{"id":22355,"date":"2023-06-30T16:10:28","date_gmt":"2023-07-01T00:10:28","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2023\/06\/30\/news-16085\/"},"modified":"2023-06-30T16:10:28","modified_gmt":"2023-07-01T00:10:28","slug":"news-16085","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2023\/06\/30\/news-16085\/","title":{"rendered":"Spyware app LetMeSpy hacked, tracked user data posted online"},"content":{"rendered":"<p>Stalkerware-type app LetMeSpy says it has been hacked, with the attacker taking user data with it.<\/p>\n<p>From the message posted to the login screen on the LetMeSpy website:<\/p>\n<blockquote>\n<p>On June 21, 2023, a security incident occurred involving obtaining unauthorized access to the data of website users.<\/p>\n<p>As a result of the attack, the criminals gained access to e-mail addresses, telephone numbers and the content of messages collected on accounts.<\/p>\n<\/blockquote>\n<p>To be clear, much of the data that was stolen is the data from the phone which has the tracking app on it,&nbsp;which has likely been installed without the phone owner&#8217;s knowledge. That&#8217;s because LetMeSpy is often invisible to the phone&#8217;s owner.&nbsp;<\/p>\n<p>So as long as someone can get quick access to install an app on your Android phone, they can monitor you. Once the app is on your phone, you often can&#8217;t tell it&#8217;s there. However, in the background, it is maliciously&nbsp;uploading all your calls, texts, and location to the LetMeSpy servers, which is what has now been hacked.<\/p>\n<p>These sorts of apps&nbsp;have been&nbsp;used by people wanting to monitor their partner&#8217;s movements, along with parents and employers.<\/p>\n<p>Polish site <a href=\"https:\/\/niebezpiecznik.pl\/\">Niebezpiecznik<\/a>&nbsp;first reported the breach. In the database file which was later dumped online, the blog said there was:<\/p>\n<ul>\n<li>26,000+ email addresses of the tool&#8217;s&nbsp;&#8220;operators&#8221; along with hashes of their passwords.<\/li>\n<li>16,000+ text messages, including passwords&nbsp;and codes for various services<\/li>\n<li>Telephone numbers of people who had contacted the tracked phones<\/li>\n<li>Telephone numbers of the people whom the tracked phone owner had called (along with the names associated with them in the contacts list)<\/li>\n<li>Database dump in SQL format, containing more data, including locations<\/li>\n<\/ul>\n<p>Spokesman Adam Sanocki for the Polish&nbsp;data protection authority UODO <a href=\"https:\/\/techcrunch.com\/2023\/06\/27\/letmespy-hacked-spyware-thousands\/\" target=\"_blank\" rel=\"nofollow\">confirmed to TechCrunch<\/a> that it had received a breach notice from LetMeSpy.&nbsp;When many breaches happen, the affected company should inform users that their data has been breached. But the&nbsp;users of the service here are the ones tracking people, and, sadly, it&#8217;s unlikely they&#8217;re going to let the people they are spying on know that their data has been taken.<\/p>\n<h2>How to prevent&nbsp;spyware and stalkerware-type apps<\/h2>\n<ul>\n<li>Set a screen lock on your phone and don&#8217;t let anyone else access it<\/li>\n<li>Keep your phone up-to-date. Make sure you&#8217;re always on the latest version of your phone&#8217;s software.<\/li>\n<li>Use an antivirus on your phone. <a href=\"https:\/\/www.malwarebytes.com\/android\" target=\"_blank\" rel=\"nofollow\">Malwarebytes for Android<\/a>&nbsp;shows you&nbsp;exactly what information you&#8217;re sharing with each app on Android, so you can&nbsp;keep an eye on your privacy. Malwarebytes&nbsp;detects the LetMeSpy app as Android\/Monitor.LetMeSpy.<\/li>\n<\/ul>\n<h2>Coalition Against Stalkerware<\/h2>\n<p>Malwarebytes is a founding member of the&nbsp;<a href=\"https:\/\/stopstalkerware.org\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Coalition Against Stalkerware.<\/a>&nbsp;We continue to share intelligence with the Coalition Against Stalkerware to improve industry-wide detections while also guiding the domestic abuse support networks within the coalition through thorny, technical questions of detection, removal, and prevention.<\/p>\n<hr \/>\n<p><strong>We don&rsquo;t just report on threats&mdash;we remove them<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by <a href=\"https:\/\/www.malwarebytes.com\/for-home\">downloading Malwarebytes today<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/06\/phone-monitoring-app-letmespy-hacked-victim-data-posted-online\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<table cellpadding=\"10\">\n<tr>\n<td valign=\"top\" align=\"left\">\n<p>Categories: <a href=\"https:\/\/www.malwarebytes.com\/blog\/category\/news\" rel=\"category tag\">News<\/a><\/p>\n<p>Categories: <a href=\"https:\/\/www.malwarebytes.com\/blog\/category\/personal\" rel=\"category tag\">Personal<\/a><\/p>\n<p>Stalkerware-type app LetMeSpy has been hacked, with the attacker taking user data with it, the service has announced.<\/p>\n<table width=\"100%\">\n<tr>\n<td align=\"right\">\n<p><b>(<a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/06\/phone-monitoring-app-letmespy-hacked-victim-data-posted-online\" title=\"Spyware app LetMeSpy hacked, tracked user data posted online\">Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/06\/phone-monitoring-app-letmespy-hacked-victim-data-posted-online\">Spyware app LetMeSpy hacked, tracked user data posted online<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[32,26699],"class_list":["post-22355","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-news","tag-personal"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/22355","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=22355"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/22355\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=22355"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=22355"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=22355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}