TechCrunch News 2024年12月19日
Tracker firm Hapn spilling names of thousands of GPS tracking customers
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

GPS追踪公司Hapn因网站漏洞导致数千客户信息泄露,包括客户姓名和工作单位等敏感信息。安全研究人员发现,通过浏览器开发者工具即可访问这些数据。泄露数据涉及超过8600个GPS追踪器,包含设备唯一识别码。虽然不包含位置信息,但客户姓名和单位信息暴露,引发隐私担忧。Hapn公司未对TechCrunch的多次邮件询问做出回应,且其隐私政策中提供的联系方式无效。客户信息在撰写本文时仍处于暴露状态。此次事件源于客户评价中提及使用GPS追踪器监控配偶的行为,进一步揭示了Hapn在数据安全方面的严重疏忽。

⚠️ Hapn公司网站存在漏洞,导致数千客户的姓名和工作单位等敏感信息泄露,暴露了严重的数据安全问题。

📱 泄露的数据包括超过8600个GPS追踪器的设备唯一识别码,虽然不包含位置数据,但客户的身份信息被泄露,引发隐私担忧。

🔍 此次事件源于安全研究人员对客户评价的调查,这些评价显示部分客户使用GPS追踪器监控配偶,反映了Hapn产品被滥用的潜在风险。

📧 Hapn公司对TechCrunch的多次邮件询问未作回应,且隐私政策中提供的联系方式无效,表明该公司在处理安全问题上的消极态度。

GPS tracking firm Hapn is exposing the names of thousands of its customers due to a website bug, TechCrunch has learned.

A security researcher alerted TechCrunch in late November to customer names and affiliations — such as the name of their workplace — spilling from one of Hapn’s servers, which TechCrunch has seen. 

Hapn, formerly known as Spytec, is a tracking company that allows users to remotely monitor the real-time location of internet-enabled tracking devices, which can be attached to vehicles or other equipment. The company also sells GPS trackers to consumers under its Spytec brand, which rely on the Hapn app for tracking. Spytec touts its GPS devices for tracking the locations of valuable possessions, and “loved ones.” According to its website, Hapn claims to track more than 460,000 devices, and counts customers within the Fortune 500.

The bug allows anyone to log in with a Hapn account to view the exposed data using the developer tools in their web browser.

The exposed data contains information on more than 8,600 GPS trackers, including the IMEI numbers for the SIM cards in each tracker, which uniquely identify each device. The exposed data does not include location data, but thousands of records contain the names and business affiliations of customers who own, or are tracked by, the GPS trackers.

Hapn has not responded to multiple emails from TechCrunch. The customer names remain exposed at the time of writing. 

Several emails to Hapn CEO Joe Besdin went unreturned. A message sent to an email address listed on the company’s privacy policy returned with a bounce error, saying that the email address does not exist. The company does not have a webpage or form for reporting security vulnerabilities.

When we contacted individuals whose names and affiliations were listed in the exposed data, several people confirmed their names and workplaces but declined to discuss their use of the GPS tracker. One company listed on Hapn’s website as a corporate customer had several trackers listed in the exposed data, TechCrunch has seen.

The security researcher said they began looking into the GPS tracker after finding that customers had left online reviews for the devices recommending the tracker for monitoring a person’s spouse or partner. (TechCrunch has seen dozens of reviews on Spytec’s online stores from customers who claim to have used the GPS devices to track their spouses.)

The list of exposed customer records also show thousands of trackers with associated names but no other discernible affiliation. It’s not known if the individuals are aware of having been tracked.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Hapn GPS追踪 数据泄露 隐私安全 安全漏洞
相关文章