Security

Spyware app pcTattletale was hacked and its website defaced

Comment

a collection of patterned illustrated eyes in blue and pink on a darker blue background
Image Credits: Jake O'Limb / PhotoMosh / Getty Images

U.S.-made consumer-grade spyware app pcTattletale has been hacked and its internal data published to its own website, according to a hacker who claimed responsibility for the breach.

The hacker posted a message on pcTattletale’s website late Friday, claiming to have hacked the servers containing pcTattletale’s operations. The spyware maker’s website briefly had links containing files from its servers, which appeared to include some victims’ stolen data. TechCrunch is not linking to the site given the ongoing risk to victims, whose private data has already been compromised by the spyware.

pcTattletale’s founder Bryan Fleming did not return an email requesting comment. It’s not clear if Fleming can receive email due to his company’s ongoing outage.

The hacker did not provide a specific motivation for the breach. The hack comes several days after a security researcher said he found and reported a vulnerability in the spyware app, which leaks the screenshots of the devices it was planted on. The researcher, Eric Daigle, said he did not publish specific details of the flaw because pcTattletale ignored requests to fix the vulnerability.

The hacker who compromised and defaced pcTattletale’s website did not exploit the vulnerability that Daigle found but said pcTattletale’s servers could be tricked into turning over the private keys for its Amazon Web Services account, which grants access to the spyware’s operations.

pcTattletale, a kind of remote access app often referred to as “stalkerware” for its ability to track people without their knowledge or consent, allows the person who planted the app to remotely view the target’s Android or Windows device and its data from anywhere in the world. pcTattletale says the app “runs invisibly in the background on their workstations and cannot be detected.” Spyware apps are stealthy by nature, and as such are difficult to identify and remove.

Earlier this week, TechCrunch revealed that pcTattletale was used to compromise the front desk check-in systems at several Wyndham hotels across the United States, which leaked screenshots of guest details and customer information. Wyndham would not say whether it authorized or allowed its franchised hotels to use the spyware app on its systems.

This is the latest example of a spyware maker losing control of the highly sensitive and personal data it collects from the devices of its targets. In recent years, more than a dozen spyware and stalkerware companies have been hacked or otherwise spilled victims’ private data — in some cases several times over — according to an ongoing tally by TechCrunch.

That list of hacked spyware makers includes LetMeSpy, a spyware made by a Polish developer, which shut down in June 2023 after its systems were hacked and its back-end data deleted; and TheTruthSpy, a phone spyware operation created and operated by Vietnamese developers, which was hacked again in February. 

Other hacked spyware makers include KidsGuard, Xnspy, Support King, Spyhide — and now pcTattletale.


If you or someone you know needs help, the National Domestic Violence Hotline (1-800-799-7233) provides 24/7 free, confidential support to victims of domestic abuse and violence. If you are in an emergency situation, call 911. The Coalition Against Stalkerware has resources if you think your phone has been compromised by spyware.

More TechCrunch

Cohere, a generative AI startup co-founded by ex-Google researchers, has raised $500 million in new cash from investors including Cisco, AMD and Fujitsu. Bloomberg says that the round, which also…

Cohere raises $500M to beat back generative AI rivals

Indian food delivery and quick commerce startup Swiggy is pivoting one of its smaller businesses, Swiggy Minis, into a link-in-bio service.

Swiggy turns Minis into a link-in-bio platform

Fragment’s digital ledger API applies real-time, double entry accounting to find where things aren’t adding up.

Fintech Fragment eases ledger problems, nabs $9M from Stripe, Jack Altman, BoxGroup, others

Identity management is one of the most common fulcrums around which security breaches have pivoted in the last several years, and one of the main reasons it’s the gift that…

Linx emerges from stealth with $33M to lock down the new security perimeter: Identity

Featured Article

Pesa unlocks new markets to keep remittances flowing to emerging economies

Founders of Pesa, a remittance fintech, know too well how costly, inaccessible and unreliable remittance services drive people to opt for risky informal channels —  like WhatsApp groups  — to transfer money.  Their firsthand experience using informal channels and realizing how prevalent their use was among Africans living in the…

Pesa unlocks new markets to keep remittances flowing to emerging economies

A little more than a year after launching the ROG Ally, Asus is releasing a refined version of its portable device, the ROG Ally X. This Windows-based machine starts shipping…

The Asus ROG Ally X turns PC gaming into a portable console

As a part of TechCrunch’s ongoing Women in AI series, which seeks to give AI-focused women academics and others their well-deserved — and overdue — time in the spotlight, TechCrunch interviewed Lakshmi…

CIA AI director Lakshmi Raman claims the agency is taking a ‘thoughtful approach’ to AI

With President Joe Biden dropping out of the race, Vice President Kamala Harris may become the Democrats’ new nominee. In announcing his plans, Biden offered his “full support and endorsement…

What Kamala Harris has said about AI, tech regulation, and more

U.S. President Joe Biden has announced he no longer plans to seek reelection, a decision that follows weeks of growing pressure from some Democratic Party supporters, including high-profile tech investors…

Joe Biden drops out of presidential race

Google is expected to announce four Pixel devices: the Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL and Pixel 9 Pro Premium, running Android 15.

