Catwatchful stalkerware app spills secrets of 62,000 users – including its own admin

Catwatchful stalkerware app spills secrets of 62,000 users - including its own admins

Another scummy stalkerware app has spilled its guts, revealing the details of its 62,000 users – and data from thousands of victims’ infected devices.

Security researcher Eric Daigle found a vulnerability in the Android spyware app Catwatchful, which allows non-consensual surveillance of others. Users’ email addresses and plaintext passwords have been revealed as a result, alongside detals of compromised devices mostly located in Latin America, dating back as far as 2018.

Irony of ironies… one of those whose personal details have been breached appears to be the administrator of Catwatchful, who TechCrunch names as Omar Soca Charcov.

Sign up to our free newsletter.
Security news, advice, and tips.

Despite the breach, Catwatchful remains operational – as Google hasn’t yet confirmed any violations of its terms of service.

If you have an Android and are worried Catwatchful might secretly be on your phone, you can detect it: just dial 543210 and then press the call button. If Catwatchful is installed, the app should appear on your screen.


Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and hosts the popular "Smashing Security" podcast. Follow him on LinkedIn, Bluesky and Mastodon, or drop him an email.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.