Cocospy stalkerware apps go offline after data breach TechCrunch

p

Latest
pp

AI
pp

Amazon
pp

Apps
pp

Biotech Health
pp

Climate
pp

Cloud Computing
pp

Commerce
pp

Crypto
pp

Enterprise
pp

EVs
pp

Fintech
pp

Fundraising
pp

Gadgets
pp

Gaming
pp

Google
pp

Government Policy
pp

Hardware
pp

Instagram
pp

Layoffs
pp

Media Entertainment
pp

Meta
pp

Microsoft
pp

Privacy
pp

Robotics
pp

Security
pp

Social
pp

Space
pp

Startups
pp

TikTok
pp

Transportation
pp

Venture
pp

Events
pp

Startup Battlefield
pp

StrictlyVC
pp

Newsletters
pp

Podcasts
pp

Videos
pp

Partner Content
pp

TechCrunch Brand Studio
pp

Crunchboard
pp

Contact Us
ppA trio of phone surveillance apps which was caught spying on millions of peoples phones earlier this year has gone offlineppCocospy Spyic and Spyzie were three nearidentical but differently branded stalkerware apps that allowed the person planting one of the apps on a targets phone access to their personal data including their messages photos call logs and realtime location data usually without that persons knowledgeppStalkerware apps like Cocospy and its clones are designed to stay hidden from device home screens making the apps difficult to detect by their victims but all the while making the phones contents continually available to the person who planted the appppIn February a security researcher told TechCrunch that the apps share the same security flaw that allowed anyone to access the personal data of any device with one of the apps installed The flaw also revealed the scale of the spying operations behind these apps by exposing the email address of every user who signed up to these spyware services with the intention of planting the spyware on someones phoneppThe researcher used the bug to scrape 32 million email addresses of Cocospy Spyic and Spyzie customers who had signed up and provided those email addresses to the data breach notification site Have I Been Pwned ppFollowing our reporting on the breach the stalkerware apps have since stopped working their websites disappeared and their Amazonhosted cloud storage was deleted TechCrunch has foundppIts not clear for what reason the stalkerware operations were shuttered The operators could not be reached for commentppConsumergrade phone surveillance operations are known to shut down or rebrand entirely following a hack or data breach typically in an effort to escape legal and reputational fallout LetMeSpy a spyware developed out of Poland confirmed its permanent shutdown in August 2023 after a data breach wiped out the developers servers USbased spyware maker pcTattletale went out of business and shut down in May 2024 following a hack and website defacementppCocospy Spyic and Spyzie are among the most recent apps in a growing list of dozens of phone surveillance operations that have been hacked or otherwise exposed their victims data as a result of shoddy coding or poor security practices By TechCrunchs count at least 25 stalkerware operations have been breached since 2017 with at least 10 of those operations including Cocospy shutting down in the wake of a breachppPhonemonitoring apps like Cocospy are often sold under the guise of parental control or tracking software but are also referred to as stalkerware or spouseware for their propensity to be misused or explicitly marketed for spying on a persons spouse or partner without their consent which is illegal ppAs such stalkerware apps are banned from app stores and are not allowed to advertise on search engines Web hosts like Amazon which hosted the stalkerware operations cache of stolen victims phone data also claim to prohibit surveillance operations from using its platformppAlthough the trio of Cocospy apps now appears nonoperational and its servers are offline affected individuals should still take action to remove the spyware from their phonesppTo detect Cocospy Spyic and Spyzie on your Android phone you can generally enter 001 on your phone apps keypad and then press the call button This backdoor feature prompts the hidden stalkerware apps to appear onscreen if they are installedppFrom here you can delete the malicious app which appears as a genericlooking app called System Service from your deviceppppIf you or someone you know needs help the National Domestic Violence Hotline 18007997233 provides 247 free confidential support to victims of domestic abuse and violence If you are in an emergency situation call 911 The Coalition Against Stalkerware has resources if you think your phone has been compromised by spywareppTopicspp
Security Editor
ppFrom seed to Series C and beyondfounders and VCs of all stages are heading to Boston Be part of the conversation Save 200 now and tap into powerful takeaways peer insights and gamechanging connectionspp Sam Altman thinks AI will have novel insights next year

pp Proxima Fusion joins the club of wellfunded nuclear contenders with 130M Series A

pp OpenAIs open model is delayed

pp Vijay Pande founding partner of a16z bio and health strategy steps down

pp AI storage platform Vast Data aimed for 25B valuation in new round sources say

pp Apple Intelligence Everything you need to know about Apples AI model and services

pp YouTube says its ecosystem created 490K jobs and added 55B to the US GDP in 2024

pp 2025 TechCrunch Media LLCp