Close Menu
Beverly Hills Examiner

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Kelsea Ballerini Praises Noah Kahan After CMA Fest Duet

    June 19, 2025

    State Department restarts foreign student visa process

    June 19, 2025

    Elissa Slotkin Drops A Truth Bomb On Republican Hypocrites Supporting Troops In LA

    June 19, 2025
    Facebook X (Twitter) Instagram
    Beverly Hills Examiner
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    Beverly Hills Examiner
    Home»Technology»A breach of a data broker’s trove of location data threatens the privacy of millions
    Technology

    A breach of a data broker’s trove of location data threatens the privacy of millions

    By AdminJanuary 13, 2025
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    A breach of a data broker’s trove of location data threatens the privacy of millions


    A hack and data breach at location data broker Gravy Analytics is threatening the privacy of millions of people around the world, whose smartphone apps unwittingly revealed their location data collected by the data giant.

    The full scale of the data breach isn’t yet known, but the alleged hacker has already published a large sample of location data from top consumer phone apps — including fitness and health, dating, and transit apps, as well as popular games. The data represents tens of millions of location data points of where people have been, live, work, and travel between.

    News of the breach broke last weekend after a hacker posted screenshots of location data on a closed-access Russian language cybercrime forum, claiming they had stolen several terabytes of consumers’ data from Gravy Analytics. Independent news outlet 404 Media first reported the forum post alleging the apparent breach, which claimed to include the historical location data of millions of smartphones. 

    Norwegian broadcaster NRK reported on January 11 that Unacast, the parent company of Gravy Analytics, disclosed the breach with the country’s data protection authorities as required under its law.

    Unacast, founded in Norway in 2004, merged with Gravy Analytics in 2023 to create what it touted at the time as “one of the largest” collections of consumers’ location data. Gravy Analytics claims to track more than a billion devices around the world daily.

    In its data breach notice filed with Norway, Unacast said it identified on January 4 that a hacker acquired files from its Amazon cloud environment through a “misappropriated key.” Unacast said it was made aware of the breach through communication with the hacker, but the company gave no further details. The company said its operations were briefly taken offline following the breach.

    Unacast said in the notice that it also notified U.K. data protection authorities of the breach. A spokesperson for the U.K.’s Information Commissioner’s Office did not immediately comment Monday when reached by TechCrunch. 

    Unacast executives Jeff White and Thomas Walle did not return multiple emails from TechCrunch this week requesting comment. In an unattributed statement from a generic Gravy Analytics email account sent to TechCrunch on Sunday, Unacast acknowledged the breach, saying that its “investigation remains ongoing.”

    Gravy Analytics’ website was still down at the time of writing. Several other domains associated with Gravy Analytics also appeared to be non-functional, according to checks by TechCrunch over the past week.

    30 million location data points leaked so far

    Data privacy advocates have long warned of the risks that data brokers pose to individuals’ privacy and national security. Researchers with access to the sample of Gravy Analytics’ location data posted by the hacker say that the information can be used to extensively track people’s recent whereabouts.

    Baptiste Robert, the CEO of digital security firm Predicta Lab who obtained a copy of the leaked dataset, said in a thread on X that the data set contained more than 30 million location data points. These included devices located at The White House in Washington D.C.; the Kremlin in Moscow; Vatican City; and military bases around the world. One of the maps shared by Robert showed the location data of Tinder users across the United Kingdom. In another post, Robert showed it was possible to identify individuals likely serving as military personnel by overlapping the stolen location data with the locations of known Russian military facilities.

    a screenshot showing purple location dots placed all over a map of the UK, showing Tinder users across the country.
    A map showing Tinder users located across the United Kingdom.Image Credits:Baptiste Robert / X

    Robert warned that the data also allows for easy deanonymization of ordinary individuals; in one example, the data tracked a person as they traveled from New York to their home in Tennessee. Forbes reported about the dangers that the dataset has for LGBTQ+ users, whose location data derived from certain apps could identify them in countries that criminalize homosexuality. 

    News of the breach comes weeks after the Federal Trade Commission banned Gravy Analytics and its subsidiary Venntel, which provides location data to government agencies and law enforcement, from collecting and selling Americans’ location data without consumers’ consent. The FTC accused the company of unlawfully tracking millions of people to sensitive locations, like healthcare clinics and military bases. 

    Location data tapped from ad networks

    Gravy Analytics sources much of its location data from a process called real-time bidding, a key part of the online advertising industry that determines during a milliseconds-short auction which advertiser gets to deliver their ad to your device.

    During that near-instant auction, all of the bidding advertisers can see some information about your device, such as the maker and model type, its IP addresses (which can be used to infer a person’s approximate location), and in some cases, more precise location data if granted by the app user, along with other technical factors that help determine which ad a user will be displayed. 

    But as a byproduct of this process, any advertiser that bids — or anyone closely monitoring these auctions — can also access that trove of so-called “bidstream” data containing device information. Data brokers, including those who sell to governments, can combine that collected information with other data about those individuals from other sources to paint a detailed picture of someone’s life and whereabouts.