Made by Google 2024: Pixel 9, Gemini, a new foldable and other things to expect from the event

WazirX, one of India’s largest cryptocurrency exchanges, has “temporarily” suspended all trading activities on its platform days after losing about $230 million, nearly half of its reserves, in a security…

WazirX halts trading after $230 million ‘force majeure’ loss

Featured Article

From Yandex’s ashes comes Nebius, a ‘startup’ with plans to be a European AI compute leader

Subject to shareholder approval, Yandex N.V. is adopting the name of one of its few remaining assets, an AI cloud platform called Nebius AI which it birthed last year.

From Yandex’s ashes comes Nebius, a ‘startup’ with plans to be a European AI compute leader

Employees at Bethesda Game Studios — the Microsoft-owned game developer that produces the Elder Scrolls and Fallout franchises — are joining the Communication Workers of America. Quality assurance testers at…

Bethesda Game Studios employees form a ‘wall-to-wall’ union

This week saw one of the most widespread IT disruptions in recent years linked to a faulty software update from popular cybersecurity firm CrowdStrike. Businesses across the world reported IT…

CrowdStrike’s update fail causes global outages and travel chaos

Alphabet, the parent company of Google, is in advanced talks to acquire cybersecurity startup Wiz for $23 billion, the Wall Street Journal reported on Sunday. TechCrunch’s sources heard similar and…

Unpacking how Alphabet’s rumored Wiz acquisition could affect VC

Around 8.5 million devices — less than 1 percent Windows machines globally — were affected by the recent CrowdStrike outage, according to a Microsoft blog post by David Weston, the…

Microsoft says 8.5M Windows devices were affected by CrowdStrike outage

Featured Article

Some Black startup founders feel betrayed by Ben Horowitz’s support for Trump

Trump is an advocate for a number of policies that could be harmful to people of color.

Some Black startup founders feel betrayed by Ben Horowitz’s support for Trump

Featured Article

Strava’s next chapter: New CEO talks AI, inclusivity, and why ‘dark mode’ took so long

TechCrunch sat down with Strava’s new CEO in London for a wide-ranging interview, delving into what the company is prioritizing, and what we can expect in the future as the company embarks on its “next chapter.”

Strava’s next chapter: New CEO talks AI, inclusivity, and why ‘dark mode’ took so long

Featured Article

Lavish parties and moral dilemmas: 4 days with Silicon Valley’s MAGA elite at the RNC

All week at the RNC, I saw an event defined by Silicon Valley. But I also saw the tech elite experience flashes of discordance.

Lavish parties and moral dilemmas: 4 days with Silicon Valley’s MAGA elite at the RNC

Featured Article

Tracking the EV battery factory construction boom across North America

A wave of automakers and battery makers — foreign and domestic — have pledged to produce North American–made batteries before 2030.

Tracking the EV battery factory construction boom across North America

Featured Article

Faulty CrowdStrike update causes major global IT outage, taking out banks, airlines and businesses globally

Security giant CrowdStrike said the outage was not caused by a cyberattack, as businesses anticipate widespread disruption.

Faulty CrowdStrike update causes major global IT outage, taking out banks, airlines and businesses globally

CISA confirmed the CrowdStrike outage was not caused by a cyberattack, but urged caution as malicious hackers exploit the situation.

US cyber agency CISA says malicious hackers are ‘taking advantage’ of CrowdStrike outage

The global outage is a perfect reminder how much of the world relies on technological infrastructure.

These startups are trying to prevent another CrowdStrike-like outage, according to VCs

The CrowdStrike outage that hit early Friday morning and knocked out computers running Microsoft Windows has grounded flights globally. Major U.S. airlines including United Airlines, American Airlines and Delta Air…

CrowdStrike outage: How your plane, train and automobile travel may be affected

Prior to the ban, Trump’s team used his channel to broadcast some of his campaigns. With the ban now lifted, his channel can resume doing so.

Twitch reinstates Trump’s account ahead of the 2024 presidential election

This week, Google is in discussions to pay $23 billion for cloud security startup Wiz, SoftBank acquires Graphcore, and more.

M&A activity heats up with Wiz, Graphcore, etc.

CrowdStrike competes with a number of vendors, including SentinelOne and Palo Alto Networks but also Microsoft, Trellix, Trend Micro and Sophos, in the endpoint security market.

CrowdStrike’s rivals stand to benefit from its update fail debacle

The IT outage may have an unexpected effect on the climate: clearer skies and maybe lower temperatures this evening

CrowdStrike chaos leads to grounded aircraft — and maybe an unusual weather effect

There’s a man in Florida right now who wants to propose to his girlfriend while they’re on a beach vacation. He couldn’t get the engagement ring before he flew down…

The CrowdStrike outage is a plot point in a rom-com 

Here’s everything you need to know so far about the global outages caused by CrowdStrike’s buggy software update.

What we know about CrowdStrike’s update fail that’s causing global outages and travel chaos