Location Tracking Life360 App Consumer Data is Leaked Online

December 6, 2024

INCIDENT

A threat actor has leaked a database containing the personal information of 442,519 Life360 customers collected by abusing a flaw in the login API. Life360 is a family networking app designed to provide location and safety services.

Known only by their 'emo' handle, they said the unsecured API endpoint used to steal the data provided an easy way to verify each impacted user's email address, name, and phone number. "When attempting to login to a life360 account on Android the login endpoint would return the first name and phone number of the user, this existed only in the API response and was not visible to the user," emo said.

Life360 did not disclose how the threat actor breached its platform, but the company stated that it had taken steps to protect its systems from further attack.

Incident Date

March 15, 2024

Location

Estimated Cost

data leaked online, cost unknown

Victims

Type of Malware

No Malware identified

Threat Source

No threat source identified