PogoWasRight.org

Menu
  • About
  • Privacy
Menu

More Evidence of mSpy Apathy Over Breach

Posted on May 27, 2015June 26, 2025 by Dissent

The mSpy data breach is the kind of breach that I cover over on databreaches.net, but the privacy implications of this one are so severe that I thought I should note it here.

If you’re using spyware to spy on your children or a partner – regardless of whether you call it spying or “monitoring” or any other euphemism – note that you – and they can be exposed in a breach by companies that do not take adequate security protections.

Brian Krebs has been all over this breach. Today, he writes:

The mSpy data was leaked to the Deep Web, where hundreds of gigabytes of files, chat logs, location records and other data was dumped after the company reportedly declined to comply with extortion demands made by hackers who’d broken into mSpy’s servers. Included in that huge archive is a 13 gigabyte (compressed) directory referencing countless screen shots taken from devices running mSpy’s software — including screen shots taken secretly by users who installed the software on a friend or partner’s device.

The log file of the screen shots taken from mSpy-infested devices doesn’t store the actual screenshot, but instead includes incomplete links to the images. Incredibly, nearly two weeks after this breach became public, all of the leaked screen shots remain viewable over the Internet with nothing more than a Web browser if one knows the base URL that precedes the file name. And that base URL is trivial to work out if you have an active mSpy account.

Read more on KrebsOnSecurity.com.

No related posts.

Category: BreachesFeatured News

Post navigation

← Skype hauled into Belgian court after refusing to hand call records to cops
When Privacy Policies Should NOT Be Published – Two Easy Lessons From the FTC’s Nomi Technologies Case →

2 thoughts on “More Evidence of mSpy Apathy Over Breach”

  1. Mike T says:
    May 27, 2015 at 3:49 pm

    I think it’s less about apathy and more about data security professionals’ attitudes towards mSpy. A company that SELLS MALWARE got hacked, exposing data of people who were r00ted by their friends and family. If I were a law talking guy, I’d be salivating at the release of a prospect list of thousands of people who are going to be pretty pissed at a company and a friend/partner, and may be willing to pay for my services.

    As a security professional though, I shrug my shoulders. Victims who practiced weak operational security by allowing people access to their mobile devices had their data outed because the service provider their “friend” used had equally weak security, and continue to show it well after they knew they had a problem. mSpy is shady and culpable, but not nearly so much as the folks who purchased their “services” to use on others.

    1. Dissent says:
      May 28, 2015 at 6:54 am

      A lot of the “victims who practiced weak opsec” may be kids whose parents gave them the phones. Or adults who, not being tech-savvy, trusted a spouse or partner to help them set up their phone.

      I wonder if this will even make a serious dent in mSpy’s business.

Comments are closed.

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map
  • EPIC Publishes New Whitepaper Detailing Privacy Risks of Government Data Mining Programs
  • Modern cars are spying on you. Here’s what you can do about it.
  • Attorney General James and Multistate Coalition Secure $5.1 Million from Education Software Company for Failing to Protect Students’ Data       
  • EU Parliament committee votes to advance controversial Europol data sharing proposal

RSS Recent Posts at DataBreaches.net

  • NHS providers reviewing stolen Synnovis data published by cyber criminals
  • Gates Down: Third Circuit Says Breaking Employer Computer Access Policies Is Not Hacking
  • Short-term renewal of cyber information sharing law appears in bill to end shutdown
  • Yanluowang ransomware IAB pleads guilty
  • Lawsuit Alleges Ex-Intel Employee Hid 18,000 Sensitive Documents Prior to Leaving the Company
©2025 PogoWasRight.org. All rights reserved.