[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f33qpisz114twj":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":24,"seoTitle":15,"seoTitleEn":25,"seoDescription":15,"seoDescriptionEn":26,"logoUrl":27,"isVerified":4,"isSensitive":4,"isSpamList":28,"isMalware":28,"company":29},"68e3266eda11adda4882514f","cocospy","Cocospy Data Breach","cocospy.com","2025-02-14T00:00:00.000Z","2025-02-20T22:36:16.000Z","2026-07-02T04:54:04.591Z","2026-07-18T23:47:44.705Z","Third party breach","",[],1798059,"known",null,"unknown","Critical",[23],"Email addresses","\u003Cp>Cocospy is a spyware service known for its phone tracking and stalkerware features. In February 2025, in an incident related to Cocospy and associated Spyic services, approximately 1.8 million customer email addresses were exposed on Cocospy's side.\u003C\u002Fp>\u003Cp>The canonical data class of this record is only the email address. Nevertheless, the nature of the service carries a high degree of sensitivity; because public news reports have included claims of unauthorized access to content such as messages, photos, call logs, and location obtained from target devices in the context of the same event. The LeakData record, however, should be limited to the email field.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The data categories monitored in Cocospy records should be treated as email addresses. Email addresses can be used for targeted phishing, password reset scenarios, and account matching across different services.\u003C\u002Fp>\u003Cp>The association of an email address with a spyware service alone can pose a serious privacy risk. The user may receive fake account closure, payment, legal warning, or security notification. Additionally, the risks to device security and personal safety for victims of monitoring services should also be considered separately.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is related to the domain cocospy.com and the February 2025 incident. The scope is limited to email addresses. Message, photo, call log, or location contents should not be added as a data class for this record; however, due to the context of the incident, users should be warned about a high privacy risk.\u003C\u002Fp>\u003Cp>Fields that are not present in this record should not be described as if they have leaked. Fields such as full card number, account password, official ID, private message, device content, or health information should only be included in the risk assessment if they are explicitly present in the record. The text is based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Individuals who have opened a Cocospy customer account, users who use the same email address on other services, and people whose association with spyware services could pose personal, legal, or security risks are at primary risk. Additionally, individuals whose devices may have been monitored should also act cautiously in terms of security.\u003C\u002Fp>\u003Cp>Users who use the same email address across different services, repeat their old passwords, and share their phone and address information across many shopping or community accounts are at higher risk. The connection between a pseudonym and real identity in corporate or community accounts can create additional social engineering risks.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users who have a positive match should check email security, examine suspicious logins on the same email, and be cautious of payment, shutdown, or legal warning messages in the context of spyware. People who suspect they may have been monitored should have their devices examined with reliable support.\u003C\u002Fp>\u003Cp>Users in the positive match field should update their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check recent sessions. Caution should be exercised against unexpected calls, deliveries, returns, support, and verification messages on records containing phone numbers, addresses, payment information, or sensitive community information.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>In the spyware and stalkerware ecosystem, user and victim data can be repeatedly put at risk. Users should use unique emails and strong authentication for critical accounts; they should regularly review device security, app permissions, and family digital security issues.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is present in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that there is a match in the Cocospy customer email records. This result only means email as a verified data field; however, it requires high caution due to the privacy context of the service.\u003C\u002Fp>","Cocospy Data Breach (1.8 Million Reported Records)","Cocospy Data Breach. 1.8 Million reported records were reported. Reported data: Email addresses. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fcocospy_com.webp",false,{"name":30,"sector":31,"country":32,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Cocospy","Spyware \u002F Stalkerware","Global"]