Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Life360 Says Personal Information Stolen From Tile Customer Support Platform

Life360 says hackers attempted to extort it after stealing personal information from a Tile customer support platform.

Location tracking company Life360 this week disclosed a data breach impacting personal information stored on a customer support platform.

The incident, Life360 revealed, was identified after a threat actor contacted it claiming to be in the possession of the stolen information, with the intent to extort the company. The hackers appear to have targeted systems associated with Life360 subsidiary Tile. 

“We promptly initiated an investigation into the potential incident and detected unauthorized access to a Tile customer support platform (but not our Tile service platform),” the company said in a data breach notice.

The potentially compromised information, Life360 said, includes names, addresses, phone numbers, email addresses, and Tile device identification numbers.

“It does not include more sensitive information, such as credit card numbers, passwords or log-in credentials, location data, or government-issued identification numbers, because the Tile customer support platform did not contain these information types,” the company said.

According to Life360, no other Tile systems beyond the customer support platform appear to have been affected by the data breach.

Advertisement. Scroll to continue reading.

“We have taken and will continue to take steps designed to further protect our systems from bad actors, and we have reported this event and the extortion attempt to law enforcement,” the location tracking company said.

Life360 shared no details on the identity of the attackers, nor did it say whether it conceded to the threat actor’s extortion demands. No information on how the data breach occurred has been provided either.

The attackers reportedly accessed a Tile system using compromised login credentials for an administrator account. The company disabled the credentials and blocked the unauthorized access to its platform.

Related: Snowflake Attacks: Mandiant Links Data Breaches to Infostealer Infections

Related: 750k Impacted by Frontier Communications Data Breach

Related: Boat Dealer MarineMax Confirms Data Breach

Related: British Retailer JD Sports Discloses Data Breach Affecting 10 Million Customers

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Geoff Belknap has joined HubSpot as Chief Trust Officer.

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.