Notorious spyware app shuts down after attacker breaches and deletes server data


LetMeSpy, a commercial spyware product that consumers could buy and use to spy on Android devices, is shutting down as the direct result of a data breach that saw a threat actor breach the company servers and wipe most of the data found there.
As reported by TechCrunch, LetMeSpy published a notice on its website, notifying its users that by the end of the month, it will no longer provide its services to anyone:
“Dear All, we would like to kindly inform you that as of August 31, 2023, the letmespy.com website will cease operations, therefore we would like to provide you with some information,” the notice reads. “Due to the data security incident that took place on June 21, 2023, access to User Accounts was blocked, for security reasons. After that date, the LetMeSpy service was disabled, as well as the option to log into User Accounts and register new User Accounts on the site.”
Those that wish to access the data available within their user account are advised to contact the company individually by September 30 this year, with the email provided on the company website. “After the expiration of retention period under the applicable law, the data stored in User Accounts will be deleted,” the notice concludes.
In late June 2023, LetMeSpy warned of a “security incident” in which an an unauthorized third party accessed the data of “website users”. “As a result of the attack, the criminals gained access to e-mail addresses, telephone numbers and the content of messages collected on accounts,” the announcement read at the time.
The message horde collected by the hacker seem to be quite extensive. After reviewing sample data, TechCrunch noted at least 13,000 devices have had data taken, which includes “years of victims’ call logs and text messages”, dating back to 2013. Also, more than 13,000 location data points, for thousands of victims, were stolen, as well. This data suggests most victims live in the US, India, and Western Africa. Furthermore, the app’s master database was taken too, which holds data on some 26,000 customers who used the app for free, as well as the email addresses of those who paid for the subscription. The company website was taken over by the attackers, as well.
Analysis: Why does it matter?
The developers of spyware apps argue that the goal of their products is security, often claiming that it’s a good way for parents to keep tabs on what their kids do online. In reality, though, the apps are mostly used by spouses in poorly functioning families, and similar. As the apps are designed to remain invisible on devices they’re installed on, many victims carry them without knowledge or consent. As a result, the apps are deemed illegal in some parts of the world.
LetMeSpy was uploading all text messages, call logs, and location data to the servers without notifying the device owner. It would then share the data with the person who installed the app, on a different device. That makes the apps an ideal gateway for hackers looking to steal sensitive data, especially when they’re poorly executed and buggy. According to some researchers, most of these apps are hollow as Swiss cheese.
The threat of spyware apps, sometimes also called stalkerware, increased by more than three times in the past three years, cybersecurity researchers from Avast recently said. The company’s Threat Researchers department, part of the Coalition Against Stalkerware, revealed that, based on its telemetry, the possibility of encountering this form of mobile malware increased 329% since 2020.
If your device has inexplicable performance drops, starts crashing or freezing for no apparent reason, heats up too much, or suddenly starts consuming too much battery, a stalkerware app could be hiding somewhere. Also, Avast says that if suddenly you have a new browser homepage, new icons on your desktop, or a different default search engine, it might be a good time to scan the phone for malware.
What have other said about the news?
In its writeup of the news, Global Village Space says the shutdown of LetMeSpy highlights the “growing concern” over the use of these apps to invate people’s privacy. “Such invasive surveillance can have severe consequences for victims, including emotional distress, stalking, and harassment,” the publication states
It goes on to stress that the governments around the world pushed to combat these tools, mentioning Support King, a tech company that wa banned by the Federal Trade Commission (FTC) from the surveillance industry in 2021, due to its mishandling of stolen data. “This regulatory action sends a strong message that the misuse of spyware will not be tolerated;” it added. The battle might have been won, but the war is ongoing, it concluded.
Reddit users cheered on the news, with one user saying “You reap what you sow”, and another adding “Whoever did it: good job.”
Go deeper
If you want to learn more about staying safe online, start by reading our guide on the best malware removal tools right now. Also check out how to clean up your Android device, as well as what are the best iOS antivirus apps.
Via: TechCrunch
LetMeSpy, a commercial spyware product that consumers could buy and use to spy on Android devices, is shutting down as the direct result of a data breach that saw a threat actor breach the company servers and wipe most of the data found there. As reported by TechCrunch, LetMeSpy published…
Recent Posts
- Reddit is experiencing outages again
- OpenAI confirms 400 million weekly ChatGPT users – here’s 5 great ways to use the world’s most popular AI chatbot
- Elon Musk’s AI said he and Trump deserve the death penalty
- Grok resets the AI race
- The GSA is shutting down its EV chargers, calling them ‘not mission critical’
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010