Angerman 🦅<p>Oh… <a href="https://infosec.exchange/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a> where.. oh, wait .. 🥹</p><p>Massive breach at <a href="https://infosec.exchange/tags/location" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>location</span></a> data seller: “Millions” of users affected</p><p>Like many other <a href="https://infosec.exchange/tags/data" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>data</span></a> <a href="https://infosec.exchange/tags/brokers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>brokers</span></a>, <a href="https://infosec.exchange/tags/Gravy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Gravy</span></a> is a company you may never have heard of, but it almost certainly knows a lot about you if you’re a <a href="https://infosec.exchange/tags/US" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>US</span></a> <a href="https://infosec.exchange/tags/citizen" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>citizen</span></a>.</p><p>Gravy Analytics specializes in location intelligence, meaning it collects <a href="https://infosec.exchange/tags/sensitive" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sensitive</span></a> <a href="https://infosec.exchange/tags/phone" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>phone</span></a> location and <a href="https://infosec.exchange/tags/behavior" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>behavior</span></a> data.</p><p>One of the buyers is the US <a href="https://infosec.exchange/tags/government" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>government</span></a> who increasingly circumvents the need to get a <a href="https://infosec.exchange/tags/warrant" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>warrant</span></a> by simply buying what they want to know from a data broker. Ironic, given that the <a href="https://infosec.exchange/tags/FTC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FTC</span></a> sued Gravy Analytics after saying it routinely collects sensitive phone location and behavior data without getting the <a href="https://infosec.exchange/tags/consent" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>consent</span></a> of <a href="https://infosec.exchange/tags/consumers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>consumers</span></a>.</p><p>And now, apparently, it’s Gravy Analytics’ turn to be <a href="https://infosec.exchange/tags/breached" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>breached</span></a>. According to 404 Media, <a href="https://infosec.exchange/tags/cybercriminals" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybercriminals</span></a> breached Gravy Analytics and stole a massive amount of data, including customer lists, information on the broader industry, and location data harvested from <a href="https://infosec.exchange/tags/smartphones" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>smartphones</span></a> which show peoples’ precise <a href="https://infosec.exchange/tags/movements" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>movements</span></a>.</p><p>The cybercriminals claim to have stolen 17TB of data and are threatening to publish the data. Considering the sensitivity of location data for some groups, this breach could potentially be just as significant as the National Public Data leak.</p><p>The whole ordeal, whether the data will be published or not, proves once again why data brokers should stop trading health and location data. 📊 </p><p>More: <a href="https://www.malwarebytes.com/blog/news/2025/01/massive-breach-at-location-data-seller-millions-of-users-affected" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">malwarebytes.com/blog/news/202</span><span class="invisible">5/01/massive-breach-at-location-data-seller-millions-of-users-affected</span></a></p>