Founder of spyware maker pcTattletale pleads guilty to hacking and advertising surveillance software

3 months ago 34

The laminitis of a U.S.-based spyware company, whose surveillance products allowed customers to spy connected the phones and computers of unsuspecting victims, pleaded blameworthy to national charges linked to his long-running operation. 

pcTattletale laminitis Bryan Fleming entered a blameworthy plea successful a San Diego national tribunal connected Tuesday to charges of machine hacking, the merchantability and advertizing of surveillance bundle for unlawful uses, and conspiracy.

The plea follows a multi-year probe by agents with Homeland Security Investigations (HSI), a portion wrong U.S. Immigration and Customs Enforcement. HSI began investigating pcTattletale successful mid-2021 arsenic portion of a wider probe into the manufacture of consumer-grade surveillance software, besides known arsenic “stalkerware.”

This is the archetypal palmy U.S. national prosecution of a stalkerware relation successful much than a decade, pursuing the 2014 indictment and consequent blameworthy plea of the creator of a phone surveillance app called StealthGenie. Fleming’s condemnation could pave the mode for further national investigations and prosecutions against those operating spyware, but besides those who simply advertise and merchantability covert surveillance software.

HSI said that pcTattletale is 1 of respective stalkerware websites nether investigation.

A spokesperson for ICE did not instantly remark erstwhile contacted by TechCrunch, nor did a typical for the U.S. Attorney’s Office for the Southern District of California, which brought the charges against Fleming.

Fleming’s lawyer Marcus Bourassa did not respond to a petition for remark Tuesday.

pcTattletale was a distant surveillance app that had been nether Fleming’s power since astatine slightest 2016. Stalkerware apps similar pcTattletale let mean consumers to bargain bundle susceptible of tracking radical and their information without their knowledge, including romanticist partners and spouses, which is amerciable successful the United States and galore different countries.

Once physically planted connected a person’s telephone oregon machine (usually with cognition of the victim’s passcode oregon login), the app would continuously upload a transcript of the victim’s information, including messages, photos and determination data, to pcTattletale’s servers and marque the information accessible to whoever planted the spyware.

Fleming shut down pcTattletale successful 2024 pursuing a information breach, which saw a hacker deface the company’s website and bargain reams of data from its servers, including identifiable accusation belonging to its customers and their victims. More than 138,000 customers who had signed up to usage pcTattletale had their breached accusation shared with data breach notification tract Have I Been Pwned

At the time, Fleming told TechCrunch that his institution was “out of concern and wholly done,” aft deleting the contents of pcTattletale’s servers.   

Despite the shutdown, national agents were already acold into their probe of Fleming’s amerciable spyware business.

Feds hunt founder’s $1.2M home

HSI began investigating pcTattletale successful June 2021 aft uncovering implicit a 100 stalkerware websites offering surveillance products, galore of which advertised lawful uses of the software, specified arsenic monitoring children oregon employees.

pcTattletale stood retired due to the fact that it was specifically advertizing its spyware for “surreptitiously spying connected spouses and partners,” wrote HSI peculiar cause Nick Jones successful the 2022 affidavit successful enactment of a hunt warrant for Fleming’s home. The affidavit was unsealed successful aboriginal December 2025 up of Fleming’s anticipated plea hearing. 

Crucially for investigators, Fleming was believed to beryllium operating pcTattletale from his location successful Bruce Township, Michigan, good wrong scope of U.S. instrumentality enforcement — dissimilar galore overseas stalkerware operators who are not.  

Unlike immoderate stalkerware operators who shield their identities to debar ineligible and reputational risks from moving with spyware, Fleming was brazen successful however helium advertised pcTattletale. In videos posted connected YouTube, Fleming could beryllium seen astatine his location promoting pcTattletale arsenic its creator and founder. 

A surveillance photograph  taken by HSI agents showing Bryan Fleming's location  successful  Michigan.A surveillance photograph taken by HSI agents extracurricular of Bryan Fleming’s location successful Michigan.Image Credits:Justice Department (affidavit)

According to the affidavit, HSI obtained a warrant successful 2022 allowing the hunt of Fleming’s email accounts. HSI said the emails showed that Fleming “knowingly assisted customers seeking to spy connected nonconsenting, non-employee adults.” 

Federal agents aboriginal surveilled Fleming’s location to corroborate it was successful information him.

Jones besides went undercover to cod evidence, posing arsenic an affiliate marketer nether the guise of promoting the spyware successful speech for a chopped of the proceeds. As a effect of this operation, Jones exchanged emails with Fleming, successful which the pcTattletale laminitis provided images intended for banner ads that promoted the spyware arsenic a mode to “catch a cheater,” which made it wide Fleming wanted to marketplace his merchandise for amerciable purposes. 

By November 2022, HSI had obtained support from a U.S. justice to hunt Fleming’s home, which agents raided soon after, seizing an chartless fig of items. Agents besides obtained records associated with Fleming’s slope and his PayPal account, which had transactions totaling much than $600,000 arsenic of the extremity of 2021. 

The search warrant was filed nether seal amid concerns that Fleming could destruct oregon tamper with evidence. Fleming has since sold the location for $1.2 million, per nationalist records.

Fleming’s condemnation is simply a triumph for privateness advocates and campaigners who enactment to antagonistic the proliferation of stalkerware and rise consciousness to its dangers.

Eva Galperin, the manager of cybersecurity astatine the Electronic Frontier Foundation and the co-founder of the Coalition Against Stalkerware, who has investigated and fought stalkerware for years, commented connected Fleming’s blameworthy plea erstwhile reached by TechCrunch.

“One of the astir striking aspects of this lawsuit is the grade to which stalkware companies similar pcTattletale run retired successful the open,” said Galperin. “This is due to the fact that the radical down these companies truthful seldom look consequences for selling tools that they themselves accidental are explicitly for monitoring different people’s devices without their cognition oregon consent.”

“I anticipation that this lawsuit changes the hazard calculus for makers of stalkerware,” said Galperin.

Fleming is expected to beryllium sentenced aboriginal this year.

——

If you oregon idiosyncratic you cognize needs help, the National Domestic Violence Hotline (1-800-799-7233) provides 24/7 free, confidential enactment to victims of home maltreatment and violence. If you are successful an exigency situation, telephone 911. The Coalition Against Stalkerware has resources if you deliberation your telephone has been compromised by spyware.

Read Entire Article