Stalkerware’s Data Breach Epidemic: 27 Companies Exposed Since 2017
The stalkerware industry, built on exploiting trust and privacy, is now hemorrhaging data—27 companies have been hacked or leaked sensitive user information since 2017.
At least 27 stalkerware companies have had data breaches or leaks since 2017, including uMobix, Catwatchful, and SpyX. Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, said: "The people who run these companies are perhaps not the most scrupulous or really concerned about the quality of their product."
"The people who run these companies are perhaps not the most scrupulous or really concerned about the quality of their product."
uMobix's 2026 breach exposed payment data of 500,000 customers; Catwatchful's 2025 breach affected 26,000 victims.
The FTC banned SpyFone and its CEO in 2023 after a 2018 data exposure. Companies like Retina-X and pcTattletale shut down after breaches, but many rebranded under new names.
Stalkerware apps are often marketed to jealous partners for illegal surveillance, with victims' data left vulnerable due to poor security practices.
Recommended Reading

