CSIDB logo
Incident

mSpy

Incident posture

Attack window
2024
Location
United Kingdom
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:58

Linked entities

Victim
mSpy
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The stalkerware provider mSpy, one of the longest-running consumer spyware apps, suffered a major breach in which millions of customer support tickets were exposed, containing the personal data of millions of its customers. A separate, earlier incident resulted in over 2 million customer records being leaked due to inadequate data security practices. These compromises were part of a broader pattern affecting the stalkerware industry, where companies have repeatedly failed to protect sensitive customer and victim information, exposing data such as support communications, personal identifiers, and other private records.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

mSpy, one of the longest-running stalkerware applications, has been affected by two distinct security incidents, the first occurring in 2018 and the second in 2024. The 2018 incident involved a data exposure in which more than 2 million customer records were leaked online, representing a significant compromise of sensitive information belonging to the platform's user base. This early breach placed mSpy among the first wave of stalkerware companies to experience major data security failures, alongside other vendors such as Retina-X, FlexiSpy, Mobistealth, Spy Master Pro, SpyHuman, SpyFone, and FamilyOrbit, all of which suffered hacks or data exposures during 2017 and 2018. The exact method of the 2018 mSpy exposure is not detailed in available reporting, though the scale of over 2 million records suggests a substantial database or backup was made accessible without adequate protection.

The 2024 incident involved a different type of compromise, in which millions of customer support tickets were exposed. These tickets contained personal data belonging to millions of mSpy customers, representing a different category of sensitive information than the 2018 leak. The exposure of customer support tickets is particularly notable because such records often contain detailed communications between customers and the company, potentially including identifying information, account details, and descriptions of the surveillance activities being conducted. This 2024 breach occurred during a period when multiple stalkerware companies were experiencing security failures, including pcTattletale, which was hacked that same year leading to the theft and public leaking of internal data and the defacement of the company's website. The pcTattletale hack ultimately resulted in the company's founder, Bryan Fleming, announcing the shutdown of the operation, and later pleading guilty to charges of computer hacking, the sale and advertising of surveillance software for unlawful uses, and conspiracy. Spytech, a Minnesota-based spyware maker, also suffered a breach in 2024 that exposed activity logs from monitored phones, tablets, and computers.

The recurring nature of mSpy's security failures, with confirmed incidents in 2018 and 2024, demonstrates a pattern of inadequate data protection practices affecting the same company across multiple years. This pattern aligns with broader observations about the stalkerware industry as a whole, which has been characterized as a "soft target" by cybersecurity researchers due to what has been described as insufficient concern for product quality and customer data protection. Between mSpy's two breaches, the stalkerware industry experienced dozens of similar incidents affecting companies including KidsGuard in 2020, Spyhide in 2023, LetMeSpy in 2023, WebDetetive in 2023 and 2024, OwnSpy in 2023, and Oospy in 2023. The cumulative effect of these breaches across the industry has exposed the personal data of tens of thousands of unwitting victims whose phones and devices were monitored without their knowledge or consent, including text messages, call logs, photos, GPS locations, and other sensitive communications. mSpy's repeated appearance in lists of compromised stalkerware companies underscores the persistent vulnerability of consumer spyware applications and the ongoing risk such platforms pose to both their customers and the individuals being surveilled through their software.

Sources

Sources available to members: 1 source.

CSIDB