Close Menu
TechBrunchTechBrunch
  • Home
  • AI
  • Apps
  • Crypto
  • Security
  • Startups
  • TechCrunch
  • Venture

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Mississippi's Age Guarantee Act Tests Decentralized Social Networks

August 28, 2025

Threads test how to share long format text on the platform

August 28, 2025

Do you hire AI, or are you a human being? Next frontier for Startup Ops in 2025

August 28, 2025
Facebook X (Twitter) Instagram
TechBrunchTechBrunch
  • Home
  • AI

    OpenAI seeks to extend human lifespans with the help of longevity startups

    January 17, 2025

    Farewell to the $200 million woolly mammoth and TikTok

    January 17, 2025

    Nord Security founder launches Nexos.ai to help enterprises move AI projects from pilot to production

    January 17, 2025

    Data proves it remains difficult for startups to raise capital, even though VCs invested $75 billion in the fourth quarter

    January 16, 2025

    Apple suspends AI notification summaries for news after generating false alerts

    January 16, 2025
  • Apps

    Mississippi's Age Guarantee Act Tests Decentralized Social Networks

    August 28, 2025

    Threads test how to share long format text on the platform

    August 28, 2025

    New AI features in WhatsApp allow you to rearrange and adjust the tone of your message

    August 27, 2025

    Google and Grok are catching up to ChatGpt, says the latest AI report from A16Z

    August 27, 2025

    Google Vids adds AI avatars to the video editor and launches the consumer version

    August 27, 2025
  • Crypto

    Coinbase CEO explains why he fired an engineer who didn't try AI right away

    August 22, 2025

    Your next customer is destroying the 2025 Expo floor

    August 19, 2025

    Crypto Company Gemini File for Winklevoss Twins IPO

    August 16, 2025

    North Korean spies pretending to be remote workers have invaded hundreds of businesses, CloudStrike says

    August 4, 2025

    Telegram's Crypto Wallet will be released in the US

    July 22, 2025
  • Security

    According to Transunion, hackers say they stole the personal information of 4.4 million customers

    August 28, 2025

    The FBI says that China's salt typhoon has hacked at least 200 US companies

    August 27, 2025

    US sanctions fraud network used by North Korea's “remote IT workers” to steal money for work

    August 27, 2025

    Doge uploads live copies of Social Security databases to “vulnerable” cloud servers, whistleblower says

    August 26, 2025

    Security researchers map hundreds of Teslamate servers spilling Tesla vehicle data

    August 26, 2025
  • Startups

    7 days left: Founders and VCs save over $300 on all stage passes

    March 24, 2025

    AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

    March 24, 2025

    20 Hottest Open Source Startups of 2024

    March 22, 2025

    Andrill may build a weapons factory in the UK

    March 21, 2025

    Startup Weekly: Wiz bets paid off at M&A Rich Week

    March 21, 2025
  • TechCrunch

    OpenSea takes a long-term view with a focus on UX despite NFT sales remaining low

    February 8, 2024

    AI will save software companies' growth dreams

    February 8, 2024

    B2B and B2C are not about who buys, but how you sell

    February 5, 2024

    It's time for venture capital to break away from fast fashion

    February 3, 2024

    a16z's Chris Dixon believes it's time to focus on blockchain use cases rather than speculation

    February 2, 2024
  • Venture

    Do you hire AI, or are you a human being? Next frontier for Startup Ops in 2025

    August 28, 2025

    From streaming to healthcare to AI, Mark Cuba reveals his “formula of confusion”

    August 27, 2025

    Uncork Capital in a 21-year venture cycle – and what's the difference between this?

    August 26, 2025

    A16z spends $1.49 million on lobbying in Washington, with rivals mostly going outside

    August 25, 2025

    Openai warns against SPVs and other “unauthorized” investments

    August 23, 2025
TechBrunchTechBrunch

Data breach exposes millions of mSpy spyware customers

TechBrunchBy TechBrunchJuly 11, 20248 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Telegram Email


A data leak at phone monitoring service mSpy has exposed millions of customers who purchased access to phone spyware apps over the past decade, and the Ukrainian company behind them.

In May 2024, unknown attackers stole millions of customer support tickets from mSpy, including attachments such as personal information, emails to support, and personal documents. Hacking of spyware providers is becoming increasingly common, but it still attracts attention because the data often contains highly sensitive personal information – in this case, information about customers who use the service.

