Tracker firm Hapn spilling names of thousands of GPS tracking customers

Date:

Share post:


GPS tracking firm Hapn is exposing the names of thousands of its customers due to a website bug, TechCrunch has learned.

A security researcher alerted TechCrunch in late November to customer names and affiliations — such as the name of their workplace — spilling from one of Hapn’s servers, which TechCrunch has seen. 

Hapn, formerly known as Spytec, is a tracking company that allows users to remotely monitor the real-time location of internet-enabled tracking devices, which can be attached to vehicles or other equipment. The company also sells GPS trackers to consumers under its Spytec brand, which rely on the Hapn app for tracking. Spytec touts its GPS devices for tracking the locations of valuable possessions and “loved ones.” According to its website, Hapn claims to track more than 460,000 devices and counts customers within the Fortune 500.

The bug allows anyone to log in with a Hapn account to view the exposed data using the developer tools in their web browser.

The exposed data contains information on more than 8,600 GPS trackers, including the IMEI numbers for the SIM cards in each tracker, which uniquely identify each device. The exposed data does not include location data, but thousands of records contain the names and business affiliations of customers who own, or are tracked by, the GPS trackers.

Hapn has not responded to multiple emails from TechCrunch. The customer names remain exposed at the time of writing. 

Several emails to Hapn CEO Joe Besdin went unreturned. A message sent to an email address listed on the company’s privacy policy returned with a bounce error, saying that the email address does not exist. The company does not have a web page or form for reporting security vulnerabilities.

When we contacted individuals whose names and affiliations were listed in the exposed data, several people confirmed their names and workplaces but declined to discuss their use of the GPS tracker. One company listed on Hapn’s website as a corporate customer had several trackers listed in the exposed data, TechCrunch has seen.

The security researcher said they began looking into the GPS tracker after finding that customers had left online reviews for the devices recommending the tracker for monitoring a person’s spouse or partner. (TechCrunch has seen dozens of reviews on Spytec’s online stores from customers who claim to have used the GPS devices to track their spouses.)

The list of exposed customer records also shows thousands of trackers with associated names but no other discernible affiliation. It’s not known if the individuals are aware of having been tracked.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Sam Altman once owned some equity in OpenAI through Sequoia

OpenAI CEO Sam Altman sat before Congress in 2023 to testify about the dangers of AI. He...

Perplexity has reportedly closed a $500M funding round

AI-powered search engine Perplexity has reportedly closed a $500 million funding round, valuing the startup at $9...

Boon raises $20.5M to build agentic AI tools for fleets

Logistics is the name of the game during the holiday season: Companies that can seal the deal...

A bad experience with an accounting firm spurred this founder to start Aiwyn

Accounting firms are struggling to adopt high-tech solutions. That’s according to a survey earlier this year from...

Meet the robot with two Guinness World Records for basketball

A team of engineers at Toyota have spent years iterating on CUE6, the basketball-shooting robot. CUE6 uses...

TuSimple pivot from self-driving to AI animation is complete with CreateAI rebrand

TuSimple has completed its pivot away from autonomous trucking to AI animation and gaming with a rebrand....

Ex-Twitch CEO Emmett Shear is founding an AI startup backed by a16z

Emmett Shear, the former CEO of Twitch, is launching a new AI startup, TechCrunch has learned. The...

In just 4 months AI coding assistant Cursor raised another $100M at a $2.5B valuation led by Thrive, sources say

Anysphere, the developer of AI-powered coding assistant Cursor, raised $100 million Series B at a post-money valuation...