Slashdot Mirror


Mobile Spyware Maker mSpy Leaks Millions of Sensitive Records (krebsonsecurity.com)

mSpy, the makers of a software-as-a-service product that claims to help more than a million paying customers spy on the mobile devices of their kids and partners, has leaked millions of sensitive records online, including passwords, call logs, text messages, contacts, notes and location data secretly collected from phones running the stealthy spyware. Krebs On Security reports: Less than a week ago, security researcher Nitish Shah directed KrebsOnSecurity to an open database on the Web that allowed anyone to query up-to-the-minute mSpy records for both customer transactions at mSpy's site and for mobile phone data collected by mSpy's software. The database required no authentication. Before it was taken offline sometime in the past 12 hours, the database contained millions of records, including the username, password and private encryption key of each mSpy customer who logged in to the mSpy site or purchased an mSpy license over the past six months. The private key would allow anyone to track and view details of a mobile device running the software, Shah said. In addition, the database included the Apple iCloud username and authentication token of mobile devices running mSpy, and what appear to be references to iCloud backup files. Anyone who stumbled upon this database also would have been able to browse the Whatsapp and Facebook messages uploaded from mobile devices equipped with mSpy. Other records exposed included the transaction details of all mSpy licenses purchased over the last six months, including customer name, email address, mailing address and amount paid. Also in the data set were mSpy user logs -- including the browser and Internet address information of people visiting the mSpy Web site.

18 comments

  1. main screen turn on by Anonymous Coward · · Score: 0

    all your base are belong to us

  2. Lay down with dogs by Anonymous Coward · · Score: 0

    And you get Maginault Newman'ed like a fucking moron-in-Chief

  3. And now.... by JustAnotherOldGuy · · Score: 1

    "mSpy, the makers of a software-as-a-service product that claims to help more than a million paying customers spy on the mobile devices of their kids and partners, has leaked millions of sensitive records online, including passwords, call logs, text messages, contacts, notes and location data secretly collected from phones running the stealthy spyware."

    And now they can spy on you!

    --
    Just cruising through this digital world at 33 1/3 rpm...
  4. Justice. by WolfgangVL · · Score: 1

    Let this be a lesson to them. Today it was Mspy... tomorrow it could be.. YOU!

    --
    You are being ripped off every second of every day, so that advertisers can help rip you off even more tomorrow.
  5. Cue the NSA supporters... by Anonymous Coward · · Score: 0

    If you are doing nothing wrong, you have nothing to hide.

    1. Re:Cue the NSA supporters... by Anonymous Coward · · Score: 0

      If you are doing nothing wrong, you have nothing to hide.

      Interestingly enough, the ones saying this probably have plenty that they'd like to hide, intelligence agencies and private individual shills or uninformed people alike. Perhaps if NSA surveillance bites the latter in the ass hard enough, they will realize that they actually do have things to hide that aren't illegal.

    2. Re: Cue the NSA supporters... by Anonymous Coward · · Score: 0

      The "not having anything to hide" argument starts with the faulty premise that privacy is about hiding a wrong

    3. Re: Cue the NSA supporters... by Anonymous Coward · · Score: 0

      In Soviet America, *everything* is illegal.

      Remember, 95% of the souls locked up in the American Gulag were coerced into "confessing" and never convicted by a jury of their peers.

    4. Re: Cue the NSA supporters... by Anonymous Coward · · Score: 0

      On the other hand, prisoners in the US have a better life than pensioners in Putin's people's paradise.

  6. MongoDB by astrofurter · · Score: 1

    I wonder if it was a MongoDB instance. IIRC their security model defaults to wide open to the world.

    1. Re: MongoDB by Anonymous Coward · · Score: 0

      But it's webscale so it's ok.

  7. Surprise! Hard to hire good people to do evil. by mangastudent · · Score: 1

    It's a lesson we've seen many times before, if you're doing something fundamentally evil, if you're evil yourself, it's hard to hire good, competent help.

    Someone else wondered if they used a database notorious for coming with wide open defaults. Doesn't matter, a competent person will investigate and implement the security that's appropriate. Competent managers and company owners will budget some time and money for Red Team penetration testing.

    Of course, there are technical people out there who are both evil and at least somewhat competent, but they're probably somewhat hard to find and hire, and they're by definition dangerous to employ.

  8. Almost used this.. by evanchik · · Score: 1

    A friend asked me for something to install on his wifes cellphone, as he was seeing suspect activities (sad), we were about to go forward with this. But i said you have to think of the worst case scenario One which would be they would lock you out of your itunes account or delete information if not paid in Bitcoin in xdays. never thought of this one of top of head. All of your iphone data are belong to us now.

    1. Re:Almost used this.. by Wulf2k · · Score: 1

      If you're at the point where you're lojacking your wife's phone, it's probably time to break up anyway.

      Either she's cheating, and you should leave, or you violate her trust, and she should leave you.

    2. Re: Almost used this.. by Anonymous Coward · · Score: 0

      Just turn on Google location history for her. Then Google does the work for you (as if they aren't tracking her already).

  9. Hold them accountable by omfglearntoplay · · Score: 1

    Companies that screw up like this should have BIG penalties. I thought I read about some laws starting to happen in some places that will kick their asses, is that right?

  10. Think of the Childrens! #freedumbs by Anonymous Coward · · Score: 0

    So brave. So free!

  11. they seemed good for all this time... by Anonymous Coward · · Score: 0

    Hi, folks!
    I've been using it for 7 months. Support staff was always responsive, didn't know they could possibly not to respond on somebody's request. Anyway, I found an official statement on their blog: https://blog.mspy.com/dont-panic-your-data-is-safe-blog-mspy/