Digital HarmsTrackerBeta
ExploreAnalysisDataAbout
All platforms
Cloud/InfraAmazonLaunched 2006Website

Amazon S3

Amazon S3 has been named in 1 documented digital harm incident. The most common harm domain is Privacy & Surveillance.

1
Incidents
0
Fatalities
0
Minors involved
—
Financial harm

Documented Incidents

1
Feb 20, 2025

Stalkerware apps Cocospy and Spyic data breach exposes 2.65 million user accounts

Security researchers discovered a vulnerability in the stalkerware apps Cocospy and Spyic that allowed anyone to download personal data, including messages, photos, call logs and the email addresses of registered users. By exploiting the flaw, they scraped roughly 1.81 million Cocospy and 880,000 Spyic email addresses (about 2.65 million unique accounts) and shared the list with the Have I Been Pwned service. The apps route traffic through Cloudflare and store data on Amazon Web Services, and the breach is linked to the China‑based developer 711.icu; the operators have not responded to requests for comment and the bug remains unpatched.

Privacy & Surveillance

By Harm Domain

Privacy & Surveillance1

Digital Harms Tracker

Connecting documented digital harms to the policy response.

This project is a work in progress. We're building in the open — data, methodology, and code are shared as we go.

Resources

  • About
  • Methodology

Get Involved

  • Submit a tip
  • Request analysis

© 2026 Digital Harms Tracker. Connecting digital harms to the policy response.