← All categories
Credit Bureau
8 devices analyzed. Set your privacy comfort level to filter.
What we found
Equifax: DEquifax lost the Social Security numbers of 147 million Americans.
In September 2017, Equifax disclosed a breach exposing the personal data of 147 million Americans -- nearly half the US population. Data stolen included Social Security numbers, birth dates, addresses, and driver's license numbers -- everything needed for identity theft. The breach exploited a known Apache Struts vulnerability (CVE-2017-5638) that had a patch available for two months before Equifax was breached. Equifax failed to apply the patch. The company's CISO, Susan Mauldin, held a Master of Fine Arts degree in music composition -- not computer science or information security. Three Equifax executives sold $1.8 million in company stock after the breach was discovered internally but before it was disclosed publicly. Jun Ying, the company's CIO, was sentenced to 4 months in prison for insider trading. The FTC settlement: $700 million, the largest data breach settlement in history. Equifax's breach response website itself had vulnerabilities, and the company initially directed consumers to a phishing look-alike domain.
Au10tix Identity Verification: DYou uploaded your passport to verify your TikTok account.
In 2024, 404 Media discovered that Au10tix had left identity verification credentials on an unsecured server since December 2022 — over a year. The exposed credentials could access identity documents (passports, driving licences, selfies) submitted by users of Uber, TikTok, X (Twitter), LinkedIn, Coinbase, and other platforms that use Au10tix for verification. You verified your identity on TikTok. Your passport photo sat on Au10tix's unsecured server.
X-Mode Location Data: DApple and Google both banned X-Mode — the only time both platforms agreed to kick out the same data broker.
X-Mode's location tracking SDK was embedded in over 400 apps, including Muslim prayer apps, dating apps, and weather apps. The collected location data was sold to US military contractors and intelligence agencies. In 2020, both Apple and Google banned X-Mode's SDK from their app stores — an unprecedented action. X-Mode rebranded as "Outlogic" and continued operations.
SafeGraph Location Data: DYou downloaded a prayer app to know when to face Mecca.
Motherboard revealed in 2020 that SafeGraph sold location data harvested from Muslim prayer apps — including Muslim Pro (100M+ downloads) — to the US military and defence contractors. The data showed which devices visited mosques, when they prayed, and where they went afterwards. SafeGraph bought this data from SDKs embedded in prayer apps whose users had no idea their worship was being tracked and sold to the Pentagon.

Your privacy tolerance