Tracelo phone tracking service breach exposed 1.4 million customers and targets
- Organization
- Tracelo
- Exploit
- Hacking
- Industry
- Location Tracking Service
Tracelo, a commercial service that claims to locate a smartphone from its number alone, was breached on 1 September 2024. A user of the BreachForums cybercrime forum operating under the alias Satanic posted roughly 264 MB of data said to have come from the service, covering 1,459,014 records.
The dump was reported to consist of three database exports. One held details of more than 646,000 people whose phones had been looked up through the service. The other two held registered account records for more than 800,000 Tracelo customers. Actual location results were not included in the leaked files.
Fields in the records reportedly included full names, phone numbers, email addresses, physical addresses, bcrypt password hashes, Google account identifiers, subscription type, mobile carrier, time zone and platform data. Because the product exists to track other people, the exposure named both the paying users and the individuals they had searched for. Reporting on the leak questioned Tracelo's consent model, noting that permission was sought through a single SMS message that could be circumvented.
eSecurity Planet reported that the activity was noticed through unusual server behaviour and that an investigation followed. No public statement from Tracelo, no regulatory filing and no notification programme for affected people were identified in coverage of the incident, and the record counts remained the leaker's claims rather than figures confirmed by the company.