Law and Government

Massive Data Leak: Millions of Phone Location Records Exposed


A recent lawsuit against Gravy Analytics highlights serious concerns about data protection and the safety of personal information held by private companies. This legal action, initiated in federal court in Northern California, alleges that Gravy Analytics failed to implement adequate safeguards for vast amounts of personal data, potentially leading to significant privacy breaches. The case is just one of four lawsuits filed since early January 2025, following a major hack that reportedly compromised an astonishing 17TB of records from the data broker’s storage.

Table of Contents

Insufficient data protection

The lawsuit argues that Gravy Analytics had a fundamental responsibility to safeguard the data it collected and stored. By allegedly failing to do so, the firm has exposed millions of individuals to an increased risk of identity theft. As reported by The Register, this latest complaint reveals that the hacked data includes tens of millions of mobile phone coordinates collected from users of major applications such as Tinder, Grindr, and Candy Crush.

The initial breach was noted in early January 2025, when a hacker threatened to release sensitive location data, customer lists, and personal information extracted from Gravy Analytics. The fallout from this incident has been severe, leading the FTC to ban Gravy Analytics, along with its subsidiary Venntel, from selling confidential location data. The FTC’s allegations assert that both entities violated the FTC Act by unfairly marketing consumer location data and harvesting it without verifiable consent.

This situation highlights the extensive risks associated with the collection of personal information by data brokers, particularly as the industry operates in a largely unregulated environment in the United States. Consequently, essential privacy protections, such as those mandated by GDPR, are not applicable.

The precise circumstances surrounding the breach remain unclear; however, cybersecurity experts emphasize the importance of preparation against potential attacks. Pierre Noel, Field CISO EMEA at Expel, states, “The solutions to prevent a major security incident are well known—adequate protection, detection, and swift incident response.” He further notes that a prevailing human bias leads many to believe cyberattacks only target others, not themselves.

Take control of your data

For regular internet users, it’s increasingly probable that personal details have fallen into the hands of third parties. Whether through permissions granted to apps, involvement in a data breach, or lawful sales to brokers, consumers often find their information compromised.

Data Privacy Day serves as a crucial reminder of the need to protect sensitive information in an age dominated by digital data. Dr. Ellison Anne Williams, CEO and founder of Enveil, emphasizes the significance of safeguarding data privacy alongside the rapidly evolving digital landscape and innovative technologies like AI.

In response to these challenges, a burgeoning market for personal data removal services has emerged. These services offer practical solutions for individuals and organizations seeking to mitigate risks by eliminating their information from data brokers. For those under GDPR protection in the EU or UK who wish to eradicate their online presence, several strategies can be effective.

Key tips include:

  • Delete social media accounts: Social platforms often collect extensive user data. Eliminating accounts can significantly enhance personal privacy.
  • Review other accounts: Online shopping or dating profiles may also monitor user behavior. A thorough examination of old accounts can help identify and delete those sharing personal data.
  • Utilize a VPN: Employing a Virtual Private Network encrypts internet traffic, safeguarding browsing history and concealing IP addresses to prevent unauthorized location tracking.

To facilitate your efforts in maintaining online privacy, consider reviewing the best VPN services available, which can provide enhanced security and anonymity online.

You might also like

Leave a comment

Leave a Reply

Related Articles

Law and Government

Trump Urged by US Lawmakers to Address UK iCloud Security Concerns

US lawmakers press Trump to tackle urgent UK iCloud security issues for...

Law and Government

Elon Musk’s Efficiency Department Faces Major Privacy Lawsuit

Elon Musk's efficiency initiative is under fire from a significant privacy lawsuit.

Law and Government

Meta’s AI: Over 80TB of Pirated Content Fuels Open-Source Llama

Meta's AI harnesses 80TB of pirated data to enhance the capabilities of...

Law and Government

Larry Ellison’s Bold Vision: Uniting America’s Data & DNA

Larry Ellison envisions a future where data and DNA seamlessly converge for...