Technology
Hackers claim massive breach of company that tracks and sells Americans' location data
When we talk about data privacy, tech giants like Google and Facebook are often blamed for using personal data to show ads and recommendations. Less discussed are the businesses whose entire business model revolves around collecting your data and selling it to other companies and governments. These companies often operate in legal gray areas, with the consent required to collect user data buried deep in the fine print.
What’s even more concerning is that these data brokers fail to adequately protect the data they collect. Last year, National Public Data made headlines for failing to secure 2.7 billion records of individuals whose data it had harvested. Now, hackers have reportedly stolen data from Gravy Analytics, the parent company of Venntel, which has sold vast amounts of smartphone location data to the U.S. government.
I’M GIVING AWAY THE LATEST & GREATEST AIRPODS PRO 2
Enter the giveaway by signing up for my free newsletter.
What you need to know about the breach
Hackers claim to have breached Gravy Analytics, a major location data broker and parent company of Venntel, a firm known for selling smartphone location data to U.S. government agencies. The compromise is massive, including sensitive location data that tracks precise smartphone movements, customer information and even internal infrastructure, according to a 404 Media report.
The hackers are threatening to make the stolen data public. The files contain precise latitude and longitude coordinates of the phone and the time at which the phone was there. Some even indicate what country the data has been collected from.
Hackers have claimed access to Gravy’s systems since 2018. If true, this represents a serious security lapse on the company’s part. It is baffling how companies that collect and sell user data (a practice that arguably shouldn’t be allowed in the first place) failed to protect it from being leaked.
404 Media also suggests that the hackers gained deep access to the company’s infrastructure, including Amazon S3 buckets and server root access. The exposed customer list reportedly includes major companies like Uber, Apple and Equifax as well as government contractors like Babel Street.
HERE’S WHAT RUTHLESS HACKERS STOLE FROM 110 MILLION AT&T CUSTOMERS
What this breach means for people
This data breach highlights the serious security flaws in the location data industry. Companies like Gravy Analytics and Venntel have been profiting from collecting and selling sensitive location data, often without proper user consent. They’ve prioritized profit over security, and now the privacy of millions is at risk. This data could end up on black markets, endangering individuals, especially those in vulnerable situations, by making them targets for harassment or worse.
The FTC’s recent crackdown on Gravy, announced in December, underscores their negligence. The proposed order will prohibit these companies from selling or using location data, except in specific cases like national security or law enforcement. The implications are worrying. Sensitive locations like schools and workplaces could become easy targets for those with malicious intent.
BEWARE OF ENCRYPTED PDFs AS THE LATEST TRICK TO DELIVER MALWARE TO YOU
5 ways to stay safe in the age of data breaches
The Gravy Analytics breach serves as a sobering reminder of the vulnerabilities in the digital age. While it’s impossible to control how every company handles data, you can take steps to minimize your exposure and protect your privacy. Here are five actionable tips to stay safe.
1) Limit app permissions: Many apps request access to location data, contacts and more, even when it’s not necessary for their functionality. Regularly review the permissions for apps on your smartphone and revoke access to anything that feels excessive. For instance, a weather app doesn’t need access to your microphone or camera.
2) Use a VPN: Virtual private networks (VPNs) can mask your IP address and encrypt your internet activity, making it harder for data brokers and hackers to track your online behavior. A good VPN adds an extra layer of security, especially when using public Wi-Fi networks. For the best VPN software, see my expert review of the best VPNs for browsing the web privately on your Windows, Mac, Android and iOS devices.
3) Opt out of data sharing where possible: Some companies allow you to opt out of having your data collected or shared. Services like Your Ad Choices and privacy settings within platforms like Google can help you reduce the amount of data collected. Check for opt-out options with any apps or services you use frequently.
4) Avoid free apps that monetize data: Free apps often generate revenue by selling user data. Instead, consider paid versions of apps that explicitly prioritize privacy. Research the company behind the app to understand its data handling policies before downloading.
5) Invest in data removal services: Data removal services can help you regain some control over your personal information by identifying and removing it from people-search websites, data broker platforms and other online databases. Check out my top picks for data removal services here.
WHAT TO DO IF YOUR BANK ACCOUNT IS HACKED
Kurt’s key takeaway
Companies that collect and sell user data pose a significant threat to privacy, and when they fail to protect this data, it often ends up in the hands of even worse actors. Cybercriminals, and even some governments, can exploit this information to target individuals. It is crucial to implement stringent repercussions for these companies when they fail in their duty to safeguard user data. A mere slap on the wrist is not enough. We need real accountability to deter negligence and protect individual privacy rights.
Should companies face stronger penalties for failing to protect personal data? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.
Ask Kurt a question or let us know what stories you’d like us to cover.
Follow Kurt on his social channels:
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2024 CyberGuy.com. All rights reserved.
Technology
Trump touts his plan to save TikTok during his victory rally
And as of today, TikTok is back. So, you know, I did a little TikTok thing we have a guy, TikTok Jack he’s a young kid, like 21 years old. And we hired this guy, and I went on TikTok; can you believe what I’ll do to win an election?And we went on TikTok and Republicans have never won the young vote, the youth vote. They win a lot of votes, but they never won the youth vote. We won the youth vote by 36 points. So I like TikTok. I like it. I had a slightly good experience wouldn’t you say?
Romney lost it by 40 points not so long ago. We won it by 36 points. That’s a very big spread.But I said, we need to save TikTok, because we’re talking about a tremendous — who, who in this audience goes with TikTok? Many? Yeah, very popular. And frankly, we have no choice, we have to save it — a lot of jobs. We don’t wanna give our business to China, we don’t wanna give our business to other people. And I said, you know, TikTok without my approval — meaning the president’s approval because Congress gave the president the right to make a deal to whatever he wants and uh… they did that a long time ago when they have a different president. They didn’t know that I was gonna be at the president, I guess.
