ADVERTISEMENT

Social media app leaks data of 172,000 users, including location coordinates

Social media app Panion leaks user data
Edvardas Mikalauskas
Edvardas Mikalauskas Senior Researcher
October 15, 2020 Updated: September 28, 2021 2 min read

What data is in the bucket?

  • 693,018 image files uploaded by the developers and users, including selfies and documents shared by users in either group or private chats
  • 61 CSV periodically updated files that contained what appears to be 2,596,369 user records, of which 171,855 records belonged to unique users

Examples of exposed records

ADVERTISEMENT

Who owns the bucket?

Who had access to the data?

What’s the impact of the leak?

  • Contact details like names and email addresses can be enough for phishers and scammers to commit targeted attacks against the exposed users via spam emails, while their stated interests can be used against them in social engineering campaigns
  • Determined criminals can combine the names and email addresses found in this bucket with other cyber breaches to build profiles of potential targets for identity theft
  • The location coordinates of these users can potentially be used for breaking and entering or cyberstalking

What happened to the data?

What to do if you’ve been affected by the leak?

  1. Immediately change your email password and consider using a password manager.
  2. Look out for potential spam emails and phishing messages popping up in your inbox. Do not click on anything suspicious, including emails from unknown senders.
ADVERTISEMENT