Leaked data from TheTruthSpy stalkerware network reveals its Android apps tracked the calls, locations, and other information of hundreds of thousands of people
Context & Ripple Effects
TechCrunch's probe into TheTruthSpy follows its earlier work giving readers a tool to check whether an Android device was compromised by one of several spyware apps — this leak is the data layer behind that exposure, showing the scale of what those apps collected. It also fits a longer pattern: researchers reported call metadata and texts stolen from Indian spyware vendor SpyHuman back in 2018 amid a wave of vigilante hacking of these firms.
The leak lands on a market already under siege — Poland-based LetMeSpy was hacked in June 2023, and Brazil-focused WebDetetive was breached weeks later with victims' stolen data deleted. Stalkerware vendors are now being breached faster than they can operate.
First-order effects
- Hundreds of thousands of people whose calls, locations, and messages were harvested by TheTruthSpy's Android apps now have their most sensitive data exposed to whoever holds the leak — including the abusers the software serves.
Second-order effects
- Vigilante hackers have a proven playbook against this category — SpyHuman in 2018, then LetMeSpy and WebDetetive in 2023 — so every remaining stalkerware vendor becomes a target, and buyers face real risk that intercepted data surfaces publicly.
Third-order effects
- If the breach-and-exposure cycle continues, consumer spyware becomes structurally untenable: distribution channels like app stores face pressure to police it, and the category consolidates or goes further underground as each vendor's security failure becomes public evidence.
The trend: Consumer stalkerware is entering a self-destruct phase where the vendors' own security failures, not regulators, are exposing both them and their customers.