[ad_1]
Following a significant data breach, the creator of stalkerware application pcTattletale has announced that the business is effectively shut down.
The announcement of the company’s closure comes shortly after a malicious actor vandalized the firm’s website, disclosing numerous data batches from pcTattletale’s servers. This included customer databases and, alarmingly, some instances of compromised private data.
Used for clandestine monitoring, pcTattletale offered the capability for a user to remotely capture and view screenshots of a victim’s Android or Windows device. Marketed with the intention of supervising workers, pcTattletale conspicuously also promoted the unlawful ability to spy on spouses or partners without consent.
Before ceasing operations, pcTattletale had 138,000 registered users as per information from the data breach notification service Have I Been Pwned.
The hacker responsible for the website defacement claimed they could coerce the pcTattletale servers into relinquishing private keys that controlled access to the company’s Amazon Web Services account. This storage held hundreds of millions of screenshots from infected devices.
At the moment, the official pcTattletale website remains unreachable.
Bryan Fleming, the founder of pcTattletale, expressed to TechCrunch via text that he has been locked out of the company’s AWS account.
Fleming stated, “I eradicated all data to prevent customer exposure due to the breach,” emphasizing that all company assets had been purged from the AWS account.
An in-depth analysis of the leaked data revealed that pcTattletale’s Amazon S3 servers housed in excess of 300 million screenshots from tracked devices extending back for several years. Instances of these screenshots being publicly accessible were independently verified by TechCrunch.
Amazon’s measures against pcTattletale appear decisive, as the Amazon S3 storage which held the device screenshots now displays an “AllAccessDisabled” notice. This suggests Amazon may have restricted all access to the account in question. Fleming declined to comment on AWS’s actions, and AWS representative Grant Milne did not provide specifics regarding the situation.
Despite deleting the company’s data, Fleming did not indicate whether those affected by the breach had been notified. He ceased correspondence with the inquiring parties.
Issues with spyware security are not unprecedented, with such applications often suffering from vulnerabilities that lead to potential data exposure. Regulatory authorities have previously sanctioned stalkerware developers for insufficient security safeguards.
Regarding inquiries on pcTattletale, FTC spokesperson Juliana Gruenwald Henderson remarked that the agency does not disclose details about potential or ongoing investigations.
pcTattletale is not the first to fall to such circumstances; similar breaches have led to the demise of other stalkerware providers. Polish-developed LetMeSpy, for instance, closed in June 2023 after a cyberattack and subsequent data deletion, while surveillance apps PhoneSpector and Highster Mobile shut down following an investigation by the New York state authorities.
[ad_2]
Frequently Asked Questions about the pcTattletale Shutdown
Q: What was pcTattletale used for?
A: pcTattletale was used for remote surveillance, allowing users to secretly capture and view screenshots of a victim’s device. It was marketed for monitoring employees but also for spying on spouses or partners without their consent.
Q: How much data was compromised in the breach?
A: Over 300 million screenshots from victims’ devices were stored on pcTattletale’s Amazon S3 servers. This data was compromised in the breach.
Q: Has pcTattletale notified individuals affected by the breach?
A: The founder of pcTattletale did not indicate whether they have notified individuals whose information was exposed in the data breach.
Q: Why is pcTattletale shutting down?
A: The shuttering of pcTattletale was a direct result of the significant data breach and subsequent actions such as the company’s AWS account being disabled and the founder’s decision to delete the stored data.
Q: Are there legal ramifications for using stalkerware?
A: Yes, using stalkerware to spy on someone without their consent is illegal, and regulatory bodies have been known to take action against stalkerware makers for violating privacy laws and inadequate security measures.










































