Stalkerware’s Data Breach Epidemic: 27 Companies Exposed Since 2017

Stalkerware’s Data Breach Epidemic: 27 Companies Exposed Since 2017

The stalkerware industry, built on exploiting trust and privacy, is now hemorrhaging data—27 companies have been hacked or leaked sensitive user information since 2017.

At least 27 stalkerware companies have had data breaches or leaks since 2017, including uMobix, Catwatchful, and SpyX. Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said: "The people who run these companies are perhaps not the most scrupulous or really concerned about the quality of their product."

"The people who run these companies are perhaps not the most scrupulous or really concerned about the quality of their product."

uMobix's 2026 breach exposed payment data of 500,000 customers; Catwatchful's 2025 breach affected 26,000 victims.

The FTC banned SpyFone and its CEO in 2023 after a 2018 data exposure. Companies like Retina-X and pcTattletale shut down after breaches, but many rebranded under new names.

Stalkerware apps are often marketed to jealous partners for illegal surveillance, with victims' data left vulnerable due to poor security practices.

Hackers Trick Users into Self-Infection with Fake CAPTCHA and Hidden Malware
Hackers exploit Windows tools and public infrastructure with a fake CAPTCHA attack chain that bypasses antivirus detection using LOLBins, steganography, and Google Calendar command-and-control.
North Korean Hackers Weaponize AI to Bypass Email Filters in Blockchain Sector Attacks
North Korean hackers are using AI-assisted malware to bypass email filters and target blockchain developers through Google ad click redirection systems.