A breach at Spytech, a relatively obscure spyware developer from Minnesota, has exposed confidential data from thousands of devices across the globe.
The hack has revealed the clandestine monitoring operations of Spytech, which has compromised over 10,000 devices since 2013. The affected devices include Android phones, Chromebooks, Macs, and Windows PCs. An informant provided TechCrunch with a trove of files extracted from Spytech’s servers, which included comprehensive activity logs from devices being monitored. Some logs date as recently as early June.
TechCrunch confirmed the legitimacy of these files by examining the detailed activity logs, including those of Spytech’s CEO, Nathan Polencheck, who had installed the spyware on one of his own devices.
Spytech’s Surveillance Uncovered
Spytech’s software, such as Realtime-Spy and SpyAgent, is marketed for parental monitoring but is also promoted for tracking spouses, boasting features to “monitor your spouse’s suspicious activities.”
While it is legal to monitor children or employees with consent, secretly tracking a device without the owner’s approval is illegal. Both the sellers and users of such spyware can face legal consequences.
Stalkerware apps like those from Spytech are usually installed by someone who has physical access to the device, often with knowledge of the device’s passcode. These apps are designed to remain hidden and are challenging to detect and remove.
Once operational, the spyware records keystrokes, screen taps, browsing history, device usage, and, for Android devices, precise location data, sending this information to a dashboard controlled by the person who installed the app.
The compromised data includes logs of all monitored devices, detailing each device’s activity. Windows PCs are the most frequently targeted, followed by Android phones, Macs, and Chromebooks.
The logs were not encrypted, raising additional concerns about Spytech’s data security practices.
TechCrunch’s examination of the location data from the affected Android devices reveals clusters of monitored devices across Europe and the United States, with some devices also located in Africa, Asia, Australia, and the Middle East.
One record from Polencheck’s account includes the exact location of his residence in Red Wing, Minnesota.
Despite the sensitive nature of the data, it lacks sufficient identifying information to inform the affected individuals about the breach.
Spytech’s CEO has not disclosed whether the company will notify its customers, the individuals whose devices were tracked, or relevant U.S. state authorities as required by data breach laws. The Minnesota Attorney General’s office did not respond to requests for comment.
A Worrying Trend in Spyware Security
TechCrunch’s ongoing tracking shows that Spytech is the fourth spyware company to be breached this year alone. In May, pcTattletale, based in Michigan, was hacked, resulting in the defacement of its website and the company’s subsequent closure.
The data from pcTattletale was later included in the breach notification service Have I Been Pwned, which reported 138,000 affected customers.
Spytech has been around since at least 1998 but remained under the radar until 2009 when an Ohio resident was convicted for using Spytech’s spyware to infiltrate a local children’s hospital’s computer systems.
This breach resulted in the collection of sensitive health data and led to the perpetrator’s guilty plea for illegal electronic surveillance.
The Spytech breach highlights the pressing need for enhanced data security and regulatory oversight in the spyware industry to safeguard personal privacy and prevent the misuse of surveillance technologies.



