Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Sword of the Sea Review – Beauty For The Sake Of Beauty

18 August 2025

Is Roblox Getting Worse?

18 August 2025

The End of Handwriting

18 August 2025
Facebook X (Twitter) Instagram
Just In
  • Sword of the Sea Review – Beauty For The Sake Of Beauty
  • Is Roblox Getting Worse?
  • The End of Handwriting
  • Nintendo Is Holding a 45-Minute Kirby Air Riders Direct On Tuesday
  • WIRED Takes You Back to School
  • How We Test Air Purifiers and What You Should Consider When Buying
  • What Do Kids Actually Think About AI?
  • The Plan to Turn the Caribbean’s Glut of Sargassum Into Biofuel
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » Candy Crush, Tinder, MyFitnessPal: See the Thousands of Apps Hijacked to Spy on Your Location
News

Candy Crush, Tinder, MyFitnessPal: See the Thousands of Apps Hijacked to Spy on Your Location

News RoomBy News Room9 January 20253 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

Some of the world’s most popular apps are likely being co-opted by rogue members of the advertising industry to harvest sensitive location data on a massive scale, with that data ending up with a location data company whose subsidiary has previously sold global location data to US law enforcement.

The thousands of apps, included in hacked files from location data company Gravy Analytics, include everything from games like Candy Crush and dating apps like Tinder to pregnancy tracking and religious prayer apps across both Android and iOS. Because much of the collection is occurring through the advertising ecosystem—not code developed by the app creators themselves—this data collection is likely happening without users’ or even app developers’ knowledge.

“For the first time publicly, we seem to have proof that one of the largest data brokers selling to both commercial and government clients appears to be acquiring their data from the online advertising ‘bid stream,’” rather than code embedded into the apps themselves, Zach Edwards, senior threat analyst at cybersecurity firm Silent Push and who has followed the location data industry closely, tells 404 Media after reviewing some of the data.

The data provides a rare glimpse inside the world of real-time bidding (RTB). Historically, location data firms paid app developers to include bundles of code that collected the location data of their users. Many companies have turned instead to sourcing location information through the advertising ecosystem, where companies bid to place ads inside apps. But a side effect is that data brokers can listen in on that process and harvest the location of peoples’ mobile phones.

“This is a nightmare scenario for privacy, because not only does this data breach contain data scraped from the RTB systems, but there’s some company out there acting like a global honey badger, doing whatever it pleases with every piece of data that comes its way,” Edwards says.

Included in the hacked Gravy data are tens of millions of mobile phone coordinates of devices inside the US, Russia, and Europe. Some of those files also reference an app next to each piece of location data. 404 Media extracted the app names and built a list of mentioned apps.

The list includes dating sites Tinder and Grindr; massive games such as Candy Crush, Temple Run, Subway Surfers, and Harry Potter: Puzzles & Spells; transit app Moovit; My Period Calendar & Tracker, a period-tracking app with more than 10 million downloads; popular fitness app MyFitness Pro; social network Tumblr; Yahoo’s email client; Microsoft’s 365 office app; and flight tracker Flightradar24. The list also mentions multiple religious-focused apps such as Muslim prayer and Christian Bible apps, various pregnancy trackers, and many VPN apps, which some users may download, ironically, in an attempt to protect their privacy.

The full list can be found here. Multiple security researchers have published other lists of apps included in the data, of varying sizes. Our version is relatively larger because it includes both Android and iOS apps, and we decided to keep duplicate instances of the same app that had slight name variations to make it easier for readers to search for apps they have installed.

Although this dataset came from an apparent hack of Gravy, it is not clear whether Gravy collected this location data itself or sourced it from another company, or which location company ultimately owns it or is licensed to use it.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleRealme 14 Pro+ With Snapdragon 7s Gen 3 Chipset, 6,000mAh Battery Listed Online: Price, Features Revealed
Next Article Sony and Honda’s Afeela 1 EV makes more sense at CES than in the real world

Related Articles

News

Is Roblox Getting Worse?

18 August 2025
News

The End of Handwriting

18 August 2025
News

WIRED Takes You Back to School

18 August 2025
News

How We Test Air Purifiers and What You Should Consider When Buying

18 August 2025
News

What Do Kids Actually Think About AI?

18 August 2025
News

The Plan to Turn the Caribbean’s Glut of Sargassum Into Biofuel

18 August 2025
Demo
Top Articles

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024105 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

Every iPhone release in chronological order: 2007-2024

29 January 202486 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
News

How We Test Air Purifiers and What You Should Consider When Buying

News Room18 August 2025
News

What Do Kids Actually Think About AI?

News Room18 August 2025
News

The Plan to Turn the Caribbean’s Glut of Sargassum Into Biofuel

News Room18 August 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025129 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024105 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
Our Picks

Nintendo Is Holding a 45-Minute Kirby Air Riders Direct On Tuesday

18 August 2025

WIRED Takes You Back to School

18 August 2025

How We Test Air Purifiers and What You Should Consider When Buying

18 August 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.