Security Flaw Exposes Thousands of Catwatchful Spyware Victims and Exposes Data Breach
A security breach in the Catwatchful spyware, a stealthy Android surveillance tool, has exposed the private data of thousands of users, including sensitive information from more than 62,000 customers and 26,000 victims’ phone records. Discovered by security expert Eric Daigle, the vulnerability occurred due to an unauthenticated API, leaking passwords and email addresses of Catwatchful customers. This breach was particularly alarming as the spyware operates undetected, using Google Firebase to collect stolen information like photos, audio, and other personal data. The breach also revealed the identity of the spyware’s creator, Omar Soca Charcov, a developer from Uruguay, though he has yet to comment on the incident. Despite the breach, the spyware remains active, with no concrete indication from Google or the hosting provider to fully shut it down. Users are advised to take steps to remove the app from affected Android devices, though Catwatchful claims that it cannot be uninstalled easily. The spyware was primarily targeting individuals in Latin America and India, with a history going back to 2018.
