TL;DR: Bryan Fleming, who built and sold stalkerware that helped 138,000+ customers secretly spy on partners, was sentenced on April 6, 2026 in San Diego federal court. His punishment: a $5,000 fine and supervised release. No prison time. This was the first successful stalkerware prosecution since 2014's StealthGenie case, and the sentence suggests the DOJ still doesn't take this industry seriously. The stalkerware market continues to thrive.

The Sentence

Bryan Fleming walked out of a San Diego federal courtroom on April 6 with a $5,000 fine and supervised release. That's it. No prison. No meaningful financial penalty. For running a business that enabled thousands of people to secretly surveil their partners.

Let's do some math. pcTattletale generated over $600,000 in revenue during its operation. Fleming's fine amounts to less than 1% of what he made selling tools to abusers. It's less than many of his customers paid in subscription fees.

Fleming pleaded guilty in January 2026 to "intentionally manufacturing, possessing, or selling a device knowing it would be used for surreptitious interception of communications." In plain English: he built spy software, he knew it was used to stalk people, and he sold it anyway.

He'd faced up to 15 years in prison and a $250,000 fine. He got one day served and pocket change.

What pcTattletale Actually Did

pcTattletale wasn't some ambiguous monitoring tool. It was purpose-built for stalking. Once secretly installed on someone's phone or computer, the software uploaded everything to Fleming's servers: text messages, emails, phone calls, GPS location, web browsing history, and video recordings of screen activity, all viewable through a remote dashboard.

Fleming marketed it to people who wanted to "catch a cheater." His communications with customers made clear he knew exactly how the software was being used. Court documents show he "knowingly assisted customers seeking to spy on nonconsenting, non-employee adults."

Fleming ran the operation from his Michigan home through Fleming Technologies LLC starting as early as 2017. Homeland Security Investigations (HSI) spent years building the case, with an undercover agent posing as both a marketing affiliate and a customer to document how pcTattletale operated.

One Prosecution Per Decade

This was only the second stalkerware prosecution since 2014, when Hammad Akbar (creator of StealthGenie) was fined $500,000 and also received no prison time. Two prosecutions in twelve years. Two fines. Zero jail time.

The DOJ has known about stalkerware for years. HSI launched an investigation examining over 100 stalkerware companies in June 2021. That investigation led to Fleming's case. But one conviction from a review of 100+ companies isn't a crackdown. It's a rounding error.

Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation and co-founder of the Coalition Against Stalkerware, pointed to the core problem: "One of the most striking aspects of this case is the extent to which stalkerware companies like pcTattletale operate out in the open. This is because the people behind these companies so rarely face consequences for selling tools that they themselves say are explicitly for monitoring other people's devices without their knowledge or consent."

Galperin added: "I hope that this case changes the risk calculus for makers of stalkerware."

With a $5,000 fine as the ceiling? It won't.

The Industry Didn't Get the Memo

pcTattletale shut down in 2024 after a breach exposed 138,000 customer accounts and data from 26,000+ victims. But the stalkerware market didn't shrink. It barely noticed.

Since pcTattletale's collapse, the hits keep coming:

  • SpyX: breached in 2025, customer and victim data exposed
  • Cocospy: breached, surveillance data leaked
  • Spyic: breached, customer credentials dumped
  • uMobix, Xnspy, Geofinder: 536,000 customer payment records exposed by a hacktivist in early 2026

These apps all follow the same playbook: market as "parental monitoring" while building features designed for intimate partner surveillance. Invisible installation. Silent data uploads. Remote dashboards showing every message, photo, and GPS ping.

And they keep getting breached, because companies built to operate in the shadows don't invest much in security. The surveillance data they collect from victims ends up exposed to anyone who can download a leaked database.

What This Sentence Says

The message from the justice system is clear: building surveillance tools that enable domestic abuse is technically illegal but practically unpunished. Fleming ran pcTattletale for at least seven years, made over $600,000, enabled the surveillance of tens of thousands of people, and got a fine that wouldn't cover a month's rent in San Diego.

The DOJ pressed charges. They got a conviction. Then the sentencing judge handed down a penalty that makes the whole exercise feel performative. Five thousand dollars and a talking-to. Don't do it again.

For the next person thinking about launching a stalkerware company, the risk calculus is simple: the reward is six figures (or more), the risk is basically nothing. Even if you're one of the vanishingly rare operators who gets caught, you'll pay less than you'd spend on a lawyer for a speeding ticket.

What You Can Do

Detect Stalkerware

Watch for unusual battery drain, unexpected data usage, or your phone warming up when idle. On Android, check Settings > Apps for anything you didn't install. On iOS, look for unfamiliar configuration profiles in Settings > General > VPN & Device Management.

Get Safe Help

If you suspect you're being monitored, plan carefully before removing stalkerware, since an abuser who sees their access disappear may escalate. Contact the National Domestic Violence Hotline at 1-800-799-7233 or the Coalition Against Stalkerware for guidance.

Report Stalkerware

Report stalkerware apps to the FTC at reportfraud.ftc.gov. The more complaints filed, the harder it becomes for regulators to ignore the industry. You can also report to the FBI's IC3 at ic3.gov.

Push for Legislation

Contact your representatives and ask why stalkerware makers face lower penalties than software pirates. The current federal framework clearly isn't working: two prosecutions in twelve years with zero jail time proves it.

References

  1. TechCrunch - Convicted spyware maker Bryan Fleming avoids jail at sentencing (April 2026)
  2. The Record - First stalkerware maker prosecuted since 2014 receives no jail time (April 2026)
  3. CyberScoop - pcTattletale stalkerware maker sentence includes fine, supervised release (April 2026)
  4. TechCrunch - Founder of spyware maker pcTattletale pleads guilty (January 2026)
  5. Coalition Against Stalkerware - Resources and detection tools