Apps & Consumer
Struktura stalkerware data exposed in hacktivist breach
A hacktivist scraped over 500,000 payment records from a stalkerware vendor, exposing customer data linked to apps used to spy on spouses and domestic partners.
A hacktivist operating under the moniker “wikkid” has scraped more than half-a-million payment records from a provider of consumer-grade phone surveillance apps, commonly known as “stalkerware.” The breach exposed over 500,000 customers’ payment records, revealing the email addresses and partial payment information of individuals who paid to spy on others. The hacktivist, who subsequently published the scraped data on a known hacking forum, told TechCrunch they “have fun targeting apps that are used to spy on people.”
The leaked dataset contains about 536,000 lines of customer email addresses, alongside transaction records for several monitoring and tracking services. These transactions include payments for phone-tracking services like Geofinder and uMobix, as well as Peekviewer, which purports to allow access to private Instagram accounts. These services are among several monitoring and tracking apps provided by the same vendor, a Ukrainian company called Struktura. The customer data also includes transaction records from Xnspy, a known phone surveillance app that spilled private data from unsuspecting people’s devices in 2022. While the dataset exposes email addresses and partial payment details, the customer records did not include the dates of the payments.
The hacking forum listing identifies the surveillance vendor as Ersten Group, which presents itself as a U.K.-presenting software development startup. However, several email addresses in the dataset used for testing and customer support instead reference Struktura, which has an identical website to Ersten Group. The earliest record in the dataset contained the email address for Struktura’s chief executive, Viktoriia Zosim, for a transaction of $1. Representatives for Ersten Group did not respond to requests for comment, and Struktura’s Zosim did not return a request for comment.
Apps like uMobix and Xnspy have explicitly marketed their services for people to spy on their spouses and domestic partners, which is illegal. Once installed on a target’s phone, these apps upload private data—including call records, text messages, photos, browsing history, and precise location data—to the person who planted the software. This incident is the latest example of a surveillance vendor exposing customer information due to security flaws, highlighting the “shoddy cybersecurity” that is common among stalkerware operators.
Why it matters
This incident highlights the inherent security risks of the stalkerware industry, where vendors facilitating illegal surveillance often fail to protect the very data they collect from their own customers. As security flaws continue to expose sensitive user and customer data, the breach underscores the systemic vulnerabilities of consumer-grade surveillance operations.