So I said very simply, a joint venture. So, if TikTok is worth nothing, zero without an approval, you know you don’t approve, they’re out of business, they’re worth nothing.
If you do approve, they’re worth like a trillion dollars, they’re worth some crazy number. So I said, I’ll approve, but let the United States of America own 50% of TikTok.I’m approving on behalf of the United States.
So they’ll have a partner, the United States, and they’ll have a lot of bidders and the United States will do what we call a joint venture. And there’s no risk, we’re not putting up any money. All we’re doing is giving them the approval without which they don’t have anything. So, I don’t know, it sounds like that works. What do you think, good? So, whether you like TikTok or not, we’re gonna make a lot of money.
Technology
Instagram announces a blatant CapCut clone
Edits is more than a video editing app; it’s a full suite of creative tools. There will be a dedicated tab for inspiration, another for keeping track of early ideas, a much higher-quality camera (which I used to record this video), all the editing tools you’d expect, the ability to share drafts with friends and other creators, and — if you decide to share your videos on Instagram — powerful insights into how those videos perform.
Technology
How to stop robocalls on your flip phone
Robocalls can be a real headache, no matter what type of phone you use. If you’re like many people who prefer the simplicity of a flip phone, you might be wondering how to tackle this issue.
Donna reached out to us with a simple but great question, asking, “Is there a way to eliminate robocalls from a flip phone?”
We’ve reported extensively on how to stop spam calls from coming to your smartphone, but what if you don’t like using a smartphone and prefer a flip phone? While flip phones are generally harder to block spam calls from, it’s not impossible, but it’s not as easy as dealing with robocalls on your smartphone.
I’M GIVING AWAY THE LATEST & GREATEST AIRPODS PRO 2
WHAT IS ARTIFICIAL INTELLIGENCE (AI)?
How to deal with robocalls on a flip phone
Dealing with robocalls on a flip phone can be challenging, but you can take a few steps to minimize them. You’ll have to make some phone calls, so it won’t be as simple as blocking spam callers on a smartphone. But if you’re willing to place a few phone calls and do some extra work, you can live happily without spam calls on your flip phone. Here are the steps you can take:
1. Avoid answering unknown numbers: If you don’t recognize the number, let it go to voicemail. Legitimate callers will leave a message.
2. Be cautious with your number: Be mindful of where you share your phone number to reduce the chances of it being added to robocall lists.
3. Register on the Do Not Call List: Register your phone number on the National Do Not Call Registry. This can help reduce the number of legitimate telemarketing calls you receive. You can register a phone number with the National Do Not Call Registry online at donotcall.gov or by calling 1-888-382-1222 from the phone you want to be registered with the Do Not Call Registry.
AN ALARMING SPIKE IN SCAM CALLS COMING FROM ROBOCALLS
4. Contact your carrier: Many carriers offer call-blocking services. Contact your carrier (e.g., Verizon, AT&T, T-Mobile) and ask if they provide robocall-blocking features for flip phones. Many carriers do, but it depends on the brand of flip phone you have and which carrier you have.
5. Manual call blocking: If your flip phone has the option, you can manually block specific numbers. Check your phone’s user manual for instructions on how to do this. While this feature is common with all smartphones, many newer flip phones can also manually block callers, but, as we mentioned, you’ll need to check your instruction manual.
END OF ANNOYING ROBOCALLS? FTC CRACKS DOWN ON DECEPTIVE PRACTICES
6. Report robocalls to the FTC: Report unwanted calls to the Federal Trade Commission (FTC). This helps authorities track and take action against robocalls. While this method doesn’t block robocalls from calling your flip phone, it does help the FTC locate robocalls and prevent them from calling. It’s a good way to help the FTC fight back against robo-spam callers. Here’s what you need to do to report a robocall to the FTC:
- Go online at ReportFraud.ftc.gov or call 1-877-382-4357.
- When filling out your report, you’ll need the robocaller’s number and the date and time of the call.
7. Consider using a data removal service: Regrettably, there is a high probability that your phone number is readily available on many lists sold by data brokers to hundreds of people search websites. However, removing it from the web can reduce the likelihood of spammers and telemarketers obtaining your number and contacting you.
While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time. Check out my top picks for data removal services here.
Kurt’s key takeaways
Robocalls can be a real nuisance, especially for flip phone users. To tackle this issue, consider registering your number on the National Do Not Call List and avoid answering unknown numbers. Additionally, check with your carrier for any call-blocking services it may offer. With a few proactive steps, you can significantly reduce those pesky interruptions.
What do you find most frustrating about robocalls, and how do you typically handle them? Let us know by writing us at Cyberguy.com/Contact
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter
Ask Kurt a question or let us know what stories you’d like us to cover
Follow Kurt on his social channels
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.
-
Science1 week ago
Metro will offer free rides in L.A. through Sunday due to fires
-
Technology1 week ago
Amazon Prime will shut down its clothing try-on program
-
Technology1 week ago
L’Oréal’s new skincare gadget told me I should try retinol
-
Technology4 days ago
Super Bowl LIX will stream for free on Tubi
-
Business6 days ago
Why TikTok Users Are Downloading ‘Red Note,’ the Chinese App
-
Technology2 days ago
Nintendo omits original Donkey Kong Country Returns team from the remaster’s credits
-
Politics1 week ago
Trump to be sentenced in New York criminal trial
-
Culture2 days ago
American men can’t win Olympic cross-country skiing medals — or can they?