Streets Wired

Security / Privacy

Your Phone Can Be Spied On Twice

Stalkerware can expose what is on a phone, while the companies collecting that data can become breach targets themselves. mSpy is a useful case study in both risks.

#Stalkerware #Spyware #Privacy #Data Breach #Mobile Security #Account Security

Commercial stalkerware creates two separate privacy problems.

The first is the obvious one: software installed on a phone can be used to monitor location, messages, email, photos, browsing activity, and other private information without the device owner understanding what is happening. The Federal Trade Commission warns that these tools can be deliberately hidden and may be used in abusive relationships.

The second problem is easier to miss: the company collecting all of that sensitive material becomes a target too.

TechCrunch reported in 2026 that at least 27 stalkerware companies since 2017 were known to have been hacked or to have leaked customer or victim data. The same report points to mSpy’s 2024 breach, which exposed millions of customer-support tickets. Malwarebytes reported that those tickets stretched back years and included personal information, support conversations, and attachments.

That is the part worth sitting with: software sold as a way to watch somebody else can create another database containing some of the most intimate data on the device.

How people usually lose control of a phone or account

Not every compromise looks like movie hacking. Most start with a much simpler opening.

Physical access. Someone who can unlock a phone may be able to change settings, add monitoring software, or approve permissions the owner never intended to grant.

Phishing. Fake login pages and convincing messages try to capture passwords, authentication codes, or account-recovery information.

Reused credentials. A password leaked from one service can be tried against another account.

SIM swapping. A criminal may convince a carrier to move a phone number to another SIM, which can expose accounts that still rely on text-message recovery or authentication.

MFA fatigue. Repeated login prompts can be used to pressure a person into approving one by mistake.

Those are attack paths worth understanding because the defenses are concrete.

Lock it down

Use a different password for every important account or move to passkeys when the service supports them. A password manager makes unique credentials much easier to maintain.

Turn on multifactor authentication for email, social media, financial accounts, and the Apple or Google account controlling the phone. CISA recommends phishing-resistant MFA, including FIDO security keys and passkeys, because they resist many common credential-stealing techniques better than text-message codes.

Keep the phone operating system and apps updated. Review signed-in devices, active sessions, account-recovery options, and apps with access to contacts, photos, location, microphone, camera, accessibility features, or device-administration privileges.

Ask your carrier what protections it offers against unauthorized number transfers, and secure the carrier account with its own strong credential or PIN.

If you think somebody is already monitoring you

Do not assume that immediately deleting an app or changing a password is always the safest first move.

The FTC notes that removing stalkerware or changing device behavior can alert the person doing the monitoring, especially in an abusive relationship. Using a different trusted device to research options, preserving evidence, and making a safety plan may be more important than quickly cleaning the phone.

The point of this column is not to make everybody paranoid.

It is to make the attack surface visible enough that ordinary people can make better security decisions before something goes wrong.