TheTruthSpy: What It Is, Why It Keeps Getting Hacked, and How to Check If It’s on Your Phone

0
TheTruthSpy monitoring app and smartphone security warning showing how to check if TheTruthSpy is on your phone

If you’ve searched for “TheTruthSpy,” you’re probably in one of two situations: someone told you about it as a phone-monitoring app, or you suspect it’s already been installed on your device without your knowledge. Either way, the facts here matter more than the marketing copy.

TheTruthSpy is not a typical parental-control app. Security researchers classify it as stalkerware, software designed to run invisibly on someone’s phone and quietly siphon off their texts, calls, location, and more. It’s also been breached repeatedly, exposing the very data it collected, including the personal information of the people it was secretly spying on.

What TheTruthSpy Actually Does

The app is sold by 1Byte Software, a Vietnam-based developer, and marketed as a way to monitor children’s or employees’ phones. But its own promotional material advertises a “stealth mode” that <cite index=”1-1″>makes it “completely invisible to users on phones/tablets where it’s installed.” </cite> That single feature is the line between legitimate monitoring and stalkerware: legitimate tools disclose themselves to the phone’s user; stalkerware hides.

Once installed, apps like this typically upload a phone’s messages, call logs, photos, browsing history, and precise location to a remote server the installer can view. Installation requires physical access to the target device, which is why these apps are most commonly associated with domestic partners, ex-partners, or family members rather than strangers.

A Long History of Data Breaches

TheTruthSpy’s core problem isn’t just what it does; it’s how badly it protects the data it collects. The timeline is unusually bad even by stalkerware standards:

  • 2018: A hacker gained access to the company’s servers.
  • 2019: The app exposed photos taken from infected phones, including images of children, publicly online.
  • 2022: Researchers and journalists identified an Insecure Direct Object Reference flaw, tracked as CVE-2022-0732, in TheTruthSpy’s backend. <cite index=”3-1″>⁣ That leak held roughly 360,000 unique device identifiers and around 337,000 user accounts, with records spanning early 2019 through April 2022. </cite> TechCrunch’s investigation went further, using the leaked location data to map hundreds of thousands of victims across multiple countries.
  • 2024: The same unpatched vulnerability was exploited again, this time exposing data from <cite index=”3-1″>roughly 50,000 more devices, in a disclosure dated February 2024</cite>.
  • 2025: Malwarebytes reported yet another flaw affecting the app’s infrastructure, meaning the underlying security issues still hadn’t been resolved years after they were first flagged.

One security researcher who has tracked the company’s history put it bluntly to Hackread: given the repeated breaches, the responsible move at this point would be for the operation to shut down entirely rather than keep collecting data it can’t protect.

Regulators Are Watching This Category

Stalkerware as an industry has drawn direct action from U.S. regulators, even if TheTruthSpy itself hasn’t been named in an enforcement order. In 2021, the Federal Trade Commission banned the stalkerware app SpyFone, its parent company Support King, and CEO Scott Zuckerman from the surveillance business entirely and required them to delete the data they’d collected and notify the people they’d spied on. That case set a precedent: the FTC has said it will treat poor security practices and unauthorized data collection by stalkerware vendors as consumer protection violations, not just a privacy footnote.

The legal risk doesn’t stop with the company that builds the software. Simply possessing an app like this isn’t illegal in most places, but using it to intercept someone’s calls, texts, or location without their consent can violate federal wiretapping law and state anti-stalking or surveillance statutes. Installing it on an adult’s phone without their knowledge is the scenario most likely to carry legal consequences; monitoring a minor child or a company-owned device under a clearly disclosed policy sits in different legal territory.

How to Check If It’s on Your Phone

Stalkerware is built to avoid detection, but it usually leaves a few traces. If you’re worried someone has installed monitoring software on your device, look for the following:

  • Unexplained battery drain or heat. Background data uploads take power, and a phone that’s suddenly draining faster with no change in your habits is worth investigating.
  • Higher data usage than normal. Constant uploads of texts, photos, or location show up in your carrier’s data logs.
  • Apps or permissions you don’t recognize. Check Settings > Apps for anything unfamiliar, and review which apps have access to your microphone, camera, and location.
  • Accessibility service entries you didn’t enable. Many stalkerware apps abuse Android’s Accessibility settings to gain deep access. Go to Settings > Accessibility and review everything listed under “Downloaded apps.”
  • Device admin apps you don’t recall installing. These sit under Settings > Security > Device admin apps and can be removed directly from that screen.
  • Someone knowing things they shouldn’t. If a partner, ex, or family member seems to know your location, conversations, or search history in detail they shouldn’t have access to, that’s a strong behavioral signal, independent of any technical check.

If you find something and suspect the person who installed it may become dangerous if it’s removed, the safer first step is often to document what you’ve found and reach out to a domestic violence support organization before deleting anything. The Coalition Against Stalkerware and the National Domestic Violence Hotline (1-800-799-7233) both have guidance built specifically for this situation, including how to preserve evidence safely.

The Bottom Line

TheTruthSpy markets itself as a monitoring tool, but its defining feature is a stealth mode built to hide from the person being watched, and its defining track record is a string of breaches going back to 2018 that have repeatedly exposed the private data of people who never agreed to be monitored in the first place. If you’re evaluating it as something to install on someone else’s phone, both the legal exposure and the app’s own security history argue against it. If you’re trying to find out whether it’s already on your phone, the checks above are the place to start.

Leave a Reply

Your email address will not be published. Required fields are marked *