Retina-X 2017 Data Breach

Retina-X Stalkerware Provider Breach (2017): 71K Operator Accounts Including Passwords Exposed

Spyware / Stalkerware · Covert device monitoring and surveillance · Mobile spyware platform · Global

Retina-X Stalkerware Provider Breach (2017): 71K Operator Accounts Including Passwords Exposed

Monitoring and spyware software company

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach involves people who could be put at risk if their inclusion were revealed. We do not confirm anyone’s presence publicly or to third parties. Check your own exposure privately below.
Breach Risk Index i
44/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
71KRecords
2017Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
Cloud MisconfigurationCybersecuritySurveillanceTarget2017

Breach Summary

Retina-X Studios, a Florida-based developer of mobile device monitoring applications later classified by the Federal Trade Commission as stalkerware, was breached in February 2017. The hacker, who told reporters they had targeted Retina-X specifically because of how the company's products were being used, gained access to Retina-X's cloud storage by extracting unencrypted credentials from the TeenShield Android application package. The attacker accessed customer accounts and the surveillance data Retina-X's products had collected, deleted material from company servers, and was the subject of a Motherboard investigation that publicly disclosed the incident in April 2017.\n\nThe exposed dataset is best understood in two layers. The first layer covers approximately 71,000 customer email addresses paired with passwords stored as unsalted MD5 hashes, representing the operator accounts of people who had purchased the surveillance apps. The second layer covers data the stalkerware itself had harvested from monitored devices, including GPS locations, text messages, photos, contacts, login credentials, and screenshots of activity captured from the phones being spied on. A second hack in 2018 followed the same pattern.\n\nThe risk profile is distinct from a typical breach because the people whose data was most severely exposed are not the ones who held accounts. Surveillance targets, including domestic-violence victims and others on whose phones the apps had been installed without their knowledge, had highly intimate communications and location data made accessible. The Federal Trade Commission settled an enforcement case against Retina-X and its owner James N. Johns Jr. in October 2019, the agency's first stalkerware action, banning the company from selling its products unless safeguards against covert use were implemented. Anyone who suspects their device may have run Retina-X apps should consult domestic-violence advocates and law enforcement before taking action, since abrupt removal can alert an abuser.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

71K records analyzed

About Retina-X

Retina-X Studios LLC was a Florida-based developer of mobile device monitoring applications, marketed as parental and employee surveillance tools. The company sold three principal products: MobileSpy, PhoneSheriff, and TeenShield, all designed to run covertly in the background of an installed mobile device while transmitting the device's text messages, GPS locations, photos, contacts, browser history, and call records to an operator-controlled dashboard. The Federal Trade Commission and digital-rights researchers ultimately classified Retina-X products as stalkerware, citing the apps' covert installation, removal of icons from device screens, and design suitability for use without the monitored individual's knowledge.

Why They Hold Your Data

Handles operator account data, including credentials and account management details, as well as indirect access pathways to monitored device data such as communications, location, and activity logs.

Recent Developments

The Federal Trade Commission filed and settled a complaint against Retina-X and its owner James N. Johns Jr. in October 2019, marking the agency's first enforcement action against a stalkerware vendor. Retina-X was barred from selling its monitoring apps unless purchasers attest the products will be used for legitimate purposes, and the company was required to design installation flows that maintain device security. By the time of the settlement, Retina-X had already announced an indefinite shutdown following a second hack in 2018. The Retina-X case has since become a reference point in regulatory and advocacy work targeting the broader stalkerware industry.

Data Points Exposed

2 verified field types
Email Address
Password High

Breach Impact

The institutional impact of the Retina-X breaches was severe and effectively terminal. The 2017 and 2018 attacks exposed both the company's customer base and the surveillance data its products had collected, which contradicted explicit privacy promises in its marketing materials. The hacker behind both incidents wiped Retina-X servers and made public statements expressing solidarity with the surveillance targets the apps had been used to spy on. The Federal Trade Commission cited the breaches as central evidence of the company's failure to secure data and brought the first U.S. stalkerware enforcement action. Retina-X stopped selling its products in April 2018 and accepted permanent restrictions on its business.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Reset any reused passwords and enable MFA on email first, then financial accounts.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because revealing who appears in this breach could expose people to stalking, harassment, or harm, we confirm exposure only to the individual concerned. Verify your identity to privately check your own exposure.

We will only confirm whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation