Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Coinbase to lay off 14% of staff as part of broader restructuring

The US government is warning of a serious CopyFail bug affecting major versions of Linux

OpenAI host Cerebras is on track for a major IPO

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    OpenAI host Cerebras is on track for a major IPO

    5 May 2026

    In Harvard study, AI provided more accurate emergency room diagnoses than two human doctors

    4 May 2026

    ‘That’s cool’ creator says AI startup stole his art

    4 May 2026

    OpenAI announces new advanced security for ChatGPT accounts, including a partnership with Yubico

    3 May 2026

    Pentagon inks deals with Nvidia, Microsoft and AWS to deploy artificial intelligence in scalable networks

    3 May 2026
  • Apps

    Image AI models are now driving app development, surpassing chatbot upgrades

    5 May 2026

    5 days to get 50% off a second Disrupt 2026 pass

    4 May 2026

    The Jack Dorsey-backed Vine reboot goes public

    4 May 2026

    Google Photos uses artificial intelligence to make the iconic wardrobe from ‘Clueless’ a reality.

    3 May 2026

    The best AI dictation apps, tested and ranked

    3 May 2026
  • Crypto

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025
  • Fintech

    Stripe introduces Link, a digital wallet that autonomous AI agents can also use

    1 May 2026

    Y Combinator alum Skio sells for $105 million in cash, raised only $8 million, founder says

    1 May 2026

    Amazon, Meta join the fight to end Google Pay and PhonePe’s dominance in India

    30 April 2026

    Steve Ballmer slams founder he backed, who pleaded guilty to fraud: ‘I was cheated and I feel stupid’

    25 April 2026

    Salmon raises $100 million in equity and debt to bring digital credit to unbanked Filipinos

    24 April 2026
  • Hardware

    This tiny, magnetic e-reader could keep you from doomscrolling

    4 May 2026

    Apple surprised by AI-driven demand for Macs

    1 May 2026

    As Tim Cook departs, Apple hits record sales — but chip shortage looms

    1 May 2026

    More Gemini features are coming to Google TV

    30 April 2026

    OpenAI could be building a phone with AI agents that replace apps

    28 April 2026
  • Media & Entertainment

    Netflix delays Greta Gerwig’s ‘Narnia’ for big theatrical push to 2027

    2 May 2026

    Roku’s $3 streaming service Howdy hits 1 million subscribers, per recent report

    29 April 2026

    Australia forces Big Tech companies to pay for news or face 2.25% tax.

    28 April 2026

    India’s app market is booming — but global platforms are raking in most of the profits

    23 April 2026

    YouTube extends its AI similarity detection technology to celebrities

    21 April 2026
  • Security

    The US government is warning of a serious CopyFail bug affecting major versions of Linux

    5 May 2026

    Hackers are still exploiting the cPanel bug to gain control of thousands of websites

    4 May 2026

    Ubuntu services were affected by outages after the DDoS attack

    1 May 2026

    Dental software maker fixes bug that exposed patients’ medical records

    1 May 2026

    Hackers are actively exploiting a bug in cPanel, which is used by millions of websites

    30 April 2026
  • Startups

    FDA Approval, Fundraising and the Reality of Building Healthcare According to BioticsAI Founder

    1 May 2026

    Legal AI startup Legora hits $5.6 billion valuation, and its battle with Harvey just got hotter

    1 May 2026

    Bill Gurley, Jack Altman back startup Pursuit, which helps companies sell to the government

    30 April 2026

    BCI startup Neurable wants to license ‘mind reading’ technology to wearable consumer devices

    29 April 2026

    Founder of Shark Tank-backed startup Sholly sues buyer Sallie Mae

    29 April 2026
  • Transportation

    Ouster’s new color lidar is coming to replace cameras

    4 May 2026

    TechCrunch Mobility: How do you ticket a robotaxi?

    4 May 2026

    Uber taps Hertz to clean, charge and fix Lucid Motors’ robotaxi

    3 May 2026

    Uber wants to turn its millions of drivers into a sensor network for self-driving companies

    2 May 2026

    Google’s Gemini AI assistant hits the road in millions of vehicles

    2 May 2026
  • Venture

    Nicolas Sauvage bets on the boring parts of AI

    4 May 2026

    Musely secures $360 million from General Catalyst without giving up equity

    2 May 2026

    The climate tech IPO window could finally open

    30 April 2026

    Sources: Anthropic Could Raise New $50B Round at $900B Valuation

    30 April 2026

    BMW i Ventures Has a New $300M Fund and AI Rides Shotgun

    29 April 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»A breach of Gravy Analytics’ vast trove of location data threatens the privacy of millions
Security

A breach of Gravy Analytics’ vast trove of location data threatens the privacy of millions

techtost.comBy techtost.com13 January 202507 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
A Breach Of Gravy Analytics' Vast Trove Of Location Data
Share
Facebook Twitter LinkedIn Pinterest Email

An intrusion and data breach at location data broker Gravy Analytics threatens the privacy of millions of people around the world whose smartphone apps inadvertently exposed location data collected by the data giant.

The full scale of the data breach is not yet known, but the alleged hacker has already released a large sample of location data from top consumer phone apps — including fitness and health, dating and transit apps, as well as popular games. The data represents tens of millions of location data points where people have been, live, work and travel to each other.

News of the breach broke last weekend when a hacker posted snapshots of location data on a closed Russian cybercrime forum, claiming to have stolen several terabytes of consumer data from Gravy Analytics. Independent news outlet 404 Media first reported the forum post alleging the apparent breach, which it claimed involved the historical location data of millions of smartphones.

Norwegian broadcaster NRK reported on January 11 that Unacast, the parent company of Gravy Analytics, disclosed the breach with the data protection authorities of the country as required by its law.

Unacast, founded in Norway in 2004, merged with Gravy Analytics in 2023 to create what was touted at the time as “one of the largest” collections of consumer location data. Gravy Analytics claims to monitor more than a billion devices worldwide every day.

In data breach notification filed in Norway, Unacast said it detected on Jan. 4 that a hacker obtained files from Amazon’s cloud environment through an “abused key.” Unacast said it was made aware of the breach by contacting the hacker, but the company did not elaborate. The company said its operations were briefly taken offline after the breach.

Unacast said in the release that it has also informed UK data protection authorities about the breach. Lucy Milburn, a spokeswoman for the UK’s Information Commissioner’s Office, confirmed to TechCrunch that the ICO “received a report from Gravy Analytics and is investigating.”

Unacast executives Jeff White and Thomas Walle did not return multiple emails from TechCrunch this week seeking comment. In a statement that is not attributed from a generic Gravy Analytics email account sent to TechCrunch On Sunday, Unacast acknowledged the breach, saying “its investigation remains ongoing.”

The Gravy Analytics website was still down at the time of writing. Several other domains related to Gravy Analytics also appeared to be down, according to checks by TechCrunch last week.

So far 30 million location data points have been leaked

Data privacy advocates have long warned about the risks that data brokers pose to individuals’ privacy and national security. Researchers with access to the sample Gravy Analytics location data released by the hacker say the information can be used to extensively track people’s recent locations.

Baptiste Robert, CEO of digital security firm Predicta Lab, which obtained a copy of the leaked data, said in a thread in X that the dataset contained more than 30 million location data points. These included devices located in the White House in Washington, DC. the Kremlin in Moscow; Vatican City? and military bases around the world. One of the maps that Robert shared showed the location data of Tinder users across the UK. In another postRobert demonstrated that it was possible to identify individuals who likely served as military personnel by overlaying the stolen location data with the locations of known Russian military installations.

A map showing Tinder users located across the UK.Image Credits:Baptiste Robert / X

Robert cautioned that the data also allows for easy de-anonymization of individuals. In one example, the data tracked a person as he traveled from New York to his home in Tennessee. Forbes reported on the risks which has the data set for LGBTQ+ users, whose location data from certain apps could identify them in countries that criminalize homosexuality.

News of the breach comes weeks after the Federal Trade Commission banned Gravy Analytics and its subsidiary Venntel, which provides location data to government agencies and law enforcement, from collecting and selling Americans’ location data without consumer consent. The FTC accused the company of illegally tracking millions of people in sensitive locations such as health care clinics and military bases.

Location data used by ad networks

Gravy Analytics sources much of its location data a process called real-time biddinga key part of the online advertising industry that determines during a short millisecond auction which advertiser can deliver their ad to your device.

