The consumer spyware services Cocospy and Spyzie suffered breaches that exposed large volumes of customer data and reportedly opened access to highly sensitive information collected from monitored devices. According to breach disclosures added to Have I Been Pwned, the Cocospy incident exposed nearly 1.8 million customer email addresses, while the Spyzie breach exposed about 519,000 email addresses; related spyware service Spyic was also reported as affected.
The compromised data reportedly included not only customer records but also victim information gathered by the spyware platforms, including captured messages, photos, and call logs. Because of the sensitivity of the incident, the exposed email addresses were provided to HIBP but were classified as sensitive, meaning they are not publicly searchable through the service.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Have I Been Pwned added data from the February 2025 Spyic spyware breach, covering nearly 876,000 customer email addresses. HIBP classified the breach as sensitive, citing reports that the incident also exposed highly sensitive victim data such as messages, photos, and call logs.
Following the breaches, datasets containing nearly 1.8 million Cocospy customer email addresses and about 519,000 Spyzie customer email addresses were provided to Have I Been Pwned. HIBP classified the incidents as sensitive, so the exposed records were not made publicly searchable.
In February 2025, the spyware services Cocospy and Spyzie were breached, with reporting indicating the related service Spyic was also affected. The incidents exposed customer email addresses and reportedly enabled unauthorized access to sensitive victim data including messages, photos, and call logs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.