mSpy 2024 Data Breach

mSpy Mobile Stalkerware Platform Breach (2024): 2.4 Million Operator Accounts & Support Tickets Exposed :: Targets' Data Also Accessible

Spyware / Stalkerware · Covert device monitoring and surveillance · Mobile spyware platform · Global

mSpy Mobile Stalkerware Platform Breach (2024): 2.4 Million Operator Accounts & Support Tickets Exposed :: Targets' Data Also Accessible

Mobile device monitoring and parental control application.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach involves people who could be put at risk if their inclusion were revealed. We do not confirm anyone’s presence publicly or to third parties. Check your own exposure privately below.
Breach Risk Index i
44/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
2.4MRecords
2024Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
MinorsChildren / minors
Classification Tags
CybersecuritySurveillanceTarget2024

Breach Summary

mSpy, a mobile surveillance and parental-control application owned by Ukraine-based Brainstack, suffered a data breach in May 2024 when unidentified attackers exfiltrated approximately 318 gigabytes of data from mSpy's Zendesk-powered customer support system, including customer support tickets dating back to 2014. The leaked dataset was made publicly available in June 2024 by hacker Maia Arson Crimew through the nonprofit transparency collective DDoSecrets, and was independently verified by TechCrunch and other security researchers. The breach was indexed by Have I Been Pwned on July 11, 2024. Despite extensive public reporting, mSpy and parent company Brainstack did not publicly acknowledge the breach. The breach affected approximately 2,394,179 unique customer email addresses based on records indexed by Have I Been Pwned. Compromised data included email addresses, IP addresses, names, customer support ticket conversations, photographs, and more than 500,000 attachments totaling 176 gigabytes. The attachments included screenshots of financial transactions, photographs of credit cards (some partially obfuscated), and nude selfies (predominantly of women), apparently included in customer support requests for various reasons. The customer support tickets themselves contained extensive disclosures about the customers' surveillance activities, including requests for help installing mSpy on partners', children's, and employees' devices and instructions on how to remove mSpy from a partner's phone after the spouse discovered the surveillance. The dataset also exposed information about Brainstack employees, including real names and false names used when responding to customer tickets, providing significant insight into the operational structure of the company. For surveillance targets and customers alike, the practical risk profile is exceptionally severe and varies between the two populations. For surveillance targets (the people whose devices were being monitored), inclusion in the dataset confirms a surveillance relationship that was likely established without consent, with the U.S. National Domestic Violence Hotline (1-800-799-7233) and the Coalition Against Stalkerware providing resources for affected individuals. For customers, inclusion in the dataset confirms participation in a stalkerware operation, with potential employment, relationship, and legal consequences that vary by jurisdiction; customers in U.S. military, judicial, government, or law enforcement roles whose participation has been documented may face additional security clearance and professional consequences. Some affected emails belong to journalists who contacted mSpy and to U.S. law enforcement filing legal demands rather than to customers. The exposure of nude selfies and credit card photographs creates additional payment-fraud and intimate-image-extortion risk. Affected customers who provided credit card information to mSpy should monitor card statements and consider replacement cards. Affected users who receive extortion attempts should not pay ransom demands because payment does not stop further extortion.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

2.4M records analyzed

About mSpy

mSpy is a mobile and computer monitoring application marketed for parental control and employee monitoring across Android, iOS, Windows, and macOS platforms. The application has been operating since approximately 2010 and is widely classified as stalkerware because of its persistent use for non-consensual surveillance of romantic partners, despite its parental-control marketing. mSpy's owner was publicly revealed through this 2024 breach to be Brainstack, a Ukraine-based information-technology company whose public website does not mention mSpy and whose job postings refer only to an unspecified 'parental control app.' Capabilities include tracking GPS location, viewing web history, accessing photos, videos, emails, SMS, Skype, WhatsApp, and keystrokes. As a stalkerware platform, mSpy maintains two distinct populations of data: customer accounts and the surveillance content captured from monitored devices.

Why They Hold Your Data

Stalkerware platforms collect customer identity, billing records, target-device identifiers, monitoring settings, and exfiltrated device activity tied to covert phone surveillance.

Recent Developments

The 2024 mSpy breach was the third documented mSpy security incident, following earlier breaches in 2015 and 2018. mSpy and parent company Brainstack did not publicly acknowledge or disclose the 2024 breach, even after more than a month had passed and the dataset had been verified by TechCrunch and other independent security researchers. The leaked dataset was disclosed by hacker Maia Arson Crimew (the same researcher who documented the pcTattletale breach) and made available to the nonprofit transparency collective DDoSecrets. Have I Been Pwned indexed the breach on July 11, 2024 with 2,394,179 unique email addresses. The breach is particularly notable for revealing the involvement of senior U.S. government and law enforcement personnel as mSpy customers, including senior-ranking U.S. military personnel, a serving U.S. federal appeals court judge, a U.S. government department's watchdog, and an Arkansas county sheriff's office.

Data Points Exposed

4 verified field types
Email Address
Full Name
IP Address
Profile Photo

Breach Impact

The institutional impact on mSpy and parent company Brainstack has been significant. The breach publicly identified Brainstack as mSpy's parent company for the first time, creating reputational and potential regulatory exposure that the company had previously avoided through corporate-structure obscurity. The case has been formally cited as illustrating the persistent and recurring failure of consumer-grade spyware vendors to secure customer and victim data, alongside earlier mSpy breaches in 2015 and 2018. The exposure of senior U.S. government and military personnel as customers raises distinct national security concerns because mSpy installations on devices belonging to spouses or family members of cleared personnel may have themselves created surveillance entry points exploitable by foreign intelligence services. Civil litigation and regulatory action have been limited despite the third recurring breach. The reputational impact has concentrated within the broader stalkerware industry and across Brainstack's other product lines.

Exploitation & Downstream Threats

• Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because revealing who appears in this breach could expose people to stalking, harassment, or harm, we confirm exposure only to the individual concerned. Verify your identity to privately check your own exposure.

We will only confirm whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation