Hacked GPS tracker reveals location data of customers


Stalkerware researcher maia arson crimew strikes again. Big time. We know maia as a researcher that loves to go after stalkerware peddlers, which Malwarebytes—as one of the founding members of the Coalition Against Stalkerware—loves to see.

The investigation into Tracki, besides uncovering a tangled web of companies, dubious websites, and false identities, also led to a data breach that maia says could possibly affect almost 12 million users. Researching the technology behind the tracker and the web portal for customers that want to see all their trackers on a map, maia found various hardcoded usernames and passwords used to load data from a number of administration and support tools.

Read more…
Source: Malwarebytes Labs


Sign up for our Newsletter


Related:

  • Open database leaked 179GB in customer, US government, and military records

    October 21, 2019

    An open database exposing records containing the sensitive data of hotel customers as well as US military personnel and officials has been disclosed by researchers. On Monday, vpnMentor’s cybersecurity team, led by Noam Rotem and Ran Locar, said the database belonged to Autoclerk, a service owned by Best Western Hotels and Resorts group. Autoclerk is a reservations management system used ...

  • Equifax failed to take even the most basic precautions, alleges lawsuit

    October 21, 2019

    A lawsuit on the 2017 data breach allege that Equifax staffers used the default – ‘admin’ – as the username and password to secure customer information portal How would you secure a portal containing valuable, personal finance information of 148 million accounts of customers spread across the US, Canada and the UK? Equifax employees chose default and ...

  • Intelligence Agencies Warn Of Flaw With VPN Products

    October 9, 2019

    Both the US NSA and UK NCSC warn hackers are actively exploiting vulnerabilities in VPN products Both the US National Security Agency (NSA) and a GQHC agency in the United Kingdom have issued warnings about “multiple vulnerabilities in Virtual Private Network (VPN) applications.” Both the NSA and the UK’s National Cyber Security Centre (NCSC) warned that advanced persistent threat (APT) ...

  • US, UK, and Australia jointly request for Facebook to stop end-to-end encryption plans

    October 4, 2019

    The United States, the United Kingdom, and Australia have joined to request that Facebook delay its plans to implement end-to-end encryption across its messaging services. First reported by BuzzFeed News, the governments on Thursday jointly published an open letter to Facebook CEO Mark Zuckerberg, asking for the company to ensure that encryption does not impede government officials ...

  • Tax and PII records of 20 million Russians stored without encryption, leaked online

    October 2, 2019

    Over 20 million tax records belonging to Russian citizens were left unprotected and exposed through an online database accessible to the public, researchers say. This week, cybersecurity researchers from Comparitech, in partnership with Bob Diachenko, said that the unsecured server contained highly sensitive information spanning from 2009 to 2016. The Amazon Web Services (AWS) Elasticsearch cluster, which was ...

  • IT Firm Manager Arrested in the Biggest Data Breach Case of Ecuador’s History

    September 18, 2019

    Ecuador officials have arrested the general manager of IT consulting firm Novaestrat after the personal details of almost the entire population of the Republic of Ecuador left exposed online in what seems to be the most significant data breach in the country’s history. Personal records of more than 20 million adults and children, both dead and ...