• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
hacktivist breaches private security app citizen

Hacktivist breaches private security app Citizen

You are here: Home / General Cyber Security News / Hacktivist breaches private security app Citizen
May 27, 2021

A hacker has posted 1.7 million records owned by private security application Citizen on the dark web.

The hacktivist, who determined them selves as a member of the loosely coupled Nameless collective, scraped knowledge en masse from Citizen-owned systems. Citizen collects and publishes info about crimes taking place in serious time. 

The info set integrated logs of police action in various towns and the metadata from videos uploaded to the app. It also included inbound links to 1.5 million videos saved on the company’s servers, symbolizing 70TB of footage, described Motherboard.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Released in 2016, Citizen commenced as Vigilante, an app that harvested emergency radio phone calls and documented the place crime was going on in true time. Apple initially pulled it from the application keep for allegedly encouraging vigilante action, but it relaunched the subsequent yr. It now contains the means for users to stay stream incidents and report emerging crime events by themselves.

The hacker, who posted the info on a dark internet site titled The Anxious Citizen’s Citizen Hack, scraped it by analyzing how the site retailers video clips and locating the authentic information on an AWS S3 bucket. They utilised the similar API as Citizen’s app to retrieve the ID of the crime incident linked to the video clip file and downloaded the incident details in bulk. The movies in the S3 bucket reportedly included some tagged for elimination by moderators but ended up still accessible by means of a immediate website link.

Citizen responded that all the scraped data was previously publicly obtainable on the company’s web-site.

The hacker’s dark web page also incorporates speak to tracking facts from Citizen, which operates its individual COVID-19 make contact with monitoring application named SafePass. In a main privacy stumble, The corporation reportedly uncovered tracking details to the public by mistake, including self-documented indications and exam success, linked to their Citizen usernames.

This thirty day period, Citizen was in the news following a reside stream from the application with around a million views sparked a manhunt in California. The application confirmed the name and photograph of a guy considered to have began a wildfire, but he turned out to be innocent. In May, Motherboard uncovered the enterprise had been testing the idea of a private security pressure immediately after automobiles branded with the Citizen symbol have been photographed in Los Angeles.


Some parts of this post are sourced from:
www.itpro.co.uk

Previous Post: «Cyber Security News Data Breach at Canada Post
Next Post: Feds Warn DarkSide May Not Stay Dark Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors
  • Top 10 Best Practices for Effective Data Protection
  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks
  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications
  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit
  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
  • Pen Testing for Compliance Only? It’s Time to Change Your Approach
  • 5 BCDR Essentials for Effective Ransomware Defense
  • Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

Copyright © TheCyberSecurity.News, All Rights Reserved.