A teen phone spying app has leaked thousands of user passwords (2024)

Table of Contents
Security See also Got a tip?
A teen phone spying app has leaked thousands of user passwords (1)

At least one server used by an app for parents to monitor their teenagers' phone activity has leaked tens of thousands of accounts of both parents and children.

Security

The mobile app, TeenSafe, bills itself as a "secure" monitoring app for iOS and Android, which lets parents view their child's text messages and location, monitor who they're calling and when, access their web browsing history, and find out which apps they have installed.

Although teen monitoring apps are controversial and privacy-invasive, the company says it doesn't require parents to obtain the consent of their children.

But the Los Angeles, Calif.-based company left its servers, hosted on Amazon's cloud, unprotected and accessible by anyone without a password.

Robert Wiggins, a UK-based security researcher who searches for public and exposed data, found two leaky servers.

Both of the servers was pulled offline after ZDNet alerted the company, including another that contains what appears to be only test data.

"We have taken action to close one of our servers to the public and begun alerting customers that could potentially be impacted," said a TeenSafe spokesperson told ZDNet on Sunday.

The database stores the parent's email address associated with TeenSafe, as well as their corresponding child's Apple ID email address. It also includes the child's device name -- which is often just their name -- and their device's unique identifier. The data contains the plaintext passwords for the child's Apple ID. Because the app requires that two-factor authentication is turned off, a malicious actor viewing this data only needs to use the credentials to break into the child's account to access their personal content data.

None of the records contained content data, such as photos or messages, or the locations of either parents or children.

The data also contained error messages associated with a failed account action, such as if a parent looking up a child's real-time location didn't complete.

Shortly before the server went offline, there were at least 10,200 records from the past three months containing customers data -- but some are duplicates.

One of the servers appeared to store test data, but it's not known if there are other exposed servers with additional data.

TeenSafe claims to have over a million parents using the service.

A teen phone spying app has leaked thousands of user passwords (2)
A teen phone spying app has leaked thousands of user passwords (3)

We began verifying some of the data by reaching out to those whose email addresses were named in the leaking data.

We contacted a dozen people over iMessage, one by one, to confirm their passwords (you can learn more about how we verify data breaches here). Not everyone responded. But several people -- parents of children who use the app -- confirmed their email addresses and passwords, or that it had been recently changed within the past month or so.

The parents also confirmed their child's email address, used as their Apple ID.

While we did not contact children for fear of causing alarm, some of the email addresses were associated with their high schools.

It's not clear why the data, let alone passwords for teens' Apple IDs, was stored in plaintext.

The company claims on its website that it's "secure" and uses encryption to scramble the data, such as in the event of a data breach.

TeenSafe said it was continuing to assess the situation and "will provide additional information" as it becomes available.

ZDNET INVESTIGATIONS

  • Researchers say a breathalyzer has flaws, casting doubt on countless convictions
  • Lawsuits threaten infosec research — just when we need it most
  • NSA's Ragtime program targets Americans, leaked files show
  • Leaked TSA documents reveal New York airport's wave of security lapses
  • US government pushed tech firms to hand over source code
  • Millions of Verizon customer records exposed in security lapse
  • Meet the shadowy tech brokers that deliver your data to the NSA
  • Inside the global terror watchlist that secretly shadows millions
  • 198 million Americans hit by 'largest ever' voter records leak
  • Britain has passed the 'most extreme surveillance law ever passed in a democracy'
  • Microsoft says 'no known ransomware' runs on Windows 10 S — so we tried to hack it
  • Leaked document reveals UK plans for wider internet surveillance
A teen phone spying app has leaked thousands of user passwords (2024)
Top Articles
10 Funny Numbers to Call to for Pranks or When You’re Bored
FEELING LUCKY? Here Are The Best Lottery Ticket Pranks!
Unity Stuck Reload Script Assemblies
Nwi Police Blotter
What Auto Parts Stores Are Open
Craigslist Dog Sitter
Bbc 5Live Schedule
Grand Park Baseball Tournaments
Infinite Campus Parent Portal Hall County
Shariraye Update
R/Altfeet
Programmieren (kinder)leicht gemacht – mit Scratch! - fobizz
Sarpian Cat
Nioh 2: Divine Gear [Hands-on Experience]
Jenn Pellegrino Photos
Abortion Bans Have Delayed Emergency Medical Care. In Georgia, Experts Say This Mother’s Death Was Preventable.
ABCproxy | World-Leading Provider of Residential IP Proxies
Bible Gateway passage: Revelation 3 - New Living Translation
Grimes County Busted Newspaper
Aliciabibs
Getmnapp
Relaxed Sneak Animations
R/Airforcerecruits
Craigslist Brandon Vt
Mississippi Craigslist
Newsday Brains Only
Bus Dublin : guide complet, tarifs et infos pratiques en 2024 !
Beth Moore 2023
Craigslist Com Humboldt
Indiana Immediate Care.webpay.md
Cruise Ships Archives
Iban's staff
Missouri State Highway Patrol Will Utilize Acadis to Improve Curriculum and Testing Management
About Us | SEIL
Polk County Released Inmates
Wildfangs Springfield
2008 Chevrolet Corvette for sale - Houston, TX - craigslist
Keeper Of The Lost Cities Series - Shannon Messenger
The Syracuse Journal-Democrat from Syracuse, Nebraska
Hebrew Bible: Torah, Prophets and Writings | My Jewish Learning
Arnesons Webcam
Gon Deer Forum
Darkglass Electronics The Exponent 500 Test
Petfinder Quiz
Rise Meadville Reviews
Menu Forest Lake – The Grillium Restaurant
The Quiet Girl Showtimes Near Landmark Plaza Frontenac
Blippi Park Carlsbad
Bama Rush Is Back! Here Are the 15 Most Outrageous Sorority Houses on the Row
Dcuo Wiki
Www.card-Data.com/Comerica Prepaid Balance
Latest Posts
Article information

Author: Lakeisha Bayer VM

Last Updated:

Views: 6122

Rating: 4.9 / 5 (49 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Lakeisha Bayer VM

Birthday: 1997-10-17

Address: Suite 835 34136 Adrian Mountains, Floydton, UT 81036

Phone: +3571527672278

Job: Manufacturing Agent

Hobby: Skimboarding, Photography, Roller skating, Knife making, Paintball, Embroidery, Gunsmithing

Introduction: My name is Lakeisha Bayer VM, I am a brainy, kind, enchanting, healthy, lovely, clean, witty person who loves writing and wants to share my knowledge and understanding with you.