fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

#stalkerware

1 post1 participant0 posts today

"A consumer-grade spyware operation called SpyX was hit by a data breach last year, TechCrunch has learned. The breach reveals that SpyX and two other related mobile apps had records on almost two million people at the time of the breach, including thousands of Apple users.

The data breach dates back to June 2024 but has not been previously reported, and there is no indication that SpyX’s operators ever notified its customers or those targeted by the spyware.

The SpyX family of mobile spyware is now, by our count, the 25th mobile surveillance operation since 2017 known to have experienced a data breach, or otherwise spilled or exposed their victims’ or users’ data, showing that the consumer-grade spyware industry continues to proliferate and put people’s private data at risk.

The breach also provides a rare look at how stalkerware like SpyX can also target Apple customers.

Troy Hunt, who runs data breach notification site Have I Been Pwned, received a copy of the breached data in the form of two text files, which contained 1.97 million unique account records with associated email addresses."

techcrunch.com/2025/03/19/data

TechCrunch · Exclusive: Data breach at stalkerware SpyX affects close to 2 million, including thousands of Apple users
More from Zack Whittaker

#Amazon is still hosting #stalkerware victims' data weeks after breach alert
#Cocospy, #Spyic, and #Spyzie, have collectively compromised over 3.1 million Android phones, which we know because apps each had a #databreach in Feb.
As part of our investigation into stalkerware operations, which included analyzing the apps themselves, TechCrunch found that some of the contents of a device compromised by the stalkerware apps are being uploaded to storage servers run by #AWS.
techcrunch.com/2025/03/13/amaz

TechCrunch · Amazon is still hosting stalkerware victims' data weeks after breach alert | TechCrunch
More from Zack Whittaker

Here’s Week 9 of the #Privacy Roundup:

- #Mozilla @mozillaofficial updates #Firefox privacy notice, adds Terms of Use
- Edge Canary disabling manifestv2 extensions
- DOGE allegedly exposing sensitive endpoints to the public internet
- More PII leaks by #stalkerware apps
- Surveillance tech in the office is very… invasive
- #Signal @signalapp threatens to cease operations in Sweden if e2e encryption is forced to be backfired by law

… and more, of course.

#privacymatters #cybersecurity #security

avoidthehack.com/privacy-week9

Imagine someone having access to every message you send, every photo you take, and knowing exactly where you are at all times. This isn't science fiction - it's happening right now to thousands of people

techcrunch.com/2025/02/27/spyz

TechCrunch · Spyzie stalkerware is spying on thousands of Android and iPhone users | TechCrunch
More from Zack Whittaker
Replied in thread

@sambowne

"With Cocospy and Spyic, you can usually enter ✱✱001✱✱ on your Android phone app’s keypad and then press the “call” button to make the stalkerware apps appear on-screen — if they are installed. This is a feature built into Cocospy and Spyic to allow the person who planted the app on the victim’s device to regain access. In this case, the feature can also be used by the victim to determine if the app is installed."

#stalkerware
#android
#Cocospy
#Spyic

A security vulnerability in a pair of phone-monitoring apps is exposing the personal data of millions of people who have the apps unwittingly installed on their devices, according to a security researcher who found the flaw.
#Stalkerware #Cocospy
techcrunch.com/2025/02/20/stal

TechCrunch · Exclusive: Stalkerware apps Cocospy and Spyic are exposing phone data of millions of people
More from Zack Whittaker

Security researcher details 2 bugs in “popular” spyware/stalkerware apps Cocospy and Spyic. 1) Exposes the personal data of millions of people who have the apps unwittingly installed on their devices. Data includes messages, photos, and call logs. 2) Exposes the email addresses of the people who signed up with the intention of planting the app on someone’s device to covertly monitor them.

Researchers collected > 2M million email addresses of the spyware’s customers. These mobile stalkerware apps share the same source code and are apparently linked to Chinese software developers.

techcrunch.com/2025/02/20/stal #security #spyware #cybersecurity #systemservice #mobilephone #china #stalkerware #Cocospy #Spyic #privacy

9) I personally like using #Ungoogledchromium and #Librewolf as my browsers of choice if not using the Tor network. But my number one browser on all of my devices is Tor Browser.
10) Always set good #passwords on all your devices. Set the autolock feature to require a password each time your screen goes dark. Don’t give your password to anyone and if it is within your threat model scan your device for #stalkerware or other #malware. stopstalkerware.org/ 4/4

stopstalkerware.orgCoalition Against Stalkerware (EN)