Android stalkerware app LetMeSpy hacked, data released online

Android stalkerware app LetMeSpy hacked, data released online

Polish developer behind the LetMeSpy phone monitoring app used to spy on thousands of people using Android phones has been breached, with the hackers stealing sensitive data collected by the app, including text messages, call logs and locations.

LetMeSpy is a free Android app marketed for parental control or employee monitoring, which can track calls, SMS and GPS locations of the phone it is installed on.

The breach was first reported by the Polish research blog Niebezpiecznik last week. When attempting to contact LetMeSpy, Niebezpiecznik got a reply from the hackers instead, who claimed that they had access to the app’s domain.

According to an alert posted on the spyware maker’s website, the information was stolen in a “security incident” that occurred on June 21, when someone obtained “unauthorized access” to its website's databases.

“As a result of the attack, the criminals gained access to e-mail addresses, telephone numbers and the content of messages collected on accounts. In order to ensure security, all account-related functions of the website were disabled immediately after the incident was discovered,” the alert says.

It appears that the stolen data has been circulating online for at least a few days. A review of the leaked database showed it included years of victims’ call logs and text messages dating back to 2013, according to TechCrunch.

The database contained current records on at least 13,000 compromised devices, although not all of them were sharing data with LetMeSpy, as well as over 13,400 location data points for several thousand victims, with the majority of them located in the US, India and Western Africa.

The data also contained the spyware’s master database, including information about 26,000 customers who used the spyware for free and the email addresses of customers who bought paying subscriptions.

Currently, it’s not clear who is responsible for the hack. According to the intruders’ claim, they have deleted data stored on the LetMySpy servers.

Back to the list

Latest Posts

Cyber Security Week in Review: July 4, 2025

Cyber Security Week in Review: July 4, 2025

In brief: Google patches Chrome 0Day, the US is on the hunt for North Korean IT workers, and more.
4 July 2025
AI chatbots fall for phishing scams

AI chatbots fall for phishing scams

The models provided the correct URL only 66% of the time; nearly 30% of responses pointed users to dead or suspended domains.
3 July 2025
Chinese hackers exploited Ivanti flaws in attacks against French government

Chinese hackers exploited Ivanti flaws in attacks against French government

ANSSI believes that the Houken campaign is operated by ‘UNC5174’, an entity believed to act as an initial access broker for China’s Ministry of State Security.
2 July 2025