensitive datasets that were subsequently published online. The source material does not detail specific malware families, phishing techniques, or other technical vectors used to gain initial access; it only confirms that the actors succeeded in obtaining and disseminating internal information. Consequently, the described TTPs are limited to the act of hacking the companies and leaking the stolen data.

The most prominently documented operation is the April 2017 compromise of FlexiSpy and Retina-X, which resulted in the public revelation of stalkerware usage on a global scale. Additional reporting from mid‑2021 references another incident involving Retina‑X, although the supplied sources do not provide further specifics about that event. Through these disclosures, the actor has contributed to broader awareness of the risks posed by readily available surveillance software and its potential to enable harassment and privacy intrusions.

Incidents

Attributed incidents are available to members.

2 incidents

Sources

Sources available to members: 2 sources.

CSIDB