Family Tracking App Exposes Real-Time Locations of 280,000 Users

An unprotected database belonging to the Family Locator app leaks sensitive location data, plain text passwords, and photos of hundreds of thousands of users, including children.

A family tracking app called Family Locator exposes the real-time locations and personal details of approximately 280,000 users due to an unsecured MongoDB database. The exposed database contains names, email addresses, plain text passwords, photographs, and precise coordinates labeled with locations like home and office. None of this highly sensitive information is encrypted, making it easily accessible to anyone who discovers the open server.

This data leak poses a severe threat because the application specifically tracks the movements of children, and random strangers potentially have access to this live location information. TechCrunch verifies the severity of the breach by setting up a dummy account and contacting a randomly selected user, who confirms that the exposed coordinates are accurate and that a tracked family member is their child. The app's privacy policy explicitly states that the company does not transfer personally identifiable information to outside parties, making this exposure a massive contradiction of their stated rules.

The incident highlights a recurring and dangerous trend in cybersecurity where basic database security protocols, such as setting a password, are completely ignored. Leaving a database without encryption or access controls represents a fundamental failure to protect vulnerable users who simply want to keep their families safe. As researchers continue to uncover these avoidable flaws, it remains unclear exactly how long this particular database sits open to the public internet before someone notices the massive security oversight.

Read More at the original source →