CSIDB logo
Incident

Catwatchful

Incident posture

Attack window
2025
Location
-
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:40

Linked entities

Victim
Catwatchful
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A security breach at Catwatchful, a stalkerware application, exposed the phone data of approximately 26,000 victims. The incident compromised sensitive information including the full database of customer email addresses and plaintext passwords. As a consumer spyware service marketed for surreptitious monitoring of individuals—often without their knowledge or consent—the platform's exposure resulted in significant unauthorized access to both customer credentials and victim surveillance data. The breach underscored the ongoing pattern of security failures within the stalkerware industry, where companies have repeatedly demonstrated an inability to protect the sensitive personal information they collect from both paying customers and the unsuspecting individuals being monitored.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In 2025, Catwatchful, a consumer-grade stalkerware application marketed for covertly monitoring another person's phone, suffered a security breach that resulted in the exposure of its full customer database. According to reporting from TechCrunch, the leak compromised the email addresses and passwords of Catwatchful's customers, stored in plaintext. The application itself was being used to collect phone data from at least 26,000 victims, meaning that the exposure of operator credentials had direct downstream consequences for the individuals whose devices had been compromised by the spyware.

The breach of Catwatchful occurred as part of a broader wave of stalkerware security failures throughout 2025. In the same year, security researchers identified a bug affecting the related surveillance operations Cocospy, Spyic, and Spyzie, which left the messages, photos, call logs, and other personal and sensitive data of millions of victims exposed online. The campaigns shared overlapping infrastructure, and the discovery of the underlying vulnerability allowed a single researcher to access the data of all three operations. The Catwatchful incident was also preceded by major stalkerware breaches in 2024, including the exposure of activity logs from devices monitored using SpyTech spyware and the breach of mSpy, during which millions of customer support tickets containing personal data of customers were exposed. The mSpy breach was the second time the company had suffered a major security incident, following an earlier exposure of more than two million customer records in 2018.

The consequences of these recurring incidents have extended beyond data exposure. After the 2024 breach of pcTattletale, in which an unknown hacker stole and leaked internal company data and defaced the company's website, the company's founder, Bryan Fleming, announced that he was shutting down the operation. Fleming subsequently pled guilty to charges of computer hacking, the sale and advertising of surveillance software for unlawful uses, and conspiracy. The pattern of stalkerware compromises stretches back to 2017, when hacktivist groups first targeted Retina-X and FlexiSpy, revealing a combined customer base of roughly 130,000 worldwide. Retina-X was breached again in 2018, after which it announced its permanent shutdown, while FlexiSpy continued to operate despite repeated adverse publicity.

The specific scope of the Catwatchful breach included the entire database of customer email addresses and plaintext passwords, alongside the underlying pool of at least 26,000 victim devices being actively monitored by those customers. This dual exposure meant that both the operators of the spyware and the targets of the surveillance had their personal information compromised as a direct result of the company's failure to secure its infrastructure. The incident reinforced concerns raised by Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, who characterized the stalkerware industry as a "soft target" due to operators' apparent lack of investment in product security and data protection.

The broader stalkerware ecosystem has experienced at least 27 known hacks or significant data exposures since 2017, with multiple companies, including TheTruthSpy, WebDetetive, pcTattletale, mSpy, and Xnspy, having been breached on more than one occasion. Other incidents in this period included the breach of Mobistealth and Spy Master Pro in 2018, which resulted in the theft of gigabytes of customer and victim records including intercepted messages and GPS coordinates, and the 2018 breach of SpyHuman, which exposed text messages and call metadata. That same year, mSpy leaked over two million customer records, and Xnore exposed the personal data of victims across its customer base, including chat messages, GPS coordinates, emails, and photos. Copy9 was also breached in 2018. In 2019, MobiiSpy left 25,000 audio recordings and 95,000 images on a publicly accessible server. KidsGuard suffered a server misconfiguration in 2020 that leaked victims' content, and pcTattletale had previously exposed real-time screenshots of victims' devices on a publicly accessible website prior to its later 2024 hack.

Following the discovery of the Catwatchful breach, the application ceased active operations, though the lasting impact of the incident continued to affect both former customers and the victims whose devices had been monitored. Security researchers and journalists covering the stalkerware industry noted that the recurrence of such breaches demonstrates a systemic inability or unwillingness among stalkerware operators to implement adequate security controls for the highly sensitive data they collect. The breach is frequently cited alongside the 2025 Cocospy, Spyic, and Spyzie exposures as evidence of the risks inherent in using consumer spyware applications marketed for covert monitoring, regardless of whether the intended use case involves monitoring a romantic partner or another individual.

Sources

Sources available to members: 1 source.

CSIDB