An unknown actor breached phone monitoring Android app LetMeSpy and gained access to its users’ data, including the contents of messages and call logs. Polish security blog Niebezpiecznik first reported the breach on June 21, which LetMeSpy later confirmed.
“As a result of the attack, the criminals gained access to e-mail addresses, telephone numbers and the content of messages collected on accounts,” an announcement on LetMeSpy’s website reads.
LetMeSpy markets its spyware as parental control or employee monitoring software. Users that install the software onto other devices can see the contents of messages, call logs, and even track the device location. The app also is notoriously difficult to detect and remove, much like others in the same category.
Many people, however, have used these kinds of apps to snoop on their partners, which is where the term “Stalkerware” comes from. Typically, a person uses physical access to their partner’s device to install the app without their knowledge. Google even banned Stalkerware ads in 2021 and continues to track and remove them.
As of January 2023, LetMeSpy claimed that users relied on its app to track over 236,000 devices. The data collected from these devices amounts to nearly 150 million information logs, including message content, call logs, and locations.
Despite their apparent stealth, hackers have breached many similar apps in recent years, including Retina-X (twice), FlexiSpy, Mobistealth, Spy Master Pro, SpyHuman, Spyfone, Family Orbit, mSpy, Copy9, Xnore, TheTruthSpy (twice), KidsGuard, Xnspy and Support King.
Details of the LetMeSpy Breach
Polish security blog Niebezpiecznik published its findings last week, stating it found 26,000 email addresses and 16,000 SMS text messages —which also contained passwords and security codes for other services. Additionally, they found call logs of the people being tracked, although Niebezpiecznik did not provide any figures for this data set.
Nonprofit transparency collective DDoSecrets apparently obtained a dataset from the leak, which it shared with TechCrunch. The dataset contained messages and call logs of 13,000 devices dating all the way back to 2013. DDoSecrets has not published the dataset on its website yet.
It is currently unclear exactly how many of the app’s users were impacted by the incident. TechCrunch stated the dataset also contained more 13,400 location data points belonging to thousands of tracked victims.
“The data also contained the spyware’s master database, including information about 26,000 customers who used the spyware for free and the email addresses of customers who bought paying subscriptions,” TechCrunch reported.
How to Remove Stalkerware from Your Phone
Stalkerware, and other kinds of spyware, are extremely intrusive tools that violate people’s privacy. Unfortunately, there are many ways in which one’s device can get infected. If you’re concerned about LetMeSpy on your Android device, search your list of apps for one called “LMS.”
LetMeSpy is but just one type of spyware, and we recommend learning how to tell if you’re phone is being monitored. Our guide will take you through all the possible signs of compromise and show you exactly how to remove spyware from your device.
The best way to protect yourself from malicious, intrusive applications is by installing a good antivirus. If you’re not sure which one to choose, you can go through our list of the best antivirus software in 2023.
