Stalkerware App “TheTruthSpy” Hacked Again, 50,000 Device Data Stolen
ID: f85c652d-d56c-5eac-bc17-c5822e7996a4
STIX ID: report--f85c652d-d56c-5eac-bc17-c5822e7996a4
Feed Name: HackRead
Threat Score
The report details that TheTruthSpy, a stalkerware app, suffered repeated breaches due to an unpatched IDOR vulnerability allowing unauthenticated enumeration and data exfiltration from roughly 50,000–140,000 Android devices (including IMEI, call logs, messages, photos, locations). Hackers and security researchers disclosed the exposure in early 2024, highlighting ongoing vendor negligence and a significant privacy risk to victims across multiple countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
