Hacktivist scrapes over 500,000 stalkerware customers’ payment records

Hacktivist scrapes over 500,000 stalkerware customers’ payment records

A recent security incident has revealed that a hacktivist has extracted more than 500,000 payment records from a company specializing in consumer-grade stalkerware applications. This breach has laid bare the email addresses and partial payment information of individuals who utilized these invasive tracking services. The leaked transactions include details for various phone tracking applications, such as Geofinder and uMobix, along with Peekviewer (previously known as Glassagram), which claims to provide access to private Instagram accounts. The Ukrainian company behind these apps, Struktura, is now facing serious scrutiny as this incident highlights ongoing security vulnerabilities within the stalkerware industry. Among the compromised user data are records from Xnspy, a notorious surveillance application that in 2022 experienced a significant data leak affecting thousands of unsuspecting Android and iPhone users. This incident is part of a troubling trend where stalkerware operators have repeatedly failed to protect user privacy, leading to numerous data breaches over recent years. Once installed on a target device, apps like uMobix and Xnspy can harvest a variety of private information, including call logs, text messages, photos, browsing history, and location data. These applications have been marketed explicitly for spying on spouses and partners, an act that is both unethical and illegal. The dataset, reviewed by TechCrunch, contains approximately 536,000 customer email addresses, details about the services they purchased, payment amounts, and the last four digits of their credit cards—though it notably lacks payment dates. TechCrunch confirmed the authenticity of the data by cross-referencing transaction records associated with disposable email addresses through various password reset processes, successfully verifying the existence of these accounts. The hacktivist, identified by the pseudonym 'wikkid,' stated that they exploited a simple vulnerability on the stalkerware vendor's website to perform the data scrape. They expressed a particular interest in targeting applications used for spying, later sharing the information on a well-known hacking forum. The vendor, referred to in the forum as Ersten Group, presents itself as a software development firm based in the U.K. However, TechCrunch uncovered that many email addresses in the dataset point back to Struktura, which operates a nearly identical website. The earliest record in the leaked data belongs to Struktura’s CEO, Viktoriia Zosim, linked to a transaction of $1. Despite attempts to reach out for comments, representatives from both Ersten Group and Struktura did not respond.

Sources : TechCrunch

Published On : Feb 09, 2026, 16:35

Computing
Market Turbulence: Four Key Factors Impacting Stocks This Week

This past week has been challenging for the stock market, driven by several significant forces that have created turbule...

CNBC | Jul 25, 2026, 20:05
Market Turbulence: Four Key Factors Impacting Stocks This Week
Startups
The Boring Company Eyes $4 Billion Funding Boost Amid Expanding Tunnel Ventures

Elon Musk's tunneling enterprise, The Boring Company, is reportedly negotiating a substantial funding round of $4 billio...

TechCrunch | Jul 25, 2026, 19:50
The Boring Company Eyes $4 Billion Funding Boost Amid Expanding Tunnel Ventures
Science
Finland Unveils World's Largest Sand Battery to Tackle Renewable Energy Challenges

In a groundbreaking move to address the critical issue of renewable energy intermittency, a small town in southern Finla...

CNBC | Jul 25, 2026, 05:35
Finland Unveils World's Largest Sand Battery to Tackle Renewable Energy Challenges
Computing
Crisis Averted: Power Line Failure Highlights Urgent Need for Data Center Resilience

A power line failure near Washington, DC, recently showcased a significant challenge faced by the electrical grid due to...

TechCrunch | Jul 25, 2026, 13:50
Crisis Averted: Power Line Failure Highlights Urgent Need for Data Center Resilience
Cybersecurity
The Elusive Phineas Fisher: The Hacktivist Who Took Down Spyware Giants

In the realm of cybersecurity, few figures are as intriguing as Phineas Fisher, a hacker who has evaded capture for near...

TechCrunch | Jul 25, 2026, 21:00
The Elusive Phineas Fisher: The Hacktivist Who Took Down Spyware Giants
View All News