started · updated
Polarsteps travel app exposed in major data privacy breach
The Dutch travel application Polarsteps has been implicated in a major security vulnerability that exposed the personal data of approximately 23 million users. According to investigations by the platform Follow the Money (FTM), the flaw resided in the app’s Application Programming Interface (API), which allowed unauthorized access to sensitive information.
Researchers reported that the vulnerability enabled the collection of over 1 billion GPS location points from nearly two million trips. The exposed data included names, private photos, videos, and highly detailed real-time location tracking. Crucially, the investigation found that even accounts and trips explicitly set to ‘private’ were accessible through the unsecured API.
The issue was initially identified by cybersecurity expert Louis Couderc, who reported the findings to the company. While Polarsteps stated that the company was aware of the issue and has since implemented rate limiting and tightened API security, FTM reported that they were able to scrape data from a single IP address for months without interruption.
Polarsteps has disputed the characterization of the event as a data leak, asserting that the information accessed via the API was publicly available. However, investigators noted that the ability to track users in real-time and access private trip details contradicts the app’s privacy settings.
Entities
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] The vulnerability allowed access to private accounts and trips set to private. www.travmagazine.nl
- [○ 1 SOURCE] Approximately 230 million photos and videos were accessible through the API. www.travmagazine.nl
- [● 2 SOURCES] The company has since tightened API security and adjusted rate limiting settings. www.travmagazine.nl · www.security.nl
- [● 3 SOURCES] The travel app Polarsteps had a security vulnerability that exposed data from over 23 million users. www.travmagazine.nl · www.security.nl
- [● 2 SOURCES] Researchers collected over 1 billion location points from nearly two million trips. www.travmagazine.nl
- [● 3 SOURCES] The security flaw was discovered by cybersecurity expert Louis Couderc in late 2024. www.travmagazine.nl · www.security.nl
- [○ 1 SOURCE] Polarsteps denies that a data leak occurred, claiming only public information was accessed. www.security.nl