The hack included customer service records dating back to 2014 that were stolen from a customer support system powered by spyware maker Zendesk.

mSpy is a phone monitoring app that is advertised as a way to track children and monitor employees. Like most spyware, this app is widely used to monitor people without their consent. This type of app is also known as “stalkerware” because it is often used by people in romantic relationships to spy on their partners without their consent or permission.

The mSpy app allows the spyware planter (usually someone who has had physical access to the victim's phone) to remotely view the contents of the phone in real time.

As is common with phone spyware, mSpy customer records contain emails from people seeking assistance in secretly tracking the phones of partners, relatives, and children, according to an exclusive review of the data by TechCrunch. These emails and messages include customer support requests from multiple senior U.S. military officials, a sitting U.S. federal appeals court judge, a U.S. government watchdog, and an Arkansas county sheriff's office seeking a free trial license for the app.

Even after collecting millions of customer service tickets, the leaked Zendesk data likely represents only a portion of mSpy's entire customer base who contacted customer support, and the number of mSpy customers is likely much higher.

However, more than a month after the leak, mSpy's owner, Ukraine-based Brainstack, has yet to acknowledge or publicly disclose the breach.

Troy Hunt, who runs the data breach notification site Have I Been Pwned, obtained a copy of the entire leaked dataset and added approximately 2.4 million unique email addresses of mSpy customers to the site's catalogue of past data breaches.

Hunt told TechCrunch that he contacted several “Have I Been Pwned” subscribers with information about the breached data, and that the leaked data was confirmed to be accurate.

According to a list recently compiled by TechCrunch, mSpy is the latest cell phone spyware campaign to be hacked in recent months. The mSpy breach shows once again that spyware makers can hardly trust their customers' and victims' data to be kept safe.

Millions of mSpy customer messages

TechCrunch analyzed the leaked dataset – more than 100GB of Zendesk records – which included millions of individual customer service tickets and their corresponding email addresses, as well as the content of those emails.

Some of the email addresses belonged to unwitting victims targeted by mSpy customers. The data also shows that several journalists contacted the company for comment after the company's last leak in 2018. US law enforcement agencies have also served or attempted to serve subpoenas and legal demands on mSpy on several occasions. In one case, after a brief email exchange, an mSpy representative provided FBI agents with billing and address information for an mSpy customer who was allegedly a suspect in a kidnapping and murder case.

Each ticket in the dataset contained a set of information about the people who contacted mSpy, and in many cases the data also included the sender's approximate location based on the IP address of their device.

TechCrunch analyzed the locations of mSpy's contact customers by extracting all the location coordinates from the dataset and plotting the data with an offline mapping tool. The results show that mSpy customers are located all over the world, with large clusters in Europe, India, Japan, South America, the UK, and the US.

A photo showing mSpy customers around the world, with large clusters in Europe, India, Japan, South America, the UK and the US.A visualization of location data points from the mSpy database, showing the customer's approximate location. Image credit: TechCrunch

While buying spyware is not illegal, selling it or using it to spy on others without their consent is. U.S. prosecutors have indicted spyware manufacturers in the past, and federal and state watchdogs have barred spyware companies from the surveillance industry, citing the cybersecurity and privacy risks spyware poses. Customers who plant spyware can also be prosecuted for wiretapping violations.

Emails in the leaked Zendesk data show that mSpy and its operators are well aware of what their customers are using the spyware for, including monitoring their phones without their knowledge. Among the requests is a customer asking how to remove mSpy from their partner's phone after their spouse found out. The dataset also raises questions about the use of mSpy by U.S. government officials and agencies, law enforcement, and law enforcement, as it is unclear whether the use of the spyware follows legal procedures.

According to the data, one of the email addresses belonged to Kevin Newsom, a sitting appellate judge on the United States Court of Appeals for the 11th Circuit, which covers Alabama, Georgia, and Florida, who used his official government email address to request a refund from mSpy.

Kate Adams, director of workplace relations for the U.S. Court of Appeals for the Eleventh Circuit, told TechCrunch, “Judge Newsom's use of mSpy was entirely in a personal capacity, addressing a family matter.” Adams did not answer specific questions about the judge's use of mSpy or whether those he monitored consented.

The dataset has also drawn interest from U.S. authorities and law enforcement agencies: An email from an official at the Social Security Administration's Office of Inspector General, the watchdog tasked with oversight of federal agencies, asked an mSpy representative whether the watchdog “could make use of this dataset.” [mSpy] “We will cooperate with parts of our criminal investigation,” he said, without giving specifics.

When TechCrunch reached out to a spokesperson for the Social Security Administration's inspector general, the official declined to comment on why he inquired about mSpy on behalf of the agency.

