Security and location services company Life360 says it was the target of an extortion attempt after a threat actor breached and stole sensitive information from a Tile customer support platform .
See also: Snowflake breach exposes customer data

Life360 provides real-time location tracking, crash detection, and emergency roadside assistance to more than 66 million members worldwide. In December 2021, it acquired Bluetooth tracking service provider Tile in a $205 million deal.
On Wednesday, Life360 revealed that an attacker breached a Tile customer support platform and gained access to names, addresses, emails, phone numbers and device identification numbers
“Like many other companies, Life360 was recently the victim of a criminal extortion attempt. We received an email from an unknown hacker claiming to be in possession of Tile customer information,” said Life360 CEO Chris Hulls.
The exposed data “does not include more sensitive information, such as credit card numbers, passwords or login credentials, location data, or government-issued identification numbers, because Tile’s customer support platform did not contain these types of information,” Hulls added.
Breaches using stolen credentials
Life360 did not disclose how the threat actor breached its platform, but the company said it had taken steps to protect its systems from further attack and reported the extortion attempts to law enforcement. Furthermore, the company has not yet disclosed when the breach was detected or how many customers were affected by the resulting data breach.
See also: Cylance: Data breach via third-party hacking
A Tile spokesperson declined to answer any of these questions, saying that Tile “continues to cooperate with law enforcement” and that it “has no further updates at this time.”

While Life360 didn't provide many details about this breach, 404 Media reported on Wednesday that the hacker used what are believed to be the stolen credentials of a former Tile employee to gain access to multiple systems .
The hacker said one of the compromised tools helps find Tile customers based on their phone numbers or private hashed identifiers and “initiate data access, location or law enforcement requests,” while others likely allowed the creation of admin, pushed notifications to Tile users, and transferred ownership of the Tile device.
However, the attacker leaked Tile customer names, addresses, email addresses, phone numbers, and device identification numbers using a different system, sending millions of requests without being detected.
It is currently uncertain whether the threat actor will publish the hacked data. However, this type of data is commonly sold on hacking forums and dark web marketplaces or circulated for free in order to boost the threat actor's reputation.
See also: 23andMe: Canadian and UK authorities investigate data breach
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
A data breach, like the one affecting Life360, is a security incident where information is accessed without authorization. This critical event can lead to the exposure of sensitive, protected or confidential data, often affecting personal information, financial data and company secrets. The consequences of a data breach can be severe, ranging from financial losses and identity theft to reputational damage and legal implications. Prevention is key, and organizations should invest in strong security measures, regular audits and employee training to mitigate the risk of such breaches. Furthermore, having a response plan ensures a structured approach to quickly and effectively address the breach, minimizing potential damage.
Source: bleepingcomputer
