Data Breaches

Sensitive Information Stolen in LetMeSpy Stalkerware Hack

Emails, phone numbers, calls logs, and collected messages stolen in data breach at Android stalkware LetMeSpy.

Emails, phone numbers, calls logs, and collected messages stolen in data breach at Android stalkware LetMeSpy.

Radeal, the Polish developer of Android stalkerware ‘LetMeSpy’, is informing users that their personal information and collected data was stolen as a result of a cyberattack.

A free application, LetMeSpy, just as its name suggests, collects information from the phones it has been installed on, including call logs, text messages, and device location.

The phone monitoring application is marketed as offering parental control and employee monitoring capabilities, but it essentially allows users to spy on others after installing the software on their devices, likely without their knowledge.

In fact, once up and running on a device, LetMeSpy hides its icon from the phone’s home screen, to prevent detection and removal.

The application uploads the collected information to remote servers, where the user who installed it can access it, essentially tracking a person in real time.

In an incident notification posted on the LetMeSpy login page, Radeal is informing users that it fell victim to a cyberattack that resulted in “unauthorized access to the data of website users”.

Advertisement. Scroll to continue reading.

“As a result of the attack, the criminals gained access to e-mail addresses, telephone numbers and the content of messages collected on accounts,” Radeal says.

The application developer suspended all account-related functions of the website, promising to restore them after mitigating the attack. Law enforcement was also informed about the incident.

According to security researcher Maia Arson Crimew, who received a copy of the allegedly stolen data, the attackers got their hands on call logs, messages, user IDs, email addresses, password hashes, geolocation logs, IP addresses, payment logs, and phone information.

The data also shows that LetMeSpy was installed on roughly 10,000 phones, although a large percentage of these devices never sent activity updates.

Crimew also discovered that at least three government workers, a Broussard police officer, and an employee at a rival stalkware company signed up for the application, though they do not appear to have used it.

However, Crimew did notice that a significant number of LetMeSpy users are US college students, likely looking to spy on their partners. The stolen information also includes global configuration data for the site, the researcher notes.

Related: American Airlines, Southwest Airlines Impacted by Data Breach at Third-Party Provider

Related: Intellihartx Informs 490k Patients of GoAnywhere-Related Data Breach

Related: Toyota Discloses New Data Breach Involving Vehicle, Customer Information

Related Content

Data Breaches

Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them.

Data Breaches

Hackers stole personal, medical, and health insurance information from a company’s data center.

Data Breaches

Hackers stole personal information, medical records, and financial information from the organization’s server.

Data Breaches

An extortion group stole personal, financial, and medical information from the hospital’s network.

Data Breaches

The bank holding company was hacked in June, but the investigation into the incident continues.

Data Breaches

The physical security firm says its alarm monitoring and system functionality have not been affected.

Data Breaches

In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment.

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version