    Analyses of the location data by security researchers, including Predicta Lab’s Robert, reveal thousands of ad-displaying apps that have shared, often unknowingly, bidstream data with data brokers.

    The data set contains data derived from popular Android and iPhone apps, including FlightRadar, Grindr, and Tinder — all of which have denied any direct business links to Gravy Analytics but acknowledged displaying ads. But by the nature of how the advertising industry works, it is both possible for ad-serving apps to have their users’ data collected while also not explicitly knowing about or agreeing to it.

    As noted by 404 Media, it is unclear how Gravy Analytics derived its massive troves of location data, such as whether the company collected the data itself or from other data brokers. 404 Media found that large amounts of the location data was inferred from the device owner’s IP address, which is geolocated to approximate their real-world location, rather than relying on the device owner allowing the app to access the device’s precise GPS coordinates.

    What you can do to prevent ad surveillance

    Per digital rights group Electronic Frontier Foundation, ad auctions happen on nearly every website, but there are measures you can take to protect yourself from advertising surveillance.

    Using an ad-blocker — or mobile-level content blocker — can be an effective defense against ad surveillance by blocking the ad code from loading on websites in the user’s browser to begin with.

    Android devices and iPhones also bake in device-level features that make it more difficult for advertisers to track you between apps or across the web, and link your pseudonymous device data to your real-world identity. The EFF also has a good guide on how to check these device settings.

    If you have an Apple device, you can go to the “Tracking” options in your Settings and switch off the setting for app requests to track. This zeroes out your device’s unique identifier, making it indistinguishable from anyone else’s.

    “If you disable the app tracking, your data has not been shared,” Robert told TechCrunch.

    Android users should go to the “Privacy” then “Ads” section of their phone’s settings. If the option is available, you can delete your advertising ID to prevent any app on your phone accessing your device’s unique identifier in the future. Those without this setting should still regularly reset their advertising IDs.

    Preventing apps from accessing your precise location when it’s not required will also help reduce your data footprint.



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleTrump’s Erroneous Claims about the Los Angeles Fire Response, Debunked
    Next Article Trudeau says Canada won’t be 51st state, though Trump a ‘successful negotiator’

    RELATED POSTS

    Hot Octopuss Pulse Duo Review: Not for Penetration

    June 19, 2025

    Multiplier, founded by ex-Stripe exec, nabs $27.5M to fuel AI-powered accounting roll-ups

    June 18, 2025

    Far-Right ‘Appeal to Heaven’ Flag Flown Above Government Agency in DC

    June 18, 2025

    Meta is reportedly building AI smart glasses with Prada, too

    June 17, 2025

    Minnesota Shooting Suspect Allegedly Used Data Broker Sites to Find Targets’ Addresses

    June 17, 2025

    Instagram tests a reposts feature

    June 16, 2025
    latest posts

    Kelsea Ballerini Praises Noah Kahan After CMA Fest Duet

    Kelsea Ballerini is opening up about her close bond with Noah Kahan following their emotional…

    State Department restarts foreign student visa process

    June 19, 2025

    Elissa Slotkin Drops A Truth Bomb On Republican Hypocrites Supporting Troops In LA

    June 19, 2025

    Kate Middleton’s sudden Royal Ascot absence signals a new reality: experts

    June 19, 2025

    Hot Octopuss Pulse Duo Review: Not for Penetration

    June 19, 2025

    Supreme Court Skrmetti Decision Permits Ban on Gender-Affirming Care for Children

    June 19, 2025

    Where to Stream Every ‘Jurassic Park’ Movie Online

    June 19, 2025
    Categories
    • Books (585)
    • Business (5,491)
    • Film (5,427)
    • Lifestyle (3,532)
    • Music (5,481)
    • Politics (5,477)
    • Science (4,838)
    • Technology (5,424)
    • Television (5,101)
    • Uncategorized (1)
    • US News (5,478)
    popular posts

    Harvard’s defiance of Trump’s ‘authoritarian incursion’ supported by 60 past and present college and university presidents

    The Trump administration has recently escalated its destructive and illegal attacks on the core freedoms…

    2024 GOP candidates Haley, Hutchinson split on discussing Trump pardon during presidential campaign

    July 30, 2023

    Herschel Walker Thinks Climate Change Spending Is About Trees

    August 22, 2022

    ‘John Wick 5’? Director Chad Stahelski Says “We’re Open To It.” – The Hollywood Reporter

    April 3, 2023
    Archives
    Browse By Category
    • Books (585)
    • Business (5,491)
    • Film (5,427)
    • Lifestyle (3,532)
    • Music (5,481)
    • Politics (5,477)
    • Science (4,838)
    • Technology (5,424)
    • Television (5,101)
    • Uncategorized (1)
    • US News (5,478)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    Supreme Court Skrmetti Decision Permits Ban on Gender-Affirming Care for Children

    June 19, 2025

    Where to Stream Every ‘Jurassic Park’ Movie Online

    June 19, 2025

    ‘Jeopardy!’ Contestant Makes Bidding Mistake That Costs the Game

    June 19, 2025
    © 2025 Beverly Hills Examiner. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT