Spyware Buyers Targeted as pcTattletale Breach Exposes 123,824 Logins
HEROIC analysts identified a data breach affecting pcTattletale, a spyware service marketed for secretly monitoring phones and computers, discovered on May 25, 2024. The attacker defaced the company's homepage and published tens of gigabytes of internal data, allegedly after pcTattletale ignored an earlier report of the security flaw. In total, 123,824 records were exposed, each containing an email address, a password hash, a first name, and an IP address.
Why the pcTattletale Breach Is Dangerous
This breach cuts two ways. The customers who purchased pcTattletale to monitor someone else's device had their own login credentials and IP addresses exposed, making it easy to trace who was using the service and from where. At the same time, the leaked data reportedly included names of infected devices and captured messages, meaning the people being secretly monitored had their private activity exposed as well. The password hashes were secured with MD5, an outdated method that modern cracking tools can break through quickly, turning those hashes back into usable passwords.
What Was Exposed in the pcTattletale Breach
- Email addresses
- Password hashes (MD5)
- First names
- IP addresses
Why This Matters for Anyone Connected to This Service
Once a password hash is cracked, it can be tried on other accounts that share the same email and password, a technique called credential stuffing. Combined with a real name and IP address, an attacker has enough to attempt account takeover, track someone's approximate location, or use the information in phishing and social engineering attempts. For a service built around covert monitoring, an exposed customer list also carries a real risk of identity theft and personal fallout for anyone whose use of the app becomes public.
How a Database Breach Like This Happens
This incident stemmed from a known security vulnerability in pcTattletale's systems that reportedly went unaddressed after being reported. Attackers who find an unpatched flaw in a website or application can use it to pull entire databases of user records directly from the server, then publish or deface the site to draw attention to the compromise. It is a direct route to stolen data that does not rely on tricking any individual user, only on a weakness in the software itself.
Check If You Are Affected
If you ever created an account with pcTattletale, whether as a customer or someone whose device was monitored, it is worth finding out if your information was part of this leak. HEROIC's free breach scanner checks a database of more than 400 billion leaked records, giving you a fast answer on whether your email address or password needs attention.
Breach Breakdown
123,824 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds