Hacked GPS tracker reveals location data of customers


Stalkerware researcher maia arson crimew strikes again. Big time. We know maia as a researcher that loves to go after stalkerware peddlers, which Malwarebytes—as one of the founding members of the Coalition Against Stalkerware—loves to see.

The investigation into Tracki, besides uncovering a tangled web of companies, dubious websites, and false identities, also led to a data breach that maia says could possibly affect almost 12 million users. Researching the technology behind the tracker and the web portal for customers that want to see all their trackers on a map, maia found various hardcoded usernames and passwords used to load data from a number of administration and support tools.

Read more…
Source: Malwarebytes Labs


Sign up for our Newsletter


Related:

  • Free streaming boxes may be routing criminal traffic through your home

    September 4, 2026

    “Free” movies and TV could cost you your privacy, bandwidth, and control of your home network. We’ve warned about illegal streaming and modded Amazon Fire TV Sticks in the past. Now, researchers have found that certain SuperBox devices and apps could quietly enroll a household connection into a proxy network, allowing third parties to route traffic through it. An earlier report identified CyberFlix ...

  • 2.8 million people affected by data breach at Baylor Genetics testing and diagnostic firm

    September 3, 2026

    Baylor Genetics, a US-based clinical diagnostic laboratory, suffered a cyberattack in which it lost sensitive data on 2.8 million people – both patients and employees. In a security update posted on its website earlier this week, the company said it spotted the intrusion in a “limited portion” of its IT environment on or around June 15. ...

  • 153M+ driver’s licenses for sale on new dark web platform

    September 2, 2026

    A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards. The collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards, according to reports. The trove of driver’s license scans reported by ...

  • P&O Ferries data blunder as it sends out passengers’ personal details by text message

    August 31, 2026

    P&O Ferries was hit by a data breach after mistakenly sending out a full list of passengers’ personal details by text message this morning, we can reveal. A blunder saw the details of 432 passengers travelling on the 12pm P&O ferry from Calais to Dover sent as an attachment in a customer services text message. It is ...

  • Healthcare data breach exposes 3.75M patient records

    August 30, 2026

    Hackers stole medical records, Social Security numbers, government IDs and financial data from millions of CareCloud patients You can be careful with your passwords and still get caught in a breach at a company you may have never heard of. That is one of the frustrating parts of the CareCloud data breach. More than 3.75 million ...

  • Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

    August 27, 2026

    Despite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social ...