Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Port raises $100M valuation from $800M round to take on Spotify’s Backstage

India’s Spinny lines up $160m funding to acquire GoMechanic, sources say

OpenAI hits back at Google with GPT-5.2 after ‘code red’ memo.

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    OpenAI hits back at Google with GPT-5.2 after ‘code red’ memo.

    14 December 2025

    Trump’s AI executive order promises ‘a rulebook’ – startups may find legal loophole instead

    13 December 2025

    Ok, so what’s up with the LinkedIn algo?

    12 December 2025

    Google Released Its Deepest Research AI Agent To Date — The Same Day OpenAI Dropped GPT-5.2

    12 December 2025

    Disney hits Google with cease and desist alleging ‘massive’ copyright infringement

    11 December 2025
  • Apps

    Google’s AI testing feature for clothes now only works with a selfie

    14 December 2025

    DoorDash driver faces felony charges after allegedly spraying customers’ food

    13 December 2025

    Google Translate now lets you listen to real-time translations on your headphones

    13 December 2025

    With iOS 26.2, Apple lets you bring back Liquid Glass again — this time on the lock screen

    12 December 2025

    World launches its ‘super app’, including payment encryption and encrypted chat features

    12 December 2025
  • Crypto

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025

    Only 5 days until Disrupt 2025 sets the startup world on fire

    22 October 2025
  • Fintech

    Coinbase starts onboarding users again in India, plans to do fiat on-ramp next year

    7 December 2025

    Walmart-backed PhonePe shuts down Pincode app in yet another step back in e-commerce

    5 December 2025

    Nexus stays out of AI, keeping half of its new $700M fund for India startup

    4 December 2025

    Fintech firm Marquis notifies dozens of US banks and credit unions of data breach after ransomware attack

    3 December 2025

    Revolut hits $75 billion valuation in new capital raise

    24 November 2025
  • Hardware

    Pebble founder unveils $75 AI smart ring to record short notes with the push of a button

    10 December 2025

    Amazon’s Ring launches controversial AI-powered facial recognition feature on video doorbells

    10 December 2025

    Google’s first AI glasses are expected next year

    9 December 2025

    eSIM adoption is on the rise thanks to travel and device compatibility

    6 December 2025

    AWS re:Invent was an all-in pitch for AI. Customers may not be ready.

    5 December 2025
  • Media & Entertainment

    Disney signs deal with OpenAI to allow Sora to create AI videos with its characters

    11 December 2025

    YouTube TV will launch genre-based subscription plans in 2026

    11 December 2025

    Founder of AI startup Tavus says users talk to AI Santa ‘for hours’ a day

    10 December 2025

    Spotify releases music videos in the US and Canada for Premium subscribers

    9 December 2025

    Amazon Music’s 2025 Delivered is now here to compete with Spotify Wrapped

    9 December 2025
  • Security

    The flaw in the photo booth manufacturer’s website exposes customers’ photos

    13 December 2025

    Home Depot exposed access to internal systems for a year, researcher says

    13 December 2025

    Security flaws in the Freedom Chat app exposed users’ phone numbers and PINs

    11 December 2025

    Petco takes down Vetco website after exposing customers’ personal information

    10 December 2025

    Petco’s security bug affected customers’ SSNs, driver’s licenses and more

    9 December 2025
  • Startups

    Port raises $100M valuation from $800M round to take on Spotify’s Backstage

    14 December 2025

    Eclipse Energy’s microbes can turn dormant oil wells into hydrogen factories

    13 December 2025

    Interest in Spoor’s AI bird tracking software is soaring

    13 December 2025

    Retro, a photo-sharing app for friends, lets you ‘time travel’ to your camera roll

    12 December 2025

    On Me Raises $6M to Shake Up the Gift Card Industry

    12 December 2025
  • Transportation

    India’s Spinny lines up $160m funding to acquire GoMechanic, sources say

    14 December 2025

    Inside Rivian’s big bet on self-driving with artificial intelligence

    13 December 2025

    Zevo wants to add robotaxis to its car-sharing fleet, starting with newcomer Tensor

    13 December 2025

    Driving aboard Rivian’s fight for autonomy

    12 December 2025

    Rivian goes big on autonomy, with custom silicon, lidar and a hint of robotaxis

    12 December 2025
  • Venture

    Runware raises $50 million in Series A to make it easier for developers to create images and videos

