Fitness App Polar Flow

Original Release Date: 7/17/2018

Summary

The popular fitness app "Polar Flow" has accidentally exposed the location of millions of users, including personnel working for intelligence services and at military bases. By simply modifying the browser's web address or abusing the API, an individual could find the names of users who track, or who have tracked, their fitness with Polar Flow, going back to 2014. Additionally, abusing the app's API revealed information on over 64,000 users whose accounts were set to private, many of whom used the app at sensitive locations around the world including the NSA, White House, MI6, and nuclear storage facilities. Since the release of this information, Polar has temporarily suspended the Explore API.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.