< Back to all clusters
[TECHNOLOGY] · Netherlands · 3 sources

started · updated

Polarsteps denies data breach following reports of API vulnerability

The travel app Polarsteps is facing scrutiny following an investigation by Follow the Money (FTM), which revealed that large amounts of user data were accessible through a vulnerability in the company's API. The investigation suggests that FTM was able to retrieve names of 23 million users, access hundreds of millions of photos, and collect billions of GPS locations.

Reports indicate that the vulnerability allowed for the collection of sensitive information, including home addresses derived from photo metadata. FTM claims it could access approximately 230 million photos and videos, as well as one billion location points from nearly two million trips. There are also allegations that certain location data used by the app was not explicitly mentioned in the company's privacy policy.

Polarsteps denies that a data breach occurred, stating that no authentication was bypassed and that trips set to ‘Only me’ remained private. The company maintains that the data accessed was primarily public profile information. However, Polarsteps acknowledged that its security against large-scale data scraping could have been improved. In response, the company has tightened API security, limited the amount of public information available via the API, and updated default user-tracking settings.

Entities

Follow the Money · Polarsteps