PogoWasRight.org

Menu
  • About
  • Privacy
Menu

‘Stalkerware’ Website Let Anyone Intercept Texts of Tens of Thousands of People

Posted on November 1, 2018 by pogowasright.org

Joseph Cox and Lorenzo Franceschi-Bicchierai report:

This story is part of When Spies Come Home, a Motherboard series about powerful surveillance software ordinary people use to spy on their loved ones.

A website and app designed to let users monitor their children, employees, or illegally spy on their spouse inadvertently allowed anyone who was using the service to obtain information contained within other peoples’ accounts and intercept the communications of around 28,000 users, Motherboard has confirmed following a tip from a hacker.

The app, called Xnore, can be installed on Android, iPhone, and BlackBerry devices, and collects Facebook and WhatsApp messages, GPS coordinates, emails, photos, browsing histories as well as records phone calls. Customer accounts were exposed by a map feature on Xnore’s website. The flaw allowed anyone who viewed the HTML code of the page to see the mobile identifier used by Xnore to view any collected data. This identifier could then be used to add the intercepted data of someone else’s account to your own.

Read more on Motherboard.

Category: BusinessFeatured NewsSurveillance

Post navigation

← VN: Expulsion of students based on privacy breach questioned
Virginia Hospital Must Answer for Snooping Employees’ Privacy Breach →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim

RSS Recent Posts on DataBreaches.net

  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors
  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy