Menu
Browse

Cyber Threat Actor: Retina-X Hacker

Aliases: 4 aliases
Actor Type Location Known Incidents
 Icon
Activist
United States of America
2 incidents
Profile

The threat actor known as the Retina‑X hacker, also referred to as Retina‑X Hackers, Retina‑X Hacker Group, or Hackers of Retina‑X, has been identified in public reporting. Open‑source indicators place the actor’s location within the United States of America. The actor came to prominence through the compromise of internal systems belonging to the consumer surveillance firms Retina‑X Studios and FlexiSpy. These intrusions were disclosed in mid‑April 2017 and were later discussed in subsequent media coverage. The actor’s activity is therefore linked to the exposure of data from companies that market mobile‑phone monitoring software.

The leaked data revealed that Retina‑X’s products, including the PhoneSheriff application, enabled purchasers to covertly monitor target devices. Once installed, the software could capture text messages, GPS locations, photographs and other personal information without the device owner’s knowledge. One publicly cited example involved a police officer in the southwestern United States whose spouse used the software to view his messages, track his movements and obtain images of him on duty. The breach also showed that FlexiSpy’s comparable tools offered similar capabilities, allowing unauthorized access to communications and location data. Collectively, the exposed records indicated that tens of thousands of individuals worldwide had acquired such stalkerware for personal use.

The disclosures underscored how consumer‑grade surveillance tools, which share some functionalities and occasionally code with government‑grade spy software, had moved into the hands of ordinary citizens. Reporting noted that buyers included lawyers, teachers, construction workers, parents and jealous lovers, illustrating a broad domestic market. Security researchers cited the incident as evidence that stalkerware facilitates privacy violations and can be employed in interpersonal abuse and harassment. By making the internal data public, the actor brought attention to the prevalence of commercially available spy tools that enable persistent, undetected monitoring. The episode remains a reference point for discussions about the risks posed by readily purchasable monitoring software.

Incidents
Attributed incidents available to members
2 incidents
Sources
Sources available to members
3 sources