HomeSecurityLife360 reports extortion attempt after Tile data breach

Life360 reports extortion attempt after Tile data breach

Security and location services company Life360 says it was the target of an extortion attempt after a threat actor breached and stole sensitive information from a Tile customer support platform .

See also: Snowflake breach exposes customer data

Life360 breach

Life360 provides real-time location tracking, crash detection, and emergency roadside assistance to more than 66 million members worldwide. In December 2021, it acquired Bluetooth tracking service provider Tile in a $205 million deal.

On Wednesday, Life360 revealed that an attacker breached a Tile customer support platform and gained access to names, addresses, emails, phone numbers and device identification numbers

“Like many other companies, Life360 was recently the victim of a criminal extortion attempt. We received an email from an unknown hacker claiming to be in possession of Tile customer information,” said Life360 CEO Chris Hulls.

The exposed data “does not include more sensitive information, such as credit card numbers, passwords or login credentials, location data, or government-issued identification numbers, because Tile’s customer support platform did not contain these types of information,” Hulls added.

Breaches using stolen credentials

Life360 did not disclose how the threat actor breached its platform, but the company said it had taken steps to protect its systems from further attack and reported the extortion attempts to law enforcement. Furthermore, the company has not yet disclosed when the breach was detected or how many customers were affected by the resulting data breach.

See also: Cylance: Data breach via third-party hacking

A Tile spokesperson declined to answer any of these questions, saying that Tile “continues to cooperate with law enforcement” and that it “has no further updates at this time.”

Tile violation

While Life360 didn't provide many details about this breach, 404 Media reported on Wednesday that the hacker used what are believed to be the stolen credentials of a former Tile employee to gain access to multiple systems .

The hacker said one of the compromised tools helps find Tile customers based on their phone numbers or private hashed identifiers and “initiate data access, location or law enforcement requests,” while others likely allowed the creation of admin, pushed notifications to Tile users, and transferred ownership of the Tile device.

However, the attacker leaked Tile customer names, addresses, email addresses, phone numbers, and device identification numbers using a different system, sending millions of requests without being detected.

It is currently uncertain whether the threat actor will publish the hacked data. However, this type of data is commonly sold on hacking forums and dark web marketplaces or circulated for free in order to boost the threat actor's reputation.

See also: 23andMe: Canadian and UK authorities investigate data breach 

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A data breach, like the one affecting Life360, is a security incident where information is accessed without authorization. This critical event can lead to the exposure of sensitive, protected or confidential data, often affecting personal information, financial data and company secrets. The consequences of a data breach can be severe, ranging from financial losses and identity theft to reputational damage and legal implications. Prevention is key, and organizations should invest in strong security measures, regular audits and employee training to mitigate the risk of such breaches. Furthermore, having a response plan ensures a structured approach to quickly and effectively address the breach, minimizing potential damage.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS