We review vendors based on rigorous testing and research but also take into account your feedback and our affiliate commission with providers. Some providers are owned by our parent company.
Learn more
vpnMentor was established in 2014 to review VPN services and cover privacy-related stories. Today, our team of hundreds of cybersecurity researchers, writers, and editors continues to help readers fight for their online freedom in partnership with Kape Technologies PLC, which also owns the following products: Holiday.com, ExpressVPN, CyberGhost, and Private Internet Access which may be ranked and reviewed on this website. The reviews published on vpnMentor are believed to be accurate as of the date of each article, and written according to our strict reviewing standards that prioritize professional and honest examination of the reviewer, taking into account the technical capabilities and qualities of the product together with its commercial value for users. The rankings and reviews we publish may also take into consideration the common ownership mentioned above, and affiliate commissions we earn for purchases through links on our website. We do not review all VPN providers and information is believed to be accurate as of the date of each article.
Advertising Disclosure

vpnMentor was established in 2014 to review VPN services and cover privacy-related stories. Today, our team of hundreds of cybersecurity researchers, writers, and editors continues to help readers fight for their online freedom in partnership with Kape Technologies PLC, which also owns the following products: Holiday.com, ExpressVPN, CyberGhost, and Private Internet Access which may be ranked and reviewed on this website. The reviews published on vpnMentor are believed to be accurate as of the date of each article, and written according to our strict reviewing standards that prioritize professional and honest examination of the reviewer, taking into account the technical capabilities and qualities of the product together with its commercial value for users. The rankings and reviews we publish may also take into consideration the common ownership mentioned above, and affiliate commissions we earn for purchases through links on our website. We do not review all VPN providers and information is believed to be accurate as of the date of each article.

Data Broker Breach Exposes the Location Data of Millions

Data Broker Breach Exposes the Location Data of Millions
Husain Parvez Published on 16th January 2025 Cybersecurity Researcher

A major data breach has compromised Gravy Analytics — a company that collects and sells smartphone location data — potentially exposing millions of users. Hackers claim to have stolen over 17 terabytes of sensitive data, including customer lists, industry insights, and precise location data of individuals' movements.

The breach, first reported by 404 Media, has raised serious privacy concerns, as experts warn that the leaked information could be used for tracking, surveillance, and de-anonymization of users worldwide.

The hackers posted samples of the stolen data on a Russian cybercrime forum, claiming to have accessed Gravy Analytics’ cloud storage through a misappropriated Amazon Web Services (AWS) key. As reported by TechCrunch, the leaked data allegedly includes over 30 million location points linked to widely used apps such as Tinder, Candy Crush, MyFitnessPal, and Flightradar24.

Gravy Analytics and its subsidiary Venntel have previously sold location data to US government agencies, including the FBI, IRS, and Department of Homeland Security, according to NBC News. The Federal Trade Commission (FTC) had already banned Gravy Analytics and Venntel, accusing them of illegally collecting and selling location data without user consent.

Privacy advocates have long warned about the risks of data brokers operating without strict oversight. Cybersecurity expert Zach Edwards described the breach as the “nightmare scenario” that privacy advocates feared, telling 404 Media that the exposure of location data could seriously endanger high-risk individuals and organizations.

Following the breach, Gravy Analytics’ website went offline, and its parent company, Unacast, notified Norwegian and UK data protection authorities. Security researchers examining the leaked data confirmed that it contained sensitive locations, such as government buildings, military bases, and high-profile landmarks.

WIRED reported that the stolen dataset likely originated from the real-time bidding (RTB) advertising ecosystem, where advertisers bid to place ads inside apps. This process accidentally exposes user location data to brokers, often without app developers' direct knowledge.

Privacy experts warn that this breach highlights the dangers of mass location tracking and the lack of strict data protection laws in the US.

Security professionals advise users to disable unnecessary location tracking, use ad blockers, and reset advertising IDs regularly to reduce their exposure. With the stolen data now circulating, millions of users face serious privacy risks. This adds to broader concerns about data security, with 97% of top US retailers also experiencing data breaches last year.

About the Author

Husain Parvez is a Cybersecurity Researcher and News Writer at vpnMentor, focusing on VPN reviews, detailed how-to guides, and hands-on tutorials. Husain is also a part of the vpnMentor Cybersecurity News bulletin and loves covering the latest events in cyberspace and data privacy.

Please, comment on how to improve this article. Your feedback matters!

Leave a comment

Sorry, links are not allowed in this field!

Name should contain at least 3 letters

The field content should not exceed 80 letters

Sorry, links are not allowed in this field!

Please enter a valid email address