CSIDB logo
Incident

uMobix

Incident posture

Attack window
Feb 2026
Location
Cyprus
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:16

Linked entities

Victim
uMobix
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacktivist breached the stalkerware provider uMobix and its associated mobile tracking apps Geofinder and Peekviewer, scraping the payment information of more than 500,000 customers and publishing it online as part of a campaign targeting the stalkerware industry. The incident exposed sensitive customer data due to the company's inadequate security practices, continuing a pattern of breaches affecting dozens of stalkerware operators over nearly a decade. The leak follows similar compromises of other consumer spyware apps, highlighting the industry's repeated failure to protect both customer information and the personal data of unwitting surveillance victims.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In February 2026, the makers of uMobix and its associated mobile tracking applications, Geofinder and Peofviewer, became the latest stalkerware providers to expose sensitive customer data. A hacktivist scraped the payment information of more than 500,000 customers and subsequently published this information online. According to reporting on the incident, the hacktivist stated that the action was carried out as a deliberate effort to target the stalkerware industry, drawing inspiration from two earlier hacktivist groups that had broken into Retina-X and FlexiSpy nearly a decade earlier. The incident marks at least the twenty-seventh known stalkerware company to have been hacked or to have leaked customer and victim data since 2017, and it represents yet another case in a long pattern of security failures within the consumer spyware sector.

The scope of the uMobix breach centers on the exposure of payment information belonging to more than 500,000 customers who had purchased access to the stalkerware service. While the specific contents of the scraped and published data are described in the source material as payment information, the underlying customer base represents individuals who used the service to monitor other people's phones, often in contexts involving intimate partners or family members. The leak places both these paying customers and the unwitting targets of the surveillance software at heightened risk. The broader implications extend to the wider ecosystem of stalkerware operations, as the uMobix incident follows closely on the heels of several similar events in 2025 alone, including breaches and data exposures involving Catwatchful, SpyX, Cocospy, Spyic, and Spyzie.

The uMobix incident follows a well-documented trajectory of stalkerware compromises that began in 2017, when hackers first targeted Retina-X and FlexiSpy in rapid succession, ultimately revealing a combined customer base of 130,000 users worldwide. The hackers involved in those early operations explicitly stated their motivation was to expose and disrupt an industry they viewed as toxic and unethical. Following the original breaches, Retina-X was hacked a second time in 2018, after which the company announced it was shutting down entirely. FlexiSpy, despite the hack and ongoing negative public attention, has remained active. Subsequent years saw a steady cadence of similar incidents, including hacks of Mobistealth and Spy Master Pro in 2018, theft of text messages and call metadata from SpyHuman, and an accidental data exposure by SpyFone through an unprotected Amazon-hosted S3 storage bucket.

In the years following, additional stalkerware operations suffered similar fates. mSpy, one of the longest-running stalkerware applications, was breached in 2018, exposing more than two million customer records, and was breached again in 2024, this time leaking millions of customer support tickets containing personal data. pcTattletale, a U.S.-based stalkerware maker, was hacked twice in 2021 and 2024; during the 2024 incident, an unknown hacker stole and leaked internal company data and defaced the company's website. The founder of pcTattletale, Bryan Fleming, subsequently announced he was shutting down the company and later pled guilty to charges of computer hacking, the sale and advertising of surveillance software for unlawful uses, and conspiracy. Other vendors such as TheTruthSpy have been compromised repeatedly, with breaches recorded in 2018, 2022, 2023, and 2024. Spyhide was breached in 2023, while LetMeSpy, WebDetetive, OwnSpy, and Oospy all suffered exposures that same year. WebDetetive was breached again in 2024.

The pattern also includes numerous cases of negligent data handling rather than active hacking. FamilyOrbit left 281 gigabytes of personal data protected only by an easy-to-find password. Xnore allowed customers to view the personal data of other customers' targets, including chat messages, GPS coordinates, emails, and photographs. MobiiSpy left 25,000 audio recordings and 95,000 images accessible on a publicly available server. KidsGuard suffered a misconfigured server that leaked victim content in 2020, and Xnspy's developers left credentials and private keys embedded in the apps' code, permitting anyone to access victim data. Cocospy and Spyic, in 2025, left victims' messages, photographs, call logs, and other personal data, along with customers' email addresses, exposed online. Catwatchful, also breached in 2025, exposed the full database of customer email addresses and plaintext passwords, and was used to compromise phone data belonging to at least 26,000 victims. The most recent incident prior to uMobix involved SpyTech, a spyware maker based in Minnesota, which exposed activity logs from monitored phones, tablets, and computers.

The cumulative impact of these incidents highlights the persistent failure of stalkerware companies to adequately protect both their own customers' data and the sensitive information of the individuals being surveilled. Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation and a long-time researcher and activist against stalkerware, characterized the stalkerware industry as a soft target, noting that the operators of these companies frequently lack scruples and demonstrate little concern for product quality or data security. Her assessment underscores the broader reality that customers using these applications face dual exposure: they may be breaking the law by engaging in unlawful surveillance, and they are simultaneously placing the personal data of both themselves and their surveillance targets at significant risk. The repeated nature of these breaches, with some companies compromised multiple times across different years, demonstrates that lessons from prior incidents have not translated into improved security practices across the industry as a whole.

Sources

Sources available to members: 1 source.

CSIDB