Angerman 🦅<p>Oh… <a href="https://infosec.exchange/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> where.. oh, wait .. 🥹</p><p>Massive breach at <a href="https://infosec.exchange/tags/location" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>location</span></a> data seller: “Millions” of users affected</p><p>Like many other <a href="https://infosec.exchange/tags/data" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>data</span></a> <a href="https://infosec.exchange/tags/brokers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>brokers</span></a>, <a href="https://infosec.exchange/tags/Gravy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Gravy</span></a> is a company you may never have heard of, but it almost certainly knows a lot about you if you’re a <a href="https://infosec.exchange/tags/US" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>US</span></a> <a href="https://infosec.exchange/tags/citizen" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>citizen</span></a>.</p><p>Gravy Analytics specializes in location intelligence, meaning it collects <a href="https://infosec.exchange/tags/sensitive" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sensitive</span></a> <a href="https://infosec.exchange/tags/phone" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>phone</span></a> location and <a href="https://infosec.exchange/tags/behavior" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>behavior</span></a> data.</p><p>One of the buyers is the US <a href="https://infosec.exchange/tags/government" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>government</span></a> who increasingly circumvents the need to get a <a href="https://infosec.exchange/tags/warrant" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>warrant</span></a> by simply buying what they want to know from a data broker. Ironic, given that the <a href="https://infosec.exchange/tags/FTC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FTC</span></a> sued Gravy Analytics after saying it routinely collects sensitive phone location and behavior data without getting the <a href="https://infosec.exchange/tags/consent" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>consent</span></a> of <a href="https://infosec.exchange/tags/consumers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>consumers</span></a>.</p><p>And now, apparently, it’s Gravy Analytics’ turn to be <a href="https://infosec.exchange/tags/breached" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>breached</span></a>. According to 404 Media, <a href="https://infosec.exchange/tags/cybercriminals" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybercriminals</span></a> breached Gravy Analytics and stole a massive amount of data, including customer lists, information on the broader industry, and location data harvested from <a href="https://infosec.exchange/tags/smartphones" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>smartphones</span></a> which show peoples’ precise <a href="https://infosec.exchange/tags/movements" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>movements</span></a>.</p><p>The cybercriminals claim to have stolen 17TB of data and are threatening to publish the data. Considering the sensitivity of location data for some groups, this breach could potentially be just as significant as the National Public Data leak.</p><p>The whole ordeal, whether the data will be published or not, proves once again why data brokers should stop trading health and location data. 📊 </p><p>More: <a href="https://www.malwarebytes.com/blog/news/2025/01/massive-breach-at-location-data-seller-millions-of-users-affected" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">malwarebytes.com/blog/news/202</span><span class="invisible">5/01/massive-breach-at-location-data-seller-millions-of-users-affected</span></a></p>