Drooid Logo
Back to story perspectives

Full Breakdown

Stalkerware Leak Exposes Private Data of Prominent European Celebrity

5/2/2026, 5:56:21 AM

The Leak: How Private Screenshots Became Public

Cybersecurity researcher Jeremiah Fowler identified a publicly accessible, non-password-protected database containing 86,859 images that appear to be screenshots taken from a victim’s smartphone. The images capture activity on WhatsApp, Facebook, Instagram, TikTok and other platforms, revealing intimate messages, photos, phone numbers, email addresses and scans of ID documents. The database was linked to stalkerware that had been installed on the device of a well-known European entrepreneur and media personality.

Background: Stalkerware and Its Legal Status

Stalkerware is covert spyware installed—typically after brief physical access—to a phone, tablet or computer. It can record GPS location, read texts, capture calls, activate cameras or microphones, and continuously upload data to a remote dashboard. Unauthorized use is criminalised in the European Union, the United States, Canada, Australia and several other jurisdictions under computer-misuse, wire-tapping and data-protection statutes.

Scale of the Exposure

The leaked repository holds 86,859 screenshots spanning private chats with models, influencers and friends, as well as romantic exchanges. In addition to text, the files include phone numbers, email addresses, invoices, receipts and identification documents. Although the storage folder was named after a known spyware service, investigators confirmed it did not belong to that provider; it appears to have been created by an individual monitoring the single target.

Official Statements & Responses

Fowler reported that he contacted the victim directly using phone numbers extracted from the screenshots and alerted law-enforcement agencies. ExpressVPN collaborated with Fowler to publish the findings and to raise public awareness. Fowler emphasized that the breach demonstrates how “personal communications and online interactions can be monitored when malicious software is present.” No official comment from the alleged attacker or the victim’s representatives was released.

Criticism & Opposition

Privacy advocates note that the incident underscores the insufficiency of end-to-end encryption once data is displayed on a device, as “encryption only protects data in transit.” The misconfigured database allowed anyone with an internet connection to view highly sensitive material, highlighting the need for stricter controls on data storage and more robust legal enforcement against stalkerware deployment.

Conflicting Reports & Gaps

All sources agree on the number of images and the general content, but no party disclosed the victim’s identity, the specific stalkerware variant used, or the identity of the individual who created the database. Consequently, the full chain of responsibility remains unverified.

Verbatim Quotes

  • “My goal in publishing these findings is to raise awareness about the risks posed by stalkerware while protecting the identities of those involved.” — Jeremiah Fowler, cybersecurity researcher
  • “This case highlights how easily personal communications and online interactions can be monitored when malicious software is present.” — Jeremiah Fowler
  • “encryption only protects data in transit,” — Jeremiah Fowler
  • “Screenshots from the leaked data (Source: ExpressVPN) “I identified that the victim of the spyware is a prominent European celebrity, entrepreneur, and media personality.” — Jeremiah Fowler
  • “This case highlights how easily personal communications and online interactions can be monitored when malicious software is present. My intention is to highlight these cybersecurity threats and provide guidance on how to identify and mitigate similar forms of digital surveillance.” — Jeremiah Fowler

What’s Next

Law-enforcement investigations are ongoing to determine the perpetrator and assess potential criminal charges. Fowler and ExpressVPN plan further outreach to educate users on detecting and removing stalkerware, including recommendations such as maintaining physical control of devices, using strong passwords, enabling multi-factor authentication, and performing full factory resets when compromise is suspected.