owner says a hacker obtained personal information on customers of the Bluetooth tracker brand. The details include names, addresses, email addresses, phone numbers and Tile device ID numbers. Life 360 CEO Chris Hulls that the stolen data does not include credit card numbers, passwords, other login credentials, location data of Tile devices or government-issued ID numbers.
“Similar to many other companies, Life360 recently became the victim of a criminal extortion attempt,” Hulls wrote. “We received emails from an unknown actor claiming to possess Tile customer information. We promptly initiated an investigation into the potential incident and detected unauthorized access to a Tile customer support platform (but not our Tile service platform).”
Hulls added that Life360 believes the stolen data was limited to customer names, their physical and email addresses and device IDs. “We have taken and will continue to take steps designed to further protect our systems from bad actors, and we have reported this event and the extortion attempt to law enforcement,” Hulls wrote. “We remain committed to keeping families safe online and in the real world.”
The attack appears to have gone beyond pinching user data, however. According to 404 Media, , the hacker was able to gain access to some of Tile’s internal tools, including one used to process any location data requests submitted by law enforcement.
The hacker says they used login credentials that apparently belonged to a former Tile employee to access the customer support systems (Tile said in a separate statement to 404 Media that it later deactivated these credentials). The information they obtained is also said to include order and return details along with the payment method used by the customers. They were also seemingly able to access tools that, for instance, allow Tile to transfer ownership of a Bluetooth tracker from one email address to another, create administrator accounts and send push notifications. The hacker told 404 Media that they didn’t use these functions.
This article contains affiliate links; if you click such a link and make a purchase, we may earn a commission.
You Might Also Like
TikTok removes Russian state-owned media accounts for ‘covert influence’
TikTok has announced in its US Elections Integrity Hub that it has removed accounts associated with Rossiya Segodnya and TV-Novosti,...
Apple’s AirPods 4 are already on sale in this early Prime Day deal
It has been less than a week since Apple released the AirPods 4, and there's already a small sale available...
Spotify’s AI Playlists are now available for Premium users in the US
Spotify’s beta AI Playlist feature is now available for Premium users in the US, Canada, Ireland and New Zealand. It...
OpenAI’s X account was hacked to promote a crypto scam
OpenAI opened a newsroom Twitter account earlier this month and it's already been hacked. The new handle was taken over...