[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1cizvr93q3abb":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":23,"affectedCountUnit":24,"hasEnglishDescription":4,"severity":25,"dataClasses":26,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":4,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda488252c1","mSpy2024","mSpy (2024) Data Breach","mspy-2024","mspy.com","2024-06-09T00:00:00.000Z","2024-07-11T19:29:21.000Z","2024-07-12T23:43:02.000Z","2026-07-18T23:54:39.544Z","Sensitive spyware support data breach","https:\u002F\u002Ftechcrunch.com\u002F2024\u002F07\u002F11\u002Fmspy-spyware-millions-customers-data-breach\u002F",[16,18,19,20],"https:\u002F\u002Fwww.securityweek.com\u002Fdata-of-millions-of-mspy-customers-leaked-online\u002F","https:\u002F\u002Fwww.malwarebytes.com\u002Fblog\u002Fnews\u002F2024\u002F07\u002Fdangerous-monitoring-tool-mspy-suffers-data-breach-exposes-customer-details","https:\u002F\u002Fwww.mspy.com\u002F",2394179,"known",null,"unknown","Critical",[27,28,29,30],"Email addresses","IP addresses","Names","Photos","\u003Cp>The mSpy 2024 data breach is a sensitive data security incident that emerged with the online publication in June 2024 of support records and attached files associated with the phone monitoring service. The verified scope is 2,394,179 unique email addresses. The canonical data classes are email addresses, IP addresses, names, and photos. In the context of the incident, there are support requests, user correspondences asking for installation assistance, and numerous attached files; however, since the support record field is not maintained as a separate class in the list of verified data classes, it is preserved in this record in the context of tags and descriptions. This incident is independent of the separate mSpy breach dating back to 2015.The main risk in the 2024 record is that customer support content, photos, and personal communication details related to the use of monitoring software are included in the same data set. Such records may pose risks of privacy, blackmail, tracking, and social pressure for both the people who purchase the service and the owners of the target devices. Therefore, the outcome should be kept in a sensitive class and guide the user not only in terms of account security but also in terms of personal safety and device control.\u003C\u002Fp>\n\u003Ch2>Types of Leaked Data and Their Risks\u003C\u002Fh2>\n\u003Cp>In this record, the verified data classes are email addresses, IP addresses, names, and photos. When an email address and a name are combined, it is possible to associate the person with the monitoring service. The IP address provides signals about the approximate connection location, network provider, and session context. Photos increase the sensitivity of the incident, as support teams are more likely to contain images related to identity, payment, screenshots, private images, or the device screen, which poses higher risk. Support requests may indicate the user's intention to install monitoring software on the target device, resolve access issues, or use tracking functions. Even if these contents do not directly include account passwords, they can associate the person with a very sensitive context.Attackers can use this data in extortion, fake technical support, legal threats, fake payment requests, or targeted social engineering messages. While there is a reputational risk for the person who purchased the service, there may be the possibility of non-consensual tracking for the owner of the target device. Therefore, the risk assessment should not be limited to email security alone; the context of photos and support correspondence should also be considered.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified incident date is June 9, 2024, the date it was recorded is July 11, 2024, and the number of verified accounts is 2,394,179. The last verification date should be recorded as July 12, 2024. The data classes are email addresses, IP addresses, names, and photos. Although support requests play an important role in describing the incident, they do not appear as a separate field among canonical data classes; therefore, the dataClasses list should be limited to these four verified fields. News sources report that the data volume is at the level of hundreds of gigabytes and consists of user data, support requests, and numerous attached files. This record does not mean that payment card numbers, passwords, or official identification documents leaked as a verified class for all users.Some additional files may contain more sensitive visuals; however, the public data field generalization should not go beyond the proven classes. Since there are different signals regarding country information at the brand, operator, and parent company levels, the country field should be kept as Unknown instead of claiming a definite center. The record should be kept separate from the 2015 device usage tracking leak; if this page appears in a user search, the assessment should proceed based on the 2024 support and additional file incident.