{"id":182900,"date":"2025-07-25T16:25:47","date_gmt":"2025-07-25T16:25:47","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/07\/25\/google-took-a-month-to-shut-down-catwatchful-a-phone-spyware-operation-hosted-on-its-servers-techcrunch\/"},"modified":"2025-07-25T16:25:47","modified_gmt":"2025-07-25T16:25:47","slug":"google-took-a-month-to-shut-down-catwatchful-a-phone-spyware-operation-hosted-on-its-servers-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/07\/25\/google-took-a-month-to-shut-down-catwatchful-a-phone-spyware-operation-hosted-on-its-servers-techcrunch\/","title":{"rendered":"Google took a month to shut down Catwatchful, a phone spyware operation hosted on its servers | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Google has suspended the account of phone surveillance operator Catwatchful, which was using the tech giant\u2019s servers to host and operate the monitoring software.<\/p>\n<p class=\"wp-block-paragraph\">Google\u2019s move to shut down the spyware operation comes a month after <a href=\"https:\/\/techcrunch.com\/2025\/07\/02\/data-breach-reveals-catwatchful-stalkerware-spying-on-thousands-android-phones\/\" target=\"_blank\" rel=\"noopener\">TechCrunch alerted the technology giant<\/a> the operator was hosting the operation on Firebase, one of Google\u2019s developer platforms. Catwatchful relied on Firebase to host and store vast amounts of data stolen from thousands of phones compromised by its spyware.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe\u2019ve investigated these reported Firebase operations and suspended them for violating our terms of service,\u201d Google spokesperson Ed Fernandez told TechCrunch in an email this week.<\/p>\n<p class=\"wp-block-paragraph\">When asked by TechCrunch, Google would not say why it took a month to investigate and suspend the operation\u2019s Firebase account. The company\u2019s <a href=\"https:\/\/cloud.google.com\/terms\/aup?hl=en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">own terms of use<\/a> broadly prohibit its customers from hosting malicious software or spyware operations on its platforms. As a for-profit company, Google has a commercial interest in retaining customers who pay for its services.<\/p>\n<p class=\"wp-block-paragraph\">As of Friday, Catwatchful is no longer functioning nor does it appear to transmit or receive data, according to a network traffic analysis of the spyware carried out by TechCrunch.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Catwatchful was an Android-specific spyware that presented itself as a child-monitoring app \u201cundetectable\u201d to the user. Much like other phone spyware apps, Catwatchful required its customers to physically install it on a person\u2019s phone, which usually requires prior knowledge of their passcode. These monitoring apps are often called<a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#stalkerware\" target=\"_blank\" rel=\"noopener\"> \u201cstalkerware\u201d (or spouseware)<\/a> for their propensity to be used for non-consensual surveillance of spouses and romantic partners, which is illegal.<\/p>\n<p class=\"wp-block-paragraph\">Once installed, the app was designed to stay hidden from the victim\u2019s home screen, and upload the victim\u2019s private messages, photos, location data, and more to a web dashboard viewable by the person who planted the app.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">TechCrunch first learned of Catwatchful in mid-June after <a href=\"https:\/\/ericdaigle.ca\/posts\/taking-over-60k-spyware-user-accounts\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">security researcher Eric Daigle identified a security bug<\/a> that was exposing the spyware operation\u2019s back-end database.<\/p>\n<p class=\"wp-block-paragraph\">The bug allowed unauthenticated access to the database, meaning no passwords or credentials were needed to see the data inside. The database contained more than 62,000 Catwatchful customer email addresses and plaintext passwords, as well as records on 26,000 victim devices compromised by the spyware.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The data also exposed the administrator behind the operation, a Uruguay-based developer called Omar Soca Charcov. TechCrunch contacted Charcov to ask if he was aware of the security lapse, or if he planned to notify affected individuals about the breach. Charcov did not respond.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">With no clear indication that Charcov would disclose the breach, TechCrunch provided a copy of the Catwatchful database to <a href=\"https:\/\/haveibeenpwned.com\/Breach\/Catwatchful\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">data breach notification service Have I Been Pwned<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Catwatchful is the latest in a long list of surveillance operations that have experienced a data breach in recent years, in large part due to shoddy coding and poor cybersecurity practices. Catwatchful is by TechCrunch\u2019s count <a href=\"https:\/\/techcrunch.com\/2025\/02\/20\/hacked-leaked-exposed-why-you-should-stop-using-stalkerware-apps\/\" target=\"_blank\" rel=\"noopener\">the fifth spyware operation this year<\/a> to have spilled users\u2019 data, and the most recent entry in a list of more than two-dozen known spyware operations since 2017 that have exposed their banks of data.<\/p>\n<p class=\"wp-block-paragraph\">As we noted <a href=\"https:\/\/techcrunch.com\/2025\/07\/02\/data-breach-reveals-catwatchful-stalkerware-spying-on-thousands-android-phones\/\" target=\"_blank\" rel=\"noopener\">in our previous story<\/a>: Android users can identify if the Catwatchful spyware is installed, even if the app is hidden, by dialing <strong>543210<\/strong> into your Android phone app\u2019s keypad and pressing the call button.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Remember to have<a href=\"https:\/\/stopstalkerware.org\/resources\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> a safety plan in place<\/a> before removing spyware from your phone.<\/p>\n<p class=\"has-text-align-center wp-block-paragraph\">\u2014<\/p>\n<p class=\"wp-block-paragraph\"><em>If you or someone you know needs help, the National Domestic Violence Hotline (1-800-799-7233) provides 24\/7 free, confidential support to victims of domestic abuse and violence. If you are in an emergency situation, call 911. The<\/em><a href=\"https:\/\/stopstalkerware.org\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><em> Coalition Against Stalkerware<\/em><\/a><em> has resources if you think your phone has been compromised by spyware.<\/em><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2025\/07\/25\/google-took-a-month-to-shut-down-catwatchful-a-phone-spyware-operation-hosted-on-its-servers\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google has suspended the account of phone surveillance operator Catwatchful, which was using the tech giant\u2019s servers to host and operate the monitoring software. Google\u2019s move to shut down the spyware operation comes a month after TechCrunch alerted the technology giant the operator was hosting the operation on Firebase, one of Google\u2019s developer platforms. Catwatchful [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":182901,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-182900","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/182900","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=182900"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/182900\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/182901"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=182900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=182900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=182900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}