    12 December 2025

    Stanford’s star reporter understands Silicon Valley’s startup culture

    12 December 2025

    The market has “changed” and founders now have the power, VCs say

    11 December 2025

    Tiger Global plans cautious business future with new $2.2 billion fund

    8 December 2025

    Sources: AI-powered synthetic research startup Aaru raises Series A at $1B ‘headline’ valuation

    6 December 2025
  • Recommended Essentials
TechTost
You are at:Home»Security»A breach of Gravy Analytics’ vast trove of location data threatens the privacy of millions
Security

A breach of Gravy Analytics’ vast trove of location data threatens the privacy of millions

techtost.comBy techtost.com13 January 202507 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
A Breach Of Gravy Analytics' Vast Trove Of Location Data
Share
Facebook Twitter LinkedIn Pinterest Email

An intrusion and data breach at location data broker Gravy Analytics threatens the privacy of millions of people around the world whose smartphone apps inadvertently exposed location data collected by the data giant.

The full scale of the data breach is not yet known, but the alleged hacker has already released a large sample of location data from top consumer phone apps — including fitness and health, dating and transit apps, as well as popular games. The data represents tens of millions of location data points where people have been, live, work and travel to each other.

News of the breach broke last weekend when a hacker posted snapshots of location data on a closed Russian cybercrime forum, claiming to have stolen several terabytes of consumer data from Gravy Analytics. Independent news outlet 404 Media first reported the forum post alleging the apparent breach, which it claimed involved the historical location data of millions of smartphones.

Norwegian broadcaster NRK reported on January 11 that Unacast, the parent company of Gravy Analytics, disclosed the breach with the data protection authorities of the country as required by its law.

Unacast, founded in Norway in 2004, merged with Gravy Analytics in 2023 to create what was touted at the time as “one of the largest” collections of consumer location data. Gravy Analytics claims to monitor more than a billion devices worldwide every day.

In data breach notification filed in Norway, Unacast said it detected on Jan. 4 that a hacker obtained files from Amazon’s cloud environment through an “abused key.” Unacast said it was made aware of the breach by contacting the hacker, but the company did not elaborate. The company said its operations were briefly taken offline after the breach.

Unacast said in the release that it has also informed UK data protection authorities about the breach. Lucy Milburn, a spokeswoman for the UK’s Information Commissioner’s Office, confirmed to TechCrunch that the ICO “received a report from Gravy Analytics and is investigating.”

Unacast executives Jeff White and Thomas Walle did not return multiple emails from TechCrunch this week seeking comment. In a statement that is not attributed from a generic Gravy Analytics email account sent to TechCrunch On Sunday, Unacast acknowledged the breach, saying “its investigation remains ongoing.”

The Gravy Analytics website was still down at the time of writing. Several other domains related to Gravy Analytics also appeared to be down, according to checks by TechCrunch last week.

So far 30 million location data points have been leaked

Data privacy advocates have long warned about the risks that data brokers pose to individuals’ privacy and national security. Researchers with access to the sample Gravy Analytics location data released by the hacker say the information can be used to extensively track people’s recent locations.

Baptiste Robert, CEO of digital security firm Predicta Lab, which obtained a copy of the leaked data, said in a thread in X that the dataset contained more than 30 million location data points. These included devices located in the White House in Washington, DC. the Kremlin in Moscow; Vatican City? and military bases around the world. One of the maps that Robert shared showed the location data of Tinder users across the UK. In another postRobert demonstrated that it was possible to identify individuals who likely served as military personnel by overlaying the stolen location data with the locations of known Russian military installations.

A map showing Tinder users located across the UK.Image Credits:Baptiste Robert / X

Robert cautioned that the data also allows for easy de-anonymization of individuals. In one example, the data tracked a person as he traveled from New York to his home in Tennessee. Forbes reported on the risks which has the data set for LGBTQ+ users, whose location data from certain apps could identify them in countries that criminalize homosexuality.

News of the breach comes weeks after the Federal Trade Commission banned Gravy Analytics and its subsidiary Venntel, which provides location data to government agencies and law enforcement, from collecting and selling Americans’ location data without consumer consent. The FTC accused the company of illegally tracking millions of people in sensitive locations such as health care clinics and military bases.