During this near-instant auction, all bidding advertisers can see certain information about your device, such as the manufacturer and model type, its IP addresses (which can be used to infer the proximity to a person’s location) and, in some cases, more precise location data if provided by the application user, along with other technical factors that help determine which ad a user will be shown.

However, as a byproduct of this process, any advertiser who bids—or anyone closely monitoring those auctions—can also access this trove of so-called “bid stream” data that contains device information. Data brokers, including those who sell to governments, can combine this collected information with other data about those individuals from other sources to paint a detailed picture of someone’s life and where they live.

Analyzes of location data by security researchers, including Robert of Predicta Labreveal thousands of ad serving apps have shared, often unknowingly, bid flow data with data brokers.

The dataset contains data sourced from popular Android and iPhone apps, including FlightRadar, Grindr and Tinder — all of which have disclaimed any direct business links to Gravy Analytics, but have acknowledged ad serving. However, due to the nature of how the advertising industry operates, it is also possible for ad-serving apps to collect their users’ data without their explicit knowledge or consent.

As noted by 404 Mediait’s unclear how Gravy Analytics sourced its massive amounts of location data, such as whether the company collected the data itself or from other data brokers. 404 Media found that large amounts of location data were inferred from the device owner’s IP address, which is geo-located to approximate their actual location, rather than relying on the device owner allowing the app to access their exact GPS coordinates device.

What you can do to prevent ad tracking

Per digital rights group Electronic Frontier FoundationAd auctions happen on almost every website, but there are steps you can take to protect yourself from ad tracking.

Using an ad blocker — or content blocker at the mobile level — can be an effective defense against ad tracking by blocking ad code on websites from loading in the user’s browser in the first place.

Android devices and iPhones also have device-level features that make it harder for advertisers to track you across apps or on the web, and link your device’s pseudonymous data to your real-world identity. The EFF also has one good guide how to check these device settings.

If you have an Apple device, you can go to the Tracking options in your Settings and turn off the setting to track application requests. This resets your device’s unique identifier, making it indistinguishable from anyone else’s.

“If you turn off app tracking, your data isn’t shared,” Robert told TechCrunch.

Android users should go to the “Privacy” and then “Ads” section of their phone’s settings. If the option is available, you can delete the advertising ID to prevent any app on your phone from accessing your unique device ID in the future. Those without this setting should reset their advertising IDs regularly.

Preventing apps from accessing your exact location when not required will also help reduce your data footprint.

Updated with comment from the ICO.

Contact Zack Whittaker securely on Signal and WhatsApp at +1 646-755-8849. You can also share documents securely with TechCrunch through SecureDrop.

Analytics breach cyber attack cyber security data data broker data privacy Gravy Location millions mobile location data our government privacy threatens trove Vast
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFloat Financial, which aims to be Canada’s Brex, raises $48.5M Series B
Next Article Xiaohongshu, China’s answer to Instagram, hits no. 1 on the App Store as TikTok faces shutdown in the US
bhanuprakash.cg
techtost.com
  • Website

Related Posts

The US government is warning of a serious CopyFail bug affecting major versions of Linux

5 May 2026

Hackers are still exploiting the cPanel bug to gain control of thousands of websites

4 May 2026

OpenAI announces new advanced security for ChatGPT accounts, including a partnership with Yubico

3 May 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Coinbase to lay off 14% of staff as part of broader restructuring

5 May 2026

The US government is warning of a serious CopyFail bug affecting major versions of Linux

5 May 2026

OpenAI host Cerebras is on track for a major IPO

5 May 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Stripe introduces Link, a digital wallet that autonomous AI agents can also use

1 May 2026

Y Combinator alum Skio sells for $105 million in cash, raised only $8 million, founder says

1 May 2026

Amazon, Meta join the fight to end Google Pay and PhonePe’s dominance in India

30 April 2026
Startups

FDA Approval, Fundraising and the Reality of Building Healthcare According to BioticsAI Founder

Legal AI startup Legora hits $5.6 billion valuation, and its battle with Harvey just got hotter

Bill Gurley, Jack Altman back startup Pursuit, which helps companies sell to the government

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.