A company selling consumer stalkerware suffered a breach exposing not only its customer records but also the intimate data covertly harvested from tens of thousands of surveillance victims.

The leaked dataset includes call logs, location histories, messages and photos siphoned from monitored phones, alongside the identities of the customers who installed the software — often on partners and family members without consent.

Security researchers who verified the data noted the vendor stored victim data unencrypted and had ignored previous vulnerability reports. Data protection authorities in several countries have opened investigations.

Advocacy groups reiterated calls to prosecute stalkerware vendors, noting the industry profits from tools whose primary use case is unlawful surveillance.