The WtSpy Breach Means Someone Could Be Logging Into Your Accounts
HEROIC analysts found a database dump attributed to WtSpy, a WhatsApp tracking service that was popular in the United States, actively being traded on dark web forums. The breach, which occured in June 2016, exposed nearly 189,000 user records. The data is partcularly sensitive because WtSpy was a surveillance-style service, meaning users who signed up with their real email addresses may not have wanted that association known. All passwords in the dump were stored in plaintext.
Your Username, Email, and Plaintext Password Are All in This Dump
The WtSpy breach contains three pieces of data that work together against you: your email address, your chosen username, and your actual password in plaintext. With this combination, an attacker knows not only how to log into other services as you, but also what username you prefer to use online. This makes it easier to find and target your other accounts. Anyone who recieved this database has everything needed to impersonate you or break into accounts where you used the same credentials.
What Was Exposed in the WtSpy Breach
- Email Address
- Username
- Passwords (plaintext)
The WtSpy Breach Means Someone Could Already Be Logging Into Your Accounts
With nearly 189,000 credential sets in circulation since 2016, attackers have had years to run these combinations through credential stuffing tools. If your email and password from WtSpy match what you use on any other service, that account is at risk right now. Identity theft, financial fraud, and account takeover are all likely outcomes for victims who have not changed their passwords. The sensitive nature of a surveillance service means many users may not have wanted their registration known, adding a layer of personal risk beyond just account security.
How a Database Breach Works
A database breach happens when an attacker finds a way into the back-end of a website or app and copies its user records. Common entry points include software vulnerabilities, weak admin passwords, and misconfigured databases that are accidentally exposed to the public internet. Once the attacker has the data, it is typically sold or posted on dark web marketplaces where it stays in circulation for years.
Check If Your Data Was Exposed
Use HEROIC's free breach scanner to check your email against more than 400 billion exposed records. If your credentials appeared in the WtSpy breach or any other known leak, you will find out immediately so you can change your passwords and secure your accounts before attackers get there first.
Breach Breakdown
188,868 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds