8 mins read
Commercial spyware not only collects private information, but it can also lose it.
Consumer surveillance services such as mSpy, TheTruthSpy, pcTattletale, Cocospy, Spyic, and Spyzie have suffered security breaches or exposed databases containing information about customers and, in some cases, the people they monitored.
This can victimize someone twice. First, spyware secretly collects their messages, photos, location, or other personal information. Then, a breach at the spyware company exposes that information to hackers or the wider internet.
An email-based exposure scan may help reveal whether information associated with you appears in known breaches, credential dumps, stealer logs, or other leaks. deleteme.com provides scans covering data breaches, dark-web sources, digital footprints, data brokers, and other online sources. Its team can also investigate and pursue removal requests when exposed information is found.
What is consumer spyware?
Consumer spyware is commercially available monitoring software installed on another person's phone, tablet, or computer.
These products are often promoted as:
Parental-control software
Employee-monitoring tools
Family-safety applications
Phone-tracking services
Partner-monitoring software
When used without the device owner's knowledge or consent, they are commonly called stalkerware or spouseware.
Depending on the product, commercial spyware may collect:
Emails and text messages
WhatsApp and other private chats
Photos and videos
Call histories and recordings
Contacts
Browsing history
GPS locations
Social media activity
Screenshots
Keystrokes and passwords
Microphone or camera recordings
The collected information is usually uploaded to the spyware company's servers. The customer who installed the app can then view the monitored person's information through an online dashboard.
This creates an additional risk. If the spyware provider is hacked or leaves its systems unsecured, the customer's information and the victim's stolen data may be exposed again.
Major publicly reported commercial spyware leaks
According to TechCrunch’s ongoing tally, at least 27 stalkerware companies have been hacked or exposed customer or victim information since 2017. Several companies have experienced multiple security incidents.
mSpy
mSpy is one of the longest-running commercial phone-monitoring services. It promotes its product for monitoring children and employees, but it has also been used to monitor people without their consent.
mSpy has experienced several reported breaches.
In 2024, attackers obtained more than 100 gigabytes of information from mSpy’s customer-support system. The stolen records dated back to 2014 and included:
Customer email addresses
Support requests
Email messages
Attachments and personal documents
Approximate locations derived from IP addresses
Information about some people targeted by mSpy customers
Approximately 2.4 million unique email addresses from the breach were added to the Have I Been Pwned breach-notification service. According to TechCrunch, this was the third known mSpy breach.
Finding an email address in the mSpy data does not automatically prove that its owner installed spyware or was monitored. The address might belong to a customer, employee, journalist, investigator, person who contacted support, or someone mentioned in a support ticket. Each match must be interpreted carefully.
TheTruthSpy, Copy9, and MxSpy
TheTruthSpy was connected to a network of similarly branded Android spyware apps, including Copy9, MxSpy, iSpyoo, SecondClone, TheSpyApp, ExactSpy, FoneTracker, and GuestSpy.
A leaked master database contained records relating to almost 400,000 compromised devices. Other leaked material included customer transactions and internal documents.
The exposed information revealed how the network collected data from monitored phones and sold access through multiple brands. The leaked records were also used to create a lookup tool that allowed people to check whether a device identifier appeared in the database.
TheTruthSpy and its related services have reportedly suffered several breaches or data exposures.
pcTattletale
pcTattletale was a commercial surveillance service for Android and Windows devices. It allowed customers to view screenshots taken from monitored devices.
In 2024, a hacker defaced the company’s website and published links to information from its servers. The exposed material included customer databases and information taken from monitored devices.
An analysis found more than 300 million screenshots stored on pcTattletale’s systems. The service reportedly had approximately 138,000 registered customers.
Following the breach, the company’s founder said pcTattletale was shutting down.
LetMeSpy
LetMeSpy was an Android monitoring app that collected messages, call logs, and location information from monitored phones.
In 2023, hackers breached the company and reportedly deleted information from its servers. LetMeSpy subsequently announced that it would end operations.
A company shutting down does not necessarily mean that every copy of its exposed information has disappeared. Data obtained before the shutdown may remain in other databases, archives, or leak repositories.
Cocospy, Spyic, and Spyzie
Cocospy, Spyic, and Spyzie were closely related commercial surveillance apps with similar code and infrastructure.
In 2025, a researcher discovered a vulnerability exposing information collected from monitored devices. The accessible information included:
Messages
Photos
Call logs
Other private phone data
Customer email addresses
The exposure affected data associated with approximately 3.1 million people across the three services.
For Cocospy and Spyic alone, approximately 2.65 million unique customer email addresses were added to Have I Been Pwned. The breach was classified as sensitive, restricting searches so people could check only email addresses they controlled.
Spyhide
A vulnerability in Spyhide reportedly allowed access to its back-end database and years of information taken from approximately 60,000 monitored devices.
After Spyhide shut down, a related service reportedly appeared under the name Oospy. This demonstrates how a spyware operation can close following public exposure and later reappear under a different brand.
Family Orbit
Family Orbit marketed family-monitoring and parental-control software.
The company reportedly left approximately 281 gigabytes of personal information online with inadequate protection. The exposed files included information collected from monitored devices.
MobiiSpy
MobiiSpy reportedly left highly sensitive victim information on an internet-accessible server.
The exposed material included approximately:
25,000 audio recordings
95,000 images
This type of exposure is particularly dangerous because it may reveal the private communications and daily activities of people who never knew they were being monitored.
uMobix and related services
In 2026, a hacktivist reportedly obtained and published more than 500,000 payment records associated with customers of monitoring services connected to uMobix, Geofinder, Peekviewer, and related brands.
The exposed information included customer email addresses and transaction details. A record may show that someone purchased a monitoring service, but it does not automatically identify the person they monitored.
Can an email scan tell you whether you were spied on?
An email scan can reveal whether an address appears in breach databases, credential dumps, stealer logs, or other searchable leaks. It cannot, by itself, confirm whether spyware is currently installed on a phone.
If your email appears in a commercial spyware leak, it might belong to:
A person who purchased the spyware
A registered account holder
Someone who contacted customer support
An employee or contractor
A person mentioned in a support request
A monitoring target whose information was uploaded
A journalist, researcher, or investigator who contacted the company
Many spyware victims never give their email address to the spyware provider. The person who installed the software may use an entirely different account.
Therefore:
A match does not always prove that you were monitored.
No match does not prove that your device is safe.
An exposure scan is not the same as a forensic examination of your phone.
How deleteme.com scans for exposure
The deleteme.com OneEmail Dark Web Scan searches using an email address across sources that can include:
Data breaches
Credential dumps
Leaked databases
Infostealer and stealer logs
Dark-web forums and marketplaces
Other digital-footprint sources
The resulting report can include an exposure overview, risk scoring, analysis, recommendations, breach findings, masked password information, and identified stealer-log activity.
deleteme.com also provides free Privacy Meters covering:
Dark Web and Breach Exposure
Data Broker Exposure
Digital Footprint Exposure
A scan may identify a match connected to a commercial spyware company when the relevant breach data is available in the sources being searched. Coverage depends on whether the dataset is known, lawfully accessible, and included in the searched repositories.
On-demand investigation of spyware-company exposure
If you are concerned about a specific spyware company, deleteme.com can conduct further investigation on request using publicly available sources and lawfully accessed or authorized databases.
An on-demand investigation may look for information associated with your:
Email addresses
Name and aliases
Phone numbers
Usernames
Domain names
Social media profiles
Other identifying details
The investigation may help determine:
Whether your information appears in an accessible spyware-related leak.
Which company or incident is connected to the exposure.
What personal information was included.
Whether the record appears to identify a customer, victim, employee, or another party.
Whether the information has been republished on another website.
Whether a removal, suppression, privacy, or legal request is possible.
Investigations are limited to lawful purposes and legally accessible sources. Results also depend on the completeness and accuracy of the available data.
How deleteme.com helps pursue removal
Through its Data Breach Scan and Removal service, deleteme.com helps identify exposed personal or business information and pursue removal from breach providers, leak websites, and other online sources.
Its Custom Removal service addresses complex websites that publish private, sensitive, defamatory, or otherwise harmful information.
Depending on the case, deleteme.com may use:
Direct takedown requests
Privacy and data-protection rights
Negotiations with website operators
Terms-of-service complaints
Search-engine removal requests
Defamation or intellectual-property arguments
Legal escalation where appropriate
Customers can track the status of removal requests through the deleteme.com dashboard.
Removal cannot be guaranteed in every case. Some sites may refuse to cooperate, operate from difficult jurisdictions, or lack a reliable contact process. Information may also reappear on mirrors or other platforms, making continued monitoring important.
What deleteme.com does not establish
An email or dark-web scan looks for evidence of data exposure. It does not directly examine the apps or files installed on your phone.
The scan does not, by itself:
Confirm that spyware is currently installed
Identify every possible monitoring application
Remove an application from your device
Prove who installed the spyware
Prove whether a listed email belongs to a customer or victim
Guarantee that every copy of leaked information can be erased
If you need to determine whether a device is actively compromised, consult a qualified mobile-security or digital-forensics specialist.
Signs that spyware may be monitoring you
Possible warning signs include:
Someone knowing private information they should not know
Unexplained battery drain or overheating
Sudden increases in mobile-data use
An unfamiliar app with extensive permissions
Unknown accessibility or device-administrator settings
Unexpected microphone, camera, or location activity
Security protections being disabled
Unfamiliar account logins
Authentication or password-reset messages you did not request
A partner insisting on knowing your device passcode
These signs are not conclusive. Ordinary software problems can produce similar symptoms.
Section 5 — Signs, Next Steps & Resources
What to do if you suspect spyware
If an abusive partner or stalker may have installed monitoring software, consider your safety before changing the device. Removing the software could alert the person who installed it.
When possible:
Use a separate, trusted device to seek help.
Preserve suspicious messages, emails, and screenshots.
Contact a domestic-abuse support organization if personal safety is involved.
Ask a qualified specialist to examine the device.
Change important passwords from a trusted device.
Review email-forwarding rules and account-recovery information.
Enable multifactor authentication.
Run an email exposure scan at deleteme.com.
Request further investigation if a spyware-company exposure is suspected.
Pursue removal or suppression when exposed information is found.
Find your information before someone else does
Commercial spyware companies have collected enormous amounts of sensitive information—and many have failed to protect it.
The deleteme.com free scan helps you search for information connected to your email across data breaches, dark-web sources, data brokers, and your wider digital footprint.
If the initial scan identifies suspicious exposure—or if you are concerned about a particular spyware company—deleteme.com can investigate further on request and help pursue removal where a valid path exists.
Scan your email at deleteme.com to discover whether your information has appeared in a breach, leak, credential dump, or stealer log.
Sources
Need help? Visit our Help Center.
More Privacy Tips