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The group at the highest risk consists of individuals who opened a support request with the mSpy service or used an email address associated with the service during the 2024 period. These individuals can be directly linked to the monitoring service due to support correspondence, names, IP addresses, and photo attachments. The second risk group comprises individuals who may be the owners of the target device. If a user has requested help regarding access, installation, or monitoring functions for someone else's device in a support request, the dataset may also affect that target person's privacy. The third risk group consists of individuals who have images, payment screens, identification images, private photos, or device screens belonging to them in additional files. Such content can be turned into blackmail and harassment material for attackers.The fourth risk group consists of individuals using corporate devices, family accounts, or shared devices; support request content may indirectly reveal business correspondence, location, contact lists, or private relationship context. In this record, the email match only points to the service account holder; however, due to the nature of the incident, the target device owner may also have been affected. This distinction should be kept clear when communicating to the user.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users matching this record should first secure their email account. Unrecognized sessions should be closed, recovery addresses and phone numbers should be checked, a strong and unique password should be chosen, and two-factor authentication should be enabled. If the same email address is used for other sensitive services, session history on those accounts should also be reviewed. Due to additional files, photos, or correspondence content that may be related to an mSpy support request, users should be cautious of fake support messages, legal threats, blackmail emails, and payment requests. Links in the messages should not be opened, money should not be sent, and threatening content should be kept as evidence.Individuals who suspect there may be monitoring software on their device should check administrator permissions, accessibility rights, unknown profiles and certificates, location sharing settings, backup accounts, and unusual data usage. If there is a personal security risk, device cleaning should not be done hastily, but planned with a trusted expert or local support channel. Immediately removing the tracking application may alert the other party in some cases, so it may be more appropriate to first establish secure communication and a support network.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident shows that monitoring software support records should also be considered among the most sensitive categories of data. In the long term, users should use a separate email address for services with high privacy risks, avoid sharing unnecessary support attachments, and carefully check the content before sending photos or screenshots. The email account should be protected with a strong password and two-factor authentication, device permissions should be regularly reviewed, and location sharing should be kept limited. If the use of tracking tools arises on work, family, or shared devices, the legal limit, explicit consent, and data retention period should be clear. Secret tracking should not be regarded as a normal security measure.From the perspective of service providers, support requests and attached files should be treated as highly sensitive data; access logs should be regularly reviewed, unnecessary file retention should be reduced, the principle of least privilege should be applied in support panels, and incident reporting should not be delayed. On the user side, permanent defense involves closing old support accounts, reducing the history of attached files, regularly checking device security, and choosing trusted channels for sensitive communications. This approach reduces both the risk of account takeover and the risk of blackmail and harassment.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Seeing a match with the mSpy 2024 record indicates that the relevant email address is found among the records associated with the 2024 support and additional file incident. When the user sees this result, they should first determine whether they have opened an mSpy account or support request. If such a request exists, the added files, correspondence content, and associated devices should be reviewed. Email security should be checked, and if old passwords are valid for other accounts, they should be changed. Caution should be exercised against extortion and fake legal notification messages due to photo or support correspondence leaks. Persons suspected of device tracking should look for unknown administrator permissions, accessibility authorizations, location sharing, backup accounts, and unusual data usage on phones, tablets, or computers.If there is a personal safety risk, this check should not be conducted alone; it should be carried out with a trusted technical expert, lawyer, or support line. Since the outcome is sensitive, the social and legal implications should be considered before sharing it with others. The goal is not just to clean up the old account, but to simultaneously reduce email security, device integrity, personal safety, and sensitive file risks.\u003C\u002Fp>","","mSpy (2024) Data Breach (2.4 Million Reported Records)","mSpy (2024) Data Breach. 2.4 Million reported records were reported. Reported data: Email addresses, IP addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmspy_com.webp",false,{"name":38,"sector":39,"country":40,"website":10,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":23},"mSpy","Monitoring software \u002F spyware","Unknown"]