A hacktivist scraped and published ~500,000+ payment records tied to consumer “stalkerware” services operated by the Ukrainian company Struktura, exposing customer email addresses and partial payment details. The leaked transactions include purchases for phone-tracking and monitoring brands such as uMobix, Geofinder, and Peekviewer (formerly Glassagram), and also reference transactions associated with other surveillance apps like Xnspy. The incident highlights ongoing security weaknesses in the commercial surveillance ecosystem, where operators’ poor security practices repeatedly expose sensitive customer—and often victim—data.
Separately, mobile threat research reported a new Android malware family, GhostChat, distributing malicious APKs that impersonate popular chat apps (including WhatsApp) to intercept messages, steal credentials, and exfiltrate contacts and media by injecting code into the app process. While both stories involve mobile-user risk, the GhostChat activity is a distinct malware campaign and not directly related to the stalkerware payment-record leak; the stalkerware reporting also contextualizes the Struktura/uMobix exposure within a broader pattern of dozens of stalkerware vendors being hacked or leaking data since 2017, including multiple high-profile incidents in 2025 affecting victims’ messages, photos, call logs, and location data.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
TechCrunch reviewed the leaked dataset, verified sample records through password-reset flows and unauthenticated invoice lookups, and reported that internal references pointed to Struktura rather than only Ersten Group. Neither the companies nor Struktura CEO Viktoriia Zosim responded to requests for comment.
After obtaining the records, the hacktivist published the dataset on a known hacking forum. The post identified the vendor as Ersten Group, while reporting later found multiple indicators linking the operation to the Ukrainian company Struktura.
A hacktivist using the alias "wikkid" exploited a trivial website bug to scrape more than 500,000 payment records from a stalkerware vendor. The exposed data included customer email addresses, app purchase details, card type information, and the last four digits of payment cards for services including Geofinder, uMobix, Peekviewer, and Xnspy.
In 2022, Xnspy was associated with a major data exposure that revealed private data from tens of thousands of Android and iPhone devices. This earlier incident is referenced because records tied to Xnspy also appeared in the newly leaked payment dataset.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcedatabreaches.net
Open sourcetechcrunch.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.