< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 9 sources · 4 days · First seen · Last updated

Polarsteps data privacy vulnerability

Overview

Investigations by Follow the Money (FTM) revealed a significant security vulnerability in the Dutch travel application Polarsteps. The flaw, located in the app’s Application Programming Interface (API), reportedly allowed unauthorized access to the personal data of approximately 23 million users.

Researchers and investigators claimed the vulnerability enabled the scraping of over 1 billion GPS location points from nearly two million trips, as well as hundreds of millions of photos and videos. The reports indicated that sensitive information, such as home addresses derived from photo metadata, was accessible. Furthermore, investigators noted that even accounts and trips explicitly set to ‘private’ appeared to be accessible through the unsecured API.

Polarsteps has disputed the characterization of the event as a data breach, asserting that the information accessed was primarily “publicly available” and that no authentication was bypassed. While the company maintains that trips set to ‘Only me’ remained private, it acknowledged that its security against large-scale data scraping could be improved. In response to the findings, Polarsteps has implemented rate limiting, tightened API security, and updated default user-tracking settings.

Entities

Follow the Money · Polarsteps · Louis Couderc

Timeline

  1. 19 days ago

    [TECHNOLOGY] 3 sources
    Polarsteps denies data breach following reports of API vulnerability

    Polarsteps is defending itself against claims of a data vulnerability after an investigation found that massive amounts of user location and photo data could be accessed via its API.

  2. 23 days ago

    [TECHNOLOGY] 6 sources
    Polarsteps travel app exposed in major data privacy breach

    A security flaw in the Polarsteps API reportedly exposed names, photos, and real-time location data for 23 million users, including those with private accounts.

Sources

bright.nl · dutchcowboys.nl · itdaily.be · nos.nl · nritmedia.nl · security.nl · travmagazine.nl · welingelichtekringen.nl · zeilen.nl