Hackers claim massive breach of company that tracks and sells Americans’ location data

15 hours ago 10

When we talk about data privacy, tech giants like Google and Facebook are often blamed for using personal data to show ads and recommendations. Less discussed are the businesses whose entire business model revolves around collecting your data and selling it to other companies and governments. These companies often operate in legal grey areas, with the consent required to collect user data buried deep in the fine print.

What’s even more concerning is that these data brokers fail to adequately protect the data they collect. Last year, National Public Data (NPD) made headlines for failing to secure 2.7 billion records of individuals whose data it had harvested. Now, hackers have reportedly stolen data from Gravy Analytics, the parent company of Venntel, which has sold vast amounts of smartphone location data to the U.S. government.

A person working on a laptop

What you need to know about the breach

Hackers claim to have breached Gravy Analytics, a major location data broker and parent company of Venntel, a firm known for selling smartphone location data to U.S. government agencies. The compromise is massive, including sensitive location data that tracks precise smartphone movements, customer information, and even internal infrastructure, according to a 404 Media report.

The hackers are threatening to make the stolen data public. The files contain precise latitude and longitude coordinates of the phone, and the time at which the phone was there. Some even indicate what country the data has been collected from.

Hackers have claimed access to Gravy’s systems since 2018. If true, this represents a serious security lapse on the company’s part. It is baffling how companies that collect and sell user data (a practice that arguably shouldn’t be allowed in the first place) failed to protect it from being leaked.

404 Media also suggests that the hackers gained deep access to the company’s infrastructure, including Amazon S3 buckets and server root access. The exposed customer list reportedly includes major companies like Uber, Apple, and Equifax, as well as government contractors like Babel Street.

A person using phone and with laptop in front of him

HERE’S WHAT RUTHLESS HACKERS STOLE FROM 110 MILLION AT&T CUSTOMERS

What this breach means for people

This data breach highlights the serious security flaws in the location data industry. Companies like Gravy Analytics and Venntel have been profiting from collecting and selling sensitive location data, often without proper user consent. They’ve prioritized profit over security, and now, the privacy of millions is at risk. This data could end up on black markets, endangering individuals, especially those in vulnerable situations, by making them targets for harassment or worse.

The FTC’s recent crackdown on Gravy, announced in December, underscores their negligence. The proposed order will prohibit these companies from selling or using location data, except in specific cases like national security or law enforcement. The implications are worrying. Sensitive locations like schools and workplaces could become easy targets for those with malicious intent.

A person using phone

BEWARE OF ENCRYPTED PDFS AS THE LATEST TRICK TO DELIVER MALWARE TO YOU

5 ways to stay safe in the age of data breaches

The Gravy Analytics breach serves as a sobering reminder of the vulnerabilities in the digital age. While it’s impossible to control how every company handles data, you can take steps to minimize your exposure and protect your privacy. Here are five actionable tips to stay safe: 

1) Limit app permissions: Many apps request access to location data, contacts, and more—even when it’s not necessary for their functionality. Regularly review the permissions for apps on your smartphone and revoke access to anything that feels excessive. For instance, a weather app doesn’t need access to your microphone or camera.

2) Use a VPN: Virtual Private Networks (VPNs) can mask your IP address and encrypt your internet activity, making it harder for data brokers and hackers to track your online behavior. A good VPN adds an extra layer of security, especially when using public Wi-Fi networks.

ExpressVPN and Surfshark are both trusted VPN services that prioritize your privacy and security and are available on a wide range of platforms, including Mac, Windows, iOS, Android, and popular browsers.

ExpressVPN: ExpressVPN is known for its speed, reliability, and strong privacy features. It offers ultra-fast servers in 105 countries, supports P2P sharing, and allows up to 8 devices to connect simultaneously. Available on a wide range of devices, it features a simple setup that takes less than 2 minutes. ExpressVPN’s strict no-log policy ensures your data is never stored, and all servers run on RAM, so no user activity is saved. With 24/7 live customer support and a 30-day money-back guarantee, ExpressVPN is a top choice for privacy-conscious users.

CYBERGUY DEALS: 

  • Save 48% now with CyberGuy’s exclusive offer – you can get now up to 3 months FREE with a 12-month plan, for $6.67/month.  Try 30 days risk-free.
  • Save 61% now with CyberGuy’s exclusive offer – you can get now up to 4 months FREE with a 24-month plan, for $4.99/month.  Try 30 days risk-free.

Surfshark: Another excellent option, Surfshark provides strong security features at an affordable price. Like ExpressVPN, Surfshark operates under a strict no-logs policy and uses advanced encryption to keep your data safe. One standout feature is Surfshark’s ability to support unlimited devices on a single account, making it ideal for families or users with multiple gadgets. Another to top choice for privacy-conscious users.

CYBERGUY DEALS:

  • Save 81% now with CyberGuy’s exclusive offer – Get 3 extra months FREE with a 12-month plan. Try 30 days risk-free, for only $3.19 per month.
  • Save 87% now with CyberGuy’s exclusive offer – Get 3 extra months FREE with a 24-month plan. Try 30 days risk-free, for only $2.19 per month.

 3) Opt out of data sharing where possible: Some companies allow you to opt out of having your data collected or shared. Services like Your Ad Choices and privacy settings within platforms like Google can help you reduce the amount of data collected. Check for opt-out options with any apps or services you use frequently.

4) Avoid free apps that monetize data: Free apps often generate revenue by selling user data. Instead, consider paid versions of apps that explicitly prioritize privacy. Research the company behind the app to understand its data handling policies before downloading.

5) Invest in data removal services: Data removal services can help you regain some control over your personal information by identifying and removing it from people-search websites, data broker platforms, and other online databases.

A service like Incogni can help you remove all this personal information from the internet. It has a very clean interface and will scan 195 websites for your information and remove it and keep it removed.

Special for CyberGuy Readers (60% off):  Incogni offers A 30-day money-back guarantee and then charges a special CyberGuy discount only through the links in this article of $5.99/month for one person (billed annually) or $13.19/month for your family (up to 4 people) on their annual plan and get a fully automated data removal service, including recurring removal from 200+ data brokers

You can add up to 3 emails, 3 home addresses and 3 phone numbers (U.S. citizens only) and have them removed from data-broker databases. I recommend the family plan because it works out to only $4.12 per person per month for year-round coverage. It’s an excellent service, and I highly recommend at least trying it out to see what it’s all about.

Get Incogni here

Get Incogni for your family (up to 4 people) here

WHAT TO DO IF YOUR BANK ACCOUNT IS HACKED

Kurt’s key takeaway

Companies that collect and sell user data pose a significant threat to privacy, and when they fail to protect this data, it often ends up in the hands of even worse actors. Cybercriminals, and even some governments, can exploit this information to target individuals. It is crucial to implement stringent repercussions for these companies when they fail in their duty to safeguard user data. A mere slap on the wrist is not enough. We need real accountability to deter negligence and protect individual privacy rights.

Should companies face stronger penalties for failing to protect personal data? Let us know in the comments.

FOR MORE OF MY SECURITY ALERTS, SUBSCRIBE TO MY FREE CYBERGUY REPORT NEWSLETTER HERE

Read Entire Article