Why cases matter more than claims
Stalkerware companies describe their products as tools for parents and employers. What regulators, prosecutors, and hackers have actually found inside these companies tells a different story. The cases below are drawn from federal indictments, FTC complaints and orders, a state attorney general settlement, and reporting that TechCrunch has built into the primary public record of the industry’s repeated data breaches. If you’re reading this because you think you’re being monitored right now, Is someone tracking my phone? and Safety first are the places to start before anything else.
This article is about specific, documented incidents and what happened to the people and companies behind them. For the wider picture — how these apps are marketed, distributed, and detected, and where the law stands — see The business of stalkerware.
The first criminal conviction: StealthGenie (2014)
In September 2014, a federal grand jury in the Eastern District of Virginia indicted Hammad Akbar, CEO of a company called InvoCode, for selling and advertising StealthGenie, an app the government said could intercept calls, texts, emails, voicemail, and photos, and could remotely turn on a phone’s microphone to “record sounds and conversations that occurred near the phone,” all without the phone owner’s knowledge (DOJ press release). The FBI had bought and tested the app itself in an undercover operation before the arrest (NPR).
Akbar pleaded guilty that November to sale of an interception device and advertisement of a known interception device. The court sentenced him to time served and ordered him to pay a $500,000 fine and forfeit StealthGenie’s source code to the government — the Justice Department called it “the first-ever criminal conviction concerning the advertisement and sale of a mobile device spyware app” (DOJ press release). Assistant Attorney General Leslie Caldwell put it directly: “Spyware is an electronic eavesdropping tool that secretly and illegally invades individual privacy. Make no mistake: selling spyware is a federal crime” (DOJ press release). A federal court had already ordered the FBI to take the StealthGenie website offline before the plea, and it never came back.
It would be more than a decade before the US government secured another criminal conviction against a stalkerware operator.
The FTC’s first stalkerware case: Retina-X (2019–2020)
In October 2019, the FTC announced its first-ever case against a “stalking app” developer, targeting Retina-X Studios and owner James N. Johns Jr. over three apps — MobileSpy, PhoneSheriff, and TeenShield — sold to more than 15,000 subscribers before the company stopped selling them in 2018 (FTC press release). The FTC’s complaint alleged the apps let purchasers monitor a device without the user’s knowledge, and that installing them required bypassing manufacturer security protections — exposing devices to security vulnerabilities and voiding warranties (FTC press release).
The FTC also found Retina-X had failed to secure the data it collected: the complaint states a hacker accessed the company’s cloud storage account twice between February 2017 and 2018, taking usernames, encrypted passwords, text messages, GPS locations, contacts, and photos — and that the company didn’t even learn about the first breach until a journalist, tipped off by the hacker, contacted them in April 2017 (FTC press release). FTC Bureau of Consumer Protection director Andrew Smith said the apps “were designed to run surreptitiously in the background and are uniquely suited to illegal and dangerous uses” (FTC press release). The settlement required Retina-X to delete all collected data and build a security program — but notably did not ban the company from the monitoring-app business outright, a gap the FTC would close in its next case.
The first outright ban: SpyFone / Support King (2021)
In September 2021, the FTC announced a first for the agency: an order banning a stalkerware company and its executive from the surveillance business entirely. The complaint alleged Support King LLC, doing business as SpyFone.com, and CEO Scott Zuckerman sold apps giving purchasers secret access to photos, text messages, web history, GPS location, emails, and video chats from a monitored phone, and that using some features required “rooting” an Android device, exposing it to further security risks (FTC press release). Acting Bureau of Consumer Protection director Samuel Levine called SpyFone “a brazen brand name for a surveillance business that helped stalkers steal private information” (FTC press release).
The FTC’s complaint also detailed a breach: in August 2018, a hacker accessed SpyFone’s servers and obtained personal data belonging to roughly 2,200 people, and the company allegedly failed to follow through on a promise to investigate with an outside security firm and law enforcement (FTC press release). The final order, in addition to the ban, required SpyFone to delete the data it had illegally harvested and notify device owners their phones might have been compromised.
The ban did not end the story. A December 2022 TechCrunch investigation found a still-active stalkerware operation called SpyTrac — with more than a million user records, one of the biggest known active Android stalkerware operations, surpassing TheTruthSpy’s victim count more than threefold — run by developers with direct technical and financial ties to Support King, including shared Amazon Web Services credentials also linked to Zuckerman’s other ventures (TechCrunch). Zuckerman denied any affiliation with SpyTrac; shortly after TechCrunch’s questions, SpyTrac’s website and related sites went offline that same December (TechCrunch). More recently, Zuckerman petitioned the FTC in 2025 to vacate or modify the 2021 order; in December 2025 the Commission voted 2-0 to deny that petition, finding he had not shown changed facts or law that would justify reopening it (FTC press release).
New York’s settlement with the Hinchy companies (2023)
In February 2023, New York Attorney General Letitia James announced a $410,000 settlement with Patrick Hinchy and 16 of his companies over apps sold under names including Auto Forward, Highster Mobile, and PhoneSpector (NY AG press release). The Attorney General’s investigation found the companies had built fake independent review websites that in reality only promoted their own products, failed to disclose the security risks of rooting or jailbreaking a device to install the software, and used confusing refund policies and false data-security claims to lure buyers (NY AG press release). Attorney General James said plainly: “Snooping on a partner and tracking their cell phone without their knowledge isn’t just a sign of an unhealthy relationship, it is against the law” (NY AG press release).
The agreement required Hinchy’s companies to pay penalties and disgorgement and to modify their software so that a monitored device’s owner would be notified that the app was installed and what data it collected (NY AG press release). PhoneSpector and Highster — not known to have been hacked themselves — subsequently shut down following the New York attorney general’s action, according to TechCrunch’s later reporting on the industry’s pattern of shutdowns (TechCrunch).
pcTattletale: breach, shutdown, and the second-ever conviction
pcTattletale marketed itself as employee and child-monitoring software while also openly advertising the ability to secretly track spouses and partners. In May 2024, a hacker exploited a flaw in the company’s infrastructure to obtain private Amazon Web Services keys, defaced pcTattletale’s website, and published large amounts of data taken from its servers, including customer information and victims’ stolen data; TechCrunch independently confirmed that screenshots taken from monitored devices were publicly accessible as a result (TechCrunch). Data breach notification service Have I Been Pwned logged 138,000 affected customer accounts (TechCrunch). Founder Bryan Fleming told TechCrunch by text message, “I deleted everything because the data breach could have exposed my customers. The account is closed [and] the servers are deleted” — and pcTattletale never came back online (TechCrunch).
The breach was not the end of Fleming’s legal exposure. Homeland Security Investigations, a division of Immigration and Customs Enforcement, had already been investigating pcTattletale since 2021 as part of a broader look at the stalkerware industry, according to a 2022 search-warrant affidavit later unsealed in court (TechCrunch). An undercover HSI agent posed as an affiliate marketer and exchanged emails with Fleming, who reportedly supplied banner ads promoting the software as a way to “catch a cheater” (TechCrunch). In January 2026, Fleming pleaded guilty in federal court in San Diego to charges including computer hacking, conspiracy, and selling and advertising surveillance software for unlawful uses — TechCrunch reported it as the first successful federal prosecution of a stalkerware operator in the US in more than a decade, since StealthGenie (TechCrunch). In April 2026, Fleming was sentenced in San Diego federal court to time served and a $5,000 fine, after prosecutors themselves recommended no custodial sentence or fine; a court affidavit found he had, in some cases, “knowingly assisted customers seeking to spy on nonconsenting, non-employee adults” (TechCrunch).
LetMeSpy: a breach that erased the company
LetMeSpy, an Android app developed by the Poland-based company Radeal, was hit by a June data breach: an attacker gained unauthorized access to the company’s database, downloaded it, and — in an unusual twist for these incidents — deleted the underlying data at the same time (TechCrunch). A copy of the stolen database, obtained by the nonprofit transparency collective DDoSecrets and shared with TechCrunch, showed the app had been used to pull data — including call logs, text messages, and real-time location data — from more than 13,000 compromised Android devices worldwide, even though LetMeSpy’s own site had previously claimed to control more than 236,000 devices (TechCrunch).
LetMeSpy posted a notice confirming the breach had involved “unauthorized access to the LetMeSpy website’s database, downloading and at the same time deleting data from the website by the author of the attack,” and announced it would cease operations by the end of August 2023 (TechCrunch). The app stopped functioning and its website stopped offering downloads. TechCrunch’s reporting on the breach also noted that another stalkerware operation, SpyTrac — tied to the already-banned Support King — had shut down several months earlier, in December 2022, following TechCrunch’s own reporting (TechCrunch).
mSpy and the recurring-breach pattern
mSpy, run by the Ukraine-based company Brainstack, is one of the longest-running consumer phone-surveillance operations, and TechCrunch’s July 2024 reporting on its third known breach illustrates why stalkerware’s security failures matter beyond any one company. Unknown attackers stole more than 100 gigabytes of Zendesk-hosted customer support records dating back to 2014, exposing roughly 2.4 million unique customer email addresses along with the contents of support tickets and attachments (TechCrunch). Have I Been Pwned added the dataset to its records after founder Troy Hunt verified it with affected users (TechCrunch).
TechCrunch’s review of the leaked tickets found requests for help “surreptitiously” monitoring partners’ phones, and traced inquiries to a sitting US federal appeals court judge (who used mSpy “entirely in his personal capacity to address a family matter,” according to a court spokesperson) and to a US Social Security Administration watchdog office asking whether it could use the software in criminal investigations (TechCrunch). This was mSpy’s third confirmed breach since roughly 2010, following an earlier 2018 leak of more than 2 million customer records (TechCrunch).
mSpy is far from alone. In February 2025, TechCrunch reported that a security researcher had found a bug in two related apps, Cocospy and Spyic, that exposed messages, photos, and call logs pulled from monitored phones, along with the email addresses of the people who had signed up to plant the apps on someone else’s device — 1.81 million for Cocospy and 880,167 for Spyic, which Have I Been Pwned founder Troy Hunt loaded as 2.65 million unique addresses after removing duplicates (TechCrunch). By TechCrunch’s own running tally, at least 27 stalkerware companies have been hacked or have leaked customer or victim data since 2017, and eight of those have shut down — some tied directly to a breach, others (like PhoneSpector and Highster) following the New York attorney general’s action instead (TechCrunch).
What these cases add up to
Retina-X, SpyFone, pcTattletale, LetMeSpy, and mSpy were all exposed through a combination of hackers who broke into their poorly secured servers, journalists who followed the resulting leaked data, and — much more rarely — years-long federal investigations that ended in a guilty plea. Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, told TechCrunch that stalkerware makers are a “soft target” precisely because “the people who run these companies are perhaps not the most scrupulous or really concerned about the quality of their product” (TechCrunch). She also cautioned that killing one company rarely kills the practice — SpyFone’s alleged reappearance as SpyTrac, and Support King’s earlier connection to the same pattern, is a documented example of that (TechCrunch).
The practical lesson for anyone who suspects stalkerware on their own phone is uncomfortable but important: if an app like this is on your device, your data isn’t just exposed to whoever installed it — it may already be sitting on a server with a documented history of being breached. That’s a reason to act, but not necessarily to act immediately or alone. Removing an app can alert whoever installed it, which is why Safety first walks through the trade-offs before you touch anything, and What is stalkerware? explains how these apps typically get onto a device in the first place. For how these companies market themselves, dodge app-store bans, and evade detection today, The business of stalkerware picks up where this article leaves off.