The Arkansas County Sheriff's Department requested a free trial of mSpy in order to give nearby parents a demo of the software, but a sergeant with the department did not respond to TechCrunch's questions about whether he had the authority to contact mSpy.

The Company Behind mSpy

This is the third known data breach by mSpy since the company was founded around 2010. mSpy is one of the longest-running phone spyware businesses, which is one of the reasons the company has garnered so many customers.

Despite the size and scope of mSpy, its operators have managed to stay out of the public eye and largely escape scrutiny until now. But now they can: It is not uncommon for spyware makers to conceal the real-world identities of their employees to protect their companies from the legal and reputational risks that come with global phone monitoring operations that are illegal in many countries.

However, the mSpy Zendesk data leak revealed that its parent company is a Ukrainian technology company called Brainstack.

Brainstack's website makes no mention of mSpy — as do its public job ads — and only talks about its work on unspecified “parental control” apps. But Zendesk's internal data dump reveals Brainstack's extensive and intimate involvement in mSpy's operations.

TechCrunch found records in the leaked Zendesk data containing information about dozens of employees with Brainstack email addresses, many of whom worked in customer support for mSpy, including responding to customer questions and refund requests.

The leaked Zendesk data includes the real names and, in some cases, phone numbers of Brainstack employees, as well as pseudonyms that employees used to hide their identities when replying to mSpy customer tickets.

When contacted by TechCrunch, two Brainstack employees confirmed that their names appeared in the leaked records but declined to discuss their work at Brainstack.

Brainstack CEO Volodymyr Sitnikov and senior executive Katerina Yurtchuk did not respond to multiple emails seeking comment before publication. Instead, an unnamed Brainstack representative did not dispute our reporting but declined to answer a series of questions for company executives.

It's not clear how mSpy's Zendesk instance was compromised, or by whom. The breach was first revealed by Swiss-based hacker Maia Arson Crimew, who later provided the data to DDoSecrets, a non-profit transparency organization that indexes leaked datasets for the public good.

Reached for comment, Zendesk spokesperson Courtney Blake told TechCrunch that “at this time, there is no evidence that the Zendesk platform has been compromised,” but did not address whether mSpy's use of Zendesk to support its spyware operation violated its terms of service.

“We are committed to upholding our user content and conduct standards and investigating alleged violations appropriately and following established procedures,” the spokesperson said.

If you or someone you know needs help, the National Domestic Violence Hotline (1-800-799-7233) offers free, confidential support to victims of domestic abuse and violence 24/7. In an emergency, call 911. If you believe your phone has been compromised by spyware, the Coalition Against Stalkerware has resources.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

According to Transunion, hackers say they stole the personal information of 4.4 million customers

August 28, 2025

The FBI says that China's salt typhoon has hacked at least 200 US companies

August 27, 2025

US sanctions fraud network used by North Korea's “remote IT workers” to steal money for work

August 27, 2025

Doge uploads live copies of Social Security databases to “vulnerable” cloud servers, whistleblower says

August 26, 2025

Security researchers map hundreds of Teslamate servers spilling Tesla vehicle data

August 26, 2025

Thetruthspy phone spyware new security flaw puts victims at risk

August 25, 2025

Leave A Reply Cancel Reply

Top Reviews
Editors Picks

7 days left: Founders and VCs save over $300 on all stage passes

March 24, 2025

AI chip startup Furiosaai reportedly rejecting $800 million acquisition offer from Meta

March 24, 2025

20 Hottest Open Source Startups of 2024

March 22, 2025

Andrill may build a weapons factory in the UK

March 21, 2025
About Us
About Us

Welcome to Tech Brunch, your go-to destination for cutting-edge insights, news, and analysis in the fields of Artificial Intelligence (AI), Cryptocurrency, Technology, and Startups. At Tech Brunch, we are passionate about exploring the latest trends, innovations, and developments shaping the future of these dynamic industries.

Our Picks

Mississippi's Age Guarantee Act Tests Decentralized Social Networks

August 28, 2025

Threads test how to share long format text on the platform

August 28, 2025

Do you hire AI, or are you a human being? Next frontier for Startup Ops in 2025

August 28, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

© 2025 TechBrunch. Designed by TechBrunch.
  • Home
  • About Tech Brunch
  • Advertise with Tech Brunch
  • Contact us
  • DMCA Notice
  • Privacy Policy
  • Terms of Use

Type above and press Enter to search. Press Esc to cancel.