26 September 2026 - 4 min read
What Happens When a Phone Monitoring App Gets Hacked

Apps that watch a child's messages, location, and photos so a parent can view them from another screen have to store that data somewhere first. That somewhere is usually a server run by the company that made the app. A February 2026 TechCrunch investigation counted at least 27 of these monitoring companies that have been breached or leaked data since 2017, with eight shutting down entirely after it happened. This is not one bad actor. It is a pattern built into how this whole category of app works.
How often do these apps actually get breached
Regularly enough that it has become its own recurring news story rather than a one-off scandal. TechCrunch's tally names companies including mSpy, Cocospy, Spyic, Spyzie, FlexiSpy, and pcTattletale among more than two dozen with a reported breach or leak on record since 2017. Some of these companies are still operating. Eight are not, having shut down after their breach became public.
What kind of data is sitting on their servers when that happens
Whatever the app was built to capture: text messages, call logs, photos, GPS location history, browser history, and in some cases audio recordings or live screenshots pulled straight off the monitored phone. When one of these companies gets breached, that is what ends up exposed, not some abstract account record, the actual private content the app collected.
An app that has nothing to send has nothing that can leak.
Get it on Google Play->Whose data is it, the parent's or the child's
Both, and that is exactly the problem. TechCrunch's reporting describes two groups exposed in these breaches: the person who installed the app, whose payment and account details get caught up in it, and the person being monitored, whose actual messages, photos, and location were sitting on that server the whole time. If a parent installs one of these apps to watch over a child, a breach exposes the child's private information, not just the parent's.
Why does this happen so often to this specific category of app
Because the entire product only works by moving a child's private activity off their phone and onto a server somewhere else, usually so a parent can check it later from a different device. That server is a target the moment it exists, and it stays a target for as long as the company keeps operating. The risk is not a bug some of these companies happened to have. It is a direct consequence of the model.
What is the alternative to sending your child's data anywhere at all
An app that never collects the data in the first place has nothing sitting on a server for anyone to breach. CrenelView works entirely on the phone it is installed on, has no account or sign-in, and has no INTERNET permission at all, which is checkable in the phone's own permissions list. It cannot send a message log, a photo, or a location anywhere, not because of a policy promise, but because there is no channel for it to do that through.
Before installing anything that watches over your child, it is worth asking one plain question: where does the information go once it leaves the phone. If the honest answer is "to a server," ask what happens to that server when, not if, it eventually gets breached.
Nothing to collect means nothing to expose. See how CrenelView works entirely on your phone.
Get it on Google Play->