Unacast tells Norwegian regulator hackers took Gravy Analytics location data

Organization
Unacast
Exploit
Credential Compromise
Industry
Technology

Unacast, the Norwegian owner of United States location data broker Gravy Analytics, notified Norway's data protection authority in January 2025 that an intruder had removed files from its Amazon Web Services environment. The filing, published by broadcaster NRK and reported on January 10, said the company learned of the incident on January 4 when the attacker contacted it directly, and that access was obtained using a misappropriated key.

Gravy Analytics collected historical location records from mobile devices and claimed to track more than a billion of them each day. TechCrunch reported that more than 30 million location data points had been published by January 13, and that researchers tracing the samples found they originated from thousands of ad supported apps across the fitness, dating, gaming and transit categories, including Tinder, Grindr, Candy Crush and FlightRadar.

The records appeared to have been gathered through the real time advertising bidstream rather than from code app developers knowingly embedded. Researchers examining the leaked samples mapped device movements around sensitive sites including government buildings and military installations.

Unacast said the contents of the copied files, and whether they contained personal data, remained under investigation. It said the cloud environment had been secured, and it notified data protection regulators in both Norway and the United Kingdom. The company did not respond to press requests for further comment.

The breach came weeks after the US Federal Trade Commission announced an enforcement action and a proposed order against Gravy Analytics and its subsidiary Venntel on December 3, 2024, over the collection and sale of sensitive location data without consumer consent. The FTC finalized that order on January 14, 2025, after the breach.

Sources