Family Locator App Exposes Location Data of Over 230,000 Users
A poorly secured MongoDB database leaves hundreds of thousands of users' locations, passwords, and personal details open to the public.
A security researcher discovers a major vulnerability in the Australian Family Locator app by ReactApps, exposing the personal data of over 230,000 users. The app leaves its backend MongoDB database completely unsecured, allowing anyone with internet access to view sensitive information. This exposed database contains users' names, email addresses, plaintext passwords, and detailed location histories.
The leaked data includes highly sensitive geofenced locations that users set up to track family members arriving at or leaving places like homes, schools, and workplaces. Because the app stores these exact addresses and lacks basic encryption, malicious hackers easily exploit this information to target families or sell the data on the dark web. The lack of standard security measures turns a helpful family tool into a significant privacy risk.
Accountability poses a major problem following this discovery, as ReactApps provides no contact details and fails to respond to any breach reports. Microsoft Azure ultimately pulls the app offline after TechCrunch attempts to reach the elusive developers. It remains unknown if any malicious actors access the data before the researcher discovers the flaw, highlighting the ongoing need for strict security practices in app development.