Hacked GPS tracker reveals location data of customers


Stalkerware researcher maia arson crimew strikes again. Big time. We know maia as a researcher that loves to go after stalkerware peddlers, which Malwarebytes—as one of the founding members of the Coalition Against Stalkerware—loves to see.

The investigation into Tracki, besides uncovering a tangled web of companies, dubious websites, and false identities, also led to a data breach that maia says could possibly affect almost 12 million users. Researching the technology behind the tracker and the web portal for customers that want to see all their trackers on a map, maia found various hardcoded usernames and passwords used to load data from a number of administration and support tools.

Read more…
Source: Malwarebytes Labs


Sign up for our Newsletter


Related:

  • Massive Quest Diagnostics data breach impacts 12 million patients

    June 4, 2019

    A massive data breach has struck Quest Diagnostics and the information of up to 11.9 million patients has potentially been compromised. On Monday, the US clinical laboratory said that American Medical Collection Agency (AMCA), a billing collections provider that works with Quest, informed the company that an unauthorized user had managed to obtain access to AMCA systems. Through the ...

  • Unsecured database exposes 85GB in security logs of major hotel chains

    May 30, 2019

    An unsecured database that exposed the security logs — and therefore potential cybersecurity weaknesses — of major hotels including Marriott locations has been uncovered by researchers. VpnMentor researchers Noam Rotem and Ran Locar published their findings on Thursday, noting that multiple hotels have been embroiled in the security incident. The team, including co-founder of vpnMentor Ariel Hochstadt, uncovered the problematic server ...

  • Apple and WhatsApp fight proposal to let spies tap encrypted comms

    May 30, 2019

    Apple, Google, Microsoft, and WhatsApp have opposed a proposal by UK spy agency GCHQ to give spies access to end-to-end encrypted communications. Rather than add a backdoor or undermine encryption itself, technical whizzes from GCHQ and its cybersecurity unit, the National Cyber Security Centre (NCSC), suggested that service provides like Apple, Google, and Facebook could “silently ...

  • Snapchat Privacy Blunder Piques Concerns About Insider Threats

    May 24, 2019

    After a report found that Snap employees were abusing their access to Snapchat data, experts are warning that insider threats will continue to be a top challenge for privacy. Snap, the company behind the popular Snapchat social media app, has found itself in hot water after a recent report revealed that Snap employees were abusing their ...

  • GDPR: How Europe’s digital privacy rules have changed everything

    May 20, 2019

    On 25 May 2018 the European Union’s General Data Protection Regulation (GDPR) came into force. At its heart, GDPR set out to update rules around privacy and consent for the digital age and to ensure that organisations are responsible in their handling of their customers’ personal data – and that those customers are aware of how their data is ...

  • Update WhatsApp now: Bug lets snoopers put spyware on your phone with just a call

    May 14, 2019

    WhatsApp has disclosed a serious vulnerability in the messaging app that gives snoops a way to remotely inject Israeli spyware on iPhone and Android devices simply by calling the target. The bug, detailed in a Monday Facebook advisory for CVE-2019-3568, is a buffer overflow vulnerability within WhatsApp’s VOIP function. An attacker would need to call a target and ...