Polarsteps, an Amsterdam-founded travel tracking application utilized by more than 23 million people worldwide, left sensitive user data—including private photographs, exact geographic locations, and home addresses—exposed to anyone via an unsecured data feed. According to an investigative report published by the journalistic platform Follow the Money (FTM), the severe security vulnerability exposed data from trips even when users had explicitly set their accounts or specific itineraries to private mode. Furthermore, the investigation revealed that the company had been aware of the architectural flaw for months prior to public disclosure.
The expansive data leak meant that unauthorized individuals could easily connect to the free application’s underlying data feed and extract vast quantities of personal information. This included users’ names, roughly 230 million photos and videos, and an astonishing 1 billion GPS data points harvested from nearly 2 million individual trips. The volume and granularity of the leaked information were more than sufficient to accurately plot user journeys on a map and track many travelers in close to real time, raising immediate and severe concerns regarding digital privacy, personal safety, and potential stalking.
The scale of the breach extended deep into the privacy settings that users trusted to protect their whereabouts. More than a million of the exposed trips had been explicitly designated as shared only with approved followers. Even accounts that were configured to be fully private still leaked valuable relational data, revealing who a specific user followed, who followed them back, and the exact type of mobile device they had used to log into the service. Compounding the issue, once investigative reporters at FTM secured the direct link to an individual user’s trip, removing that reporter as an authorized follower changed nothing, failing to revoke access to the underlying data stream.
Among the most alarming findings of the investigation was the exposure of users’ residential home addresses. FTM researchers were able to pinpoint dozens of home addresses directly from the exact location metadata embedded quietly inside users’ uploaded photographs—such as an innocuous snapshot of packed suitcases taken indoors before leaving for a vacation. In addition to photo metadata, the investigators were able to deduce many more residential addresses by analyzing the recurring geographic coordinates where people routinely returned each night at the end of their journeys.
Crucially, this expansive collection and storage of photo-location data appeared nowhere within the official privacy policy published by Polarsteps. The hidden data tracking was also entirely absent from the personal file that the company provided to FTM when reporters formally requested to review their own accumulated user records under data protection regulations.
The security lapse was first flagged to the company last year by an independent French cybersecurity researcher. According to the researcher, when he reached out to Polarsteps to report the glaring vulnerability, company representatives informed him that they were already aware of the situation. Frustrated by the lack of visible remediation, the researcher ultimately took his findings to Follow the Money, whose subsequent journalistic investigation confirmed that the data remained completely exposed and accessible for at least six additional months.
Academic experts have sharply criticized the company’s handling of the technical oversight. Marc Schuilenburg, a professor of digital surveillance at Erasmus University, did not mince words, calling the company’s prolonged inaction negligent. He warned that leaked and readily accessible location data of this magnitude can easily be weaponized by malicious actors to stalk, harass, burglarize, or physically threaten unsuspecting individuals.
Investigators emphasized that the massive exposure was not the result of a sophisticated malicious cyberattack. No user passwords were stolen, and unauthorized parties did not need to breach user accounts or bypass authentication walls to gain entry. Instead, the vulnerability stemmed from foundational architectural oversights: anyone with basic technical skills could connect directly to Polarsteps’ backend servers and scrape the data freely, entirely unhindered by request limits, CAPTCHA verifications, or login walls.
In response to the damaging revelations, representatives for Polarsteps noted that no passwords or user accounts were ultimately compromised during the incident, and confirmed that they are actively in communication with the Dutch Data Protection Authority (AP). The company, which has experienced explosive growth from around 1 million users in 2019 to its current scale of over 23 million, is now under new executive leadership.
Chief Executive Clare Jones, who was appointed to lead the company in 2024, acknowledged the severity of the oversight. She stated that the company deeply regrets the incident and should have detected and resolved the problem internally before external investigators brought it to light. Jones added that Polarsteps is currently conducting a thorough internal review to determine exactly how the security gap persisted for so long. In the wake of the FTM report, the company has implemented technical changes to tighten its server systems and secure its data feeds. At the same time, representatives for the platform noted that a significant portion of the exposed material had originally been made public voluntarily by the users themselves through their sharing habits.
Ironically, the company’s own official website routinely cautions travelers that sharing location details in real time or publishing granular travel updates "can make you a target" for bad actors. As the fallout from the initial investigation continues to unfold, Follow the Money announced that a second installment of its comprehensive investigation—focusing specifically on dozens of military personnel whose movements were tracked by reporters to sensitive domestic and international military bases and missions—is scheduled for publication on Saturday.
