Metro

Travel App Exposed Locations and Photos of 23 Million Users

Amsterdam-based travel app Polarsteps exposed the personal information of more than 23 million users through an unsecured data feed.

An investigation by Follow the Money found that people with basic technical skills could access names, photos, videos and location records.

The exposed data included about 230 million photos and videos. It also contained one billion GPS locations from nearly two million trips.

This information could allow someone to track a person’s journey on a map, sometimes close to real time.

More than one million of the affected trips were only meant to be visible to approved followers.

The problem also affected fully private accounts. Outsiders could reportedly view details about followers, followed accounts and the devices used to log in.

Researchers could still access a trip through its link after the user removed them as a follower.

Home addresses were among the exposed details. Investigators identified some homes through location data stored inside users’ photos.

Follow the Money said a French cybersecurity researcher first reported the weakness in 2025. The data reportedly remained exposed for at least six months.

The incident did not involve hackers breaking into user accounts. No passwords were stolen.

Instead, the app’s servers allowed large amounts of information to be collected without login walls, CAPTCHAs or proper request limits.

Polarsteps chief executive Clare Jones said the company should have detected the problem itself.

The company has tightened its systems and contacted the Dutch Data Protection Authority, known as the AP.

Polarsteps stressed that no accounts or passwords were compromised. It also said users had chosen to make some of the exposed information public.

The company’s privacy settings, however, promised that private and follower-only trips would have limited access.