Apps & Consumer
uMobix breach highlights ongoing stalkerware security failures
Stalkerware provider uMobix is the latest to suffer a data breach, exposing more than 500,000 customers, continuing a trend of security failures across the global stalkerware industry.
The uMobix breach, which exposed payment information for more than 500,000 customers, marks the latest incident in a pattern of security failures within the stalkerware industry. The leak occurred after a hacktivist scraped and published the payment data online. In 2025, a breach at Catwatchful compromised the phone data of at least 26,000 victims, while other operations like Cocospy, Spyic, and Spyzie left the personal data of millions of victims exposed online. Prior to these, 2024 saw multiple breaches, including at mSpy, which leaked over 2 million customer records in 2018 and suffered another breach in 2024, and pcTattletale, which shut down after a hacker leaked its internal data. The founder of pcTattletale, Bryan Fleming, later pled guilty to charges of computer hacking and conspiracy.
According to the publication TechCrunch, at least 27 stalkerware companies have been hacked or have leaked customer and victims’ data online since 2017. This history of vulnerability has made the sector a frequent target for hackers. When the U.S.-based Retina-X and the Thailand-based FlexiSpy were breached back-to-back in 2017, the hacks revealed a total number of 130,000 customers worldwide. Other companies have repeatedly left sensitive data exposed. For example, MobiiSpy left 25,000 audio recordings and 95,000 images on an open server, while Spyhide exposed data belonging to around 60,000 victims. Eva Galperin, the director of cybersecurity at the Electronic Frontier Foundation (a digital rights nonprofit), described the industry as a soft target, suggesting that those who run these firms may lack scruples and concern for product quality.
Stalkerware companies often market their products as solutions to catch cheating partners by encouraging illegal and unethical behavior. However, using these applications for surreptitious monitoring constitutes unlawful surveillance in most jurisdictions. The Federal Trade Commission (the U.S. consumer protection regulator) previously banned SpyFone from operating in the surveillance industry following a security lapse. Yet, even when enforcement or hacks force companies to close, the market often adapts. As Eva Galperin, the director of cybersecurity at the Electronic Frontier Foundation, explained, “What happens most often, when you actually manage to kill a stalkerware company, is that the stalkerware company comes up like mushrooms after the rain.” Some trends exist; the cybersecurity firm Malwarebytes reported that the use of stalkerware is declining, though experts warn that surveillance may simply be shifting to physical trackers.
Why it matters
The stalkerware industry is frequently targeted by hackers, leading to massive data exposures of sensitive personal information belonging to millions of victims, despite the companies’ claims of providing security.