Location data used by ad networks

Gravy Analytics sources much of its location data a process called real-time biddinga key part of the online advertising industry that determines during a short millisecond auction which advertiser can deliver their ad to your device.

During this near-instant auction, all bidding advertisers can see certain information about your device, such as the manufacturer and model type, its IP addresses (which can be used to infer the proximity to a person’s location) and, in some cases, more precise location data if provided by the application user, along with other technical factors that help determine which ad a user will be shown.

However, as a byproduct of this process, any advertiser who bids—or anyone closely monitoring those auctions—can also access this trove of so-called “bid stream” data that contains device information. Data brokers, including those who sell to governments, can combine this collected information with other data about those individuals from other sources to paint a detailed picture of someone’s life and where they live.

Analyzes of location data by security researchers, including Robert of Predicta Labreveal thousands of ad serving apps have shared, often unknowingly, bid flow data with data brokers.

The dataset contains data sourced from popular Android and iPhone apps, including FlightRadar, Grindr and Tinder — all of which have disclaimed any direct business links to Gravy Analytics, but have acknowledged ad serving. However, due to the nature of how the advertising industry operates, it is also possible for ad-serving apps to collect their users’ data without their explicit knowledge or consent.

As noted by 404 Mediait’s unclear how Gravy Analytics sourced its massive amounts of location data, such as whether the company collected the data itself or from other data brokers. 404 Media found that large amounts of location data were inferred from the device owner’s IP address, which is geo-located to approximate their actual location, rather than relying on the device owner allowing the app to access their exact GPS coordinates device.

What you can do to prevent ad tracking

Per digital rights group Electronic Frontier FoundationAd auctions happen on almost every website, but there are steps you can take to protect yourself from ad tracking.

Using an ad blocker — or content blocker at the mobile level — can be an effective defense against ad tracking by blocking ad code on websites from loading in the user’s browser in the first place.

Android devices and iPhones also have device-level features that make it harder for advertisers to track you across apps or on the web, and link your device’s pseudonymous data to your real-world identity. The EFF also has one good guide how to check these device settings.

If you have an Apple device, you can go to the Tracking options in your Settings and turn off the setting to track application requests. This resets your device’s unique identifier, making it indistinguishable from anyone else’s.

“If you turn off app tracking, your data isn’t shared,” Robert told TechCrunch.

Android users should go to the “Privacy” and then “Ads” section of their phone’s settings. If the option is available, you can delete the advertising ID to prevent any app on your phone from accessing your unique device ID in the future. Those without this setting should reset their advertising IDs regularly.

Preventing apps from accessing your exact location when not required will also help reduce your data footprint.

Updated with comment from the ICO.

Contact Zack Whittaker securely on Signal and WhatsApp at +1 646-755-8849. You can also share documents securely with TechCrunch through SecureDrop.

Analytics breach cyber attack cyber security data data broker data privacy Gravy Location millions mobile location data our government privacy threatens trove Vast
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFloat Financial, which aims to be Canada’s Brex, raises $48.5M Series B
Next Article Xiaohongshu, China’s answer to Instagram, hits no. 1 on the App Store as TikTok faces shutdown in the US
bhanuprakash.cg
techtost.com
  • Website

Related Posts

The flaw in the photo booth manufacturer’s website exposes customers’ photos

13 December 2025

Home Depot exposed access to internal systems for a year, researcher says

13 December 2025

Security flaws in the Freedom Chat app exposed users’ phone numbers and PINs

11 December 2025
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Port raises $100M valuation from $800M round to take on Spotify’s Backstage

14 December 2025

India’s Spinny lines up $160m funding to acquire GoMechanic, sources say

14 December 2025

OpenAI hits back at Google with GPT-5.2 after ‘code red’ memo.

14 December 2025
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Coinbase starts onboarding users again in India, plans to do fiat on-ramp next year

7 December 2025

Walmart-backed PhonePe shuts down Pincode app in yet another step back in e-commerce

5 December 2025

Nexus stays out of AI, keeping half of its new $700M fund for India startup

4 December 2025
Startups

Port raises $100M valuation from $800M round to take on Spotify’s Backstage

Eclipse Energy’s microbes can turn dormant oil wells into hydrogen factories

Interest in Spoor’s AI bird tracking software is soaring

© 2025 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.