Hack reveals thousands of apps that leaked users’ location data
A hacking group recently revealed that it had breached the location-data company Gravy Analytics and exfiltrated sensitive location data on millions of users.
A leaked sample of the data has revealed a list of thousands of apps which allegedly leaked this data. Some of the apps in the list included Candy Crush, Tinder, MyFitnessPal, Disney Magic Kingdoms, FuboTV, and AccuWeather: Weather Radar.
It is likely that users of the apps were unaware of their location data being bought and sold in the largely unregulated location-data industry, as the data appeared to be gathered via exploiting a loophole in mobile-ad real-time bidding auctions that can share a device’s location.
Last month, the Federal Trade Commission announced a proposed settlement with Gravy Analytics which prohibited the company from “selling, disclosing, or using sensitive location data in any product or service, and must establish a sensitive data location program.” Gravy Analytics merged with Unacast in 2023.
It is likely that users of the apps were unaware of their location data being bought and sold in the largely unregulated location-data industry, as the data appeared to be gathered via exploiting a loophole in mobile-ad real-time bidding auctions that can share a device’s location.
Last month, the Federal Trade Commission announced a proposed settlement with Gravy Analytics which prohibited the company from “selling, disclosing, or using sensitive location data in any product or service, and must establish a sensitive data location program.” Gravy Analytics merged with Unacast in 2023.