social.tchncs.de is one of the many independent Mastodon servers you can use to participate in the fediverse.
A friendly server from Germany – which tends to attract techy people, but welcomes everybody. This is one of the oldest Mastodon instances.

Administered by:

Server stats:

3.8K
active users

#stalkerware

3 posts2 participants0 posts today

"A consumer-grade spyware operation called SpyX was hit by a data breach last year, TechCrunch has learned. The breach reveals that SpyX and two other related mobile apps had records on almost two million people at the time of the breach, including thousands of Apple users.

The data breach dates back to June 2024 but has not been previously reported, and there is no indication that SpyX’s operators ever notified its customers or those targeted by the spyware.

The SpyX family of mobile spyware is now, by our count, the 25th mobile surveillance operation since 2017 known to have experienced a data breach, or otherwise spilled or exposed their victims’ or users’ data, showing that the consumer-grade spyware industry continues to proliferate and put people’s private data at risk.

The breach also provides a rare look at how stalkerware like SpyX can also target Apple customers.

Troy Hunt, who runs data breach notification site Have I Been Pwned, received a copy of the breached data in the form of two text files, which contained 1.97 million unique account records with associated email addresses."

techcrunch.com/2025/03/19/data

TechCrunch · Exclusive: Data breach at stalkerware SpyX affects close to 2 million, including thousands of Apple usersAnother consumer-grade spyware operation was hacked in June 2024, which exposed thousands of Apple Account credentials.

#Amazon is still hosting #stalkerware victims' data weeks after breach alert
#Cocospy, #Spyic, and #Spyzie, have collectively compromised over 3.1 million Android phones, which we know because apps each had a #databreach in Feb.
As part of our investigation into stalkerware operations, which included analyzing the apps themselves, TechCrunch found that some of the contents of a device compromised by the stalkerware apps are being uploaded to storage servers run by #AWS.
techcrunch.com/2025/03/13/amaz

TechCrunch · Amazon is still hosting stalkerware victims' data weeks after breach alert | TechCrunchAmazon won't say if it will stop hosting data from three phone surveillance operations that spilled private data on millions of people.

Here’s Week 9 of the #Privacy Roundup:

- #Mozilla @mozillaofficial updates #Firefox privacy notice, adds Terms of Use
- Edge Canary disabling manifestv2 extensions
- DOGE allegedly exposing sensitive endpoints to the public internet
- More PII leaks by #stalkerware apps
- Surveillance tech in the office is very… invasive
- #Signal @signalapp threatens to cease operations in Sweden if e2e encryption is forced to be backfired by law

… and more, of course.

#privacymatters #cybersecurity #security

avoidthehack.com/privacy-week9

Replied in thread

@sambowne

"With Cocospy and Spyic, you can usually enter ✱✱001✱✱ on your Android phone app’s keypad and then press the “call” button to make the stalkerware apps appear on-screen — if they are installed. This is a feature built into Cocospy and Spyic to allow the person who planted the app on the victim’s device to regain access. In this case, the feature can also be used by the victim to determine if the app is installed."

#stalkerware
#android
#Cocospy
#Spyic