{"id":46434,"date":"2025-01-14T14:55:08","date_gmt":"2025-01-14T19:55:08","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=46434"},"modified":"2025-01-14T14:55:51","modified_gmt":"2025-01-14T19:55:51","slug":"gravy-analytics-hacked","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2025\/01\/14\/gravy-analytics-hacked\/","title":{"rendered":"Gravy Analytics Hacked"},"content":{"rendered":"<p><a href=\"https:\/\/www.404media.co\/hackers-claim-massive-breach-of-location-data-giant-threaten-to-leak-data\/\">Joseph Cox<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.404media.co\/hackers-claim-massive-breach-of-location-data-giant-threaten-to-leak-data\/\">\n<p>Hackers claim to have compromised Gravy Analytics, the parent company of Venntel which has sold masses of smartphone location data to the U.S. government.  The hackers said they have stolen a massive amount of data, including customer lists, information on the broader industry, and even location data harvested from smartphones which show peoples&rsquo; precise movements, and they are threatening to publish the data publicly.<\/p>\n<p>[&#8230;]<\/p>\n<p>The thousands of apps, <a href=\"https:\/\/www.404media.co\/hackers-claim-massive-breach-of-location-data-giant-threaten-to-leak-data\/\">included in hacked files<\/a> from location data company Gravy Analytics, include everything from games like Candy Crush to dating apps like Tinder, to pregnancy tracking and religious prayer apps across both Android and iOS. Because much of the collection is occurring through the advertising ecosystem &mdash;not code developed by the app creators themselves&mdash; this data collection is likely happening both without users&rsquo; and even app developers&rsquo; knowledge.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/pxlnv.com\/linklog\/gravy-analytics-leaked\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/gravy-analytics-leaked\/\">\n<p>You remember Gravy Analytics, right? It is the one from the <a href=\"https:\/\/pxlnv.com\/linklog\/global-surveillance-babel-street\/\">stories<\/a> and the <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2024\/12\/ftc-takes-action-against-gravy-analytics-venntel-unlawfully-selling-location-data-tracking-consumers\">FTC settlements<\/a>, though it should not be confused with <a href=\"https:\/\/pxlnv.com\/linklog\/us-regulators-data-brokers\/\">all the other ones<\/a>.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.macrumors.com\/2025\/01\/13\/data-broker-hack-iphone-location-info\/\">Juli Clover<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2025\/01\/13\/data-broker-hack-iphone-location-info\/\">\n<p>Gravy Analytics&rsquo; parent company Unacast disclosed the data breach earlier this month [<a href=\"https:\/\/fido.nrk.no\/8a09133d2b14a7e72c31006ef2611b22fd78d7c6bfd7cc62f7d35f13b3c2d338\/Datatilsynet_Unacast_Security%20Incident%20Notification_Redacted.pdf\">PDF<\/a>], and said that its AWS cloud storage environment had been accessed by an unauthorized person using a &ldquo;misappropriated access key.&rdquo;<\/p>\n<p>[&#8230;]<\/p>\n<p>The order required Gravy Analytics to delete all historic location data and any data products developed using data collected from consumers, but it was apparently too late because the company&rsquo;s systems had likely already been breached at the time.<\/p>\n<p>Gravy Analytics collects location data through a real-time ad bidding process that allows companies competing to buy an ad to see customer IP address and more precise location data if enabled.<\/p>\n<p>[&#8230;]<\/p>\n<p>Baptiste Robert, CEO of security firm Predicta Lab, told TechCrunch that  iPhone  users that had app tracking disabled did not have their data shared.<\/p>\n<\/blockquote>\n\n<p>See also: <a href=\"https:\/\/www.schneier.com\/blog\/archives\/2025\/01\/apps-that-are-spying-on-your-location.html\">Bruce Schneier<\/a>:<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/01\/14\/brazil-fines-apple-over-faceapp\/\">Brazil Fines Apple Over FaceApp<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/01\/14\/treasury-department-hacked\/\">Treasury Department Hacked<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/12\/09\/ftc-and-cfpb-reigning-in-data-brokers\/\">FTC and CFPB Reining in Data Brokers<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/01\/31\/nsa-buying-logs-from-data-brokers\/\">NSA Buying Logs From Data Brokers<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/06\/15\/odni-report-on-commercially-available-information\/\">ODNI Report on Commercially Available Information<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/04\/20\/plenty-of-tracking-despite-app-tracking-transparency\/\">Plenty of Tracking Despite App Tracking Transparency<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/04\/15\/more-users-opting-in-to-app-tracking\/\">More Users Opting in to App Tracking<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/08\/28\/governments-buying-phone-location-data\/\">Governments Buying Phone Location Data<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Joseph Cox: Hackers claim to have compromised Gravy Analytics, the parent company of Venntel which has sold masses of smartphone location data to the U.S. government. The hackers said they have stolen a massive amount of data, including customer lists, information on the broader industry, and even location data harvested from smartphones which show peoples&rsquo; [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2025-01-14T19:55:13Z","apple_news_api_id":"b64227ee-059a-44f4-9b8a-bcd0e28b7ceb","apple_news_api_modified_at":"2025-01-14T19:55:53Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAA==","apple_news_api_share_url":"https:\/\/apple.news\/AtkIn7gWaRPSbirzQ4ot86w","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[354,2065,1755,432,31,2586,355],"class_list":["post-46434","post","type-post","status-publish","format-standard","hentry","category-technology","tag-advertising","tag-app-tracking-transparency","tag-breach","tag-gps","tag-ios","tag-ios-18","tag-privacy"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/46434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=46434"}],"version-history":[{"count":2,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/46434\/revisions"}],"predecessor-version":[{"id":46436,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/46434\/revisions\/46436"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=46434"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=46434"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=46434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}