
You may know Polarsteps, a travel app that lets you let friends and family know about your vacation. The app turned out to be less secure than expected. The globally popular Dutch travel app failed to adequately protect user data for at least six months.
research platform follow the money A security flaw has been discovered that could have exposed the travel information of millions of users, even those who had their profiles set to private. What is there to see?
Polarsteps doesn’t protect data well
in short: FTM obsolete According to reports, 23 million international user names can view hundreds of millions of photos and access billions of GPS locations through millions of Polarsteps. NOS.
This is possible with the help of so-called application programming interfaces (APIs). Normally this part is protected and inaccessible, but with Polarsteps servers everyone can easily connect, write FTM.
This allows journalists to track protected accounts without the user’s permission. within a few months FTM Lots of information.
Polarsteps has had leaks before
In October 2025, network security researcher Louis Couderc discovered a vulnerability in Polarsteps. Even without permission, he can track thousands of users through the API. He reported the situation to Polarsteps but was told the leak was already known. He then shared his findings with Follow the Money, after which reporters were able to monitor large numbers of travelers for months.
In its response, Polarsteps stressed that no passwords were stolen and that FTM Unable to access account.
Consequences of insecure connections
according to FTM Polarsteps connection is not secure enough. This allows retrieval of large amounts of material. An important part of this includes location data. Enable real-time tracking of users based on FTM The exact location is obtained every five to ten minutes through the Polarsteps server.
FTM Capable of collecting more than 1 billion location points from nearly 2 million trips and placing them on a digital map. This means many journeys can be tracked almost instantly. The journey ahead is also evident. FTM can set notifications when users enter specific areas.
By combining the locations that users frequently returned to, researchers were also able to determine the home addresses of many people.
Polarsteps says it has stepped up safety measures
Polarsteps object FTM It’s amazing that data can be collected on such a large scale. Is it safe for you to use this app now? It’s not entirely certain, but the company says it has beefed up security measures and is looking into further measures.
According to Polarsteps, some of the information discovered is public because users themselves chose to share it. The company is also working on how to prevent users from forgetting to turn off tracking when they get home.
It’s not uncommon for data in apps to be insecure
“You’re more likely to see this in apps,” said privacy consultant Floor Terra. FTM. “There’s a gap between what you expect as an average user and what’s actually happening with your data. If people don’t know what happens to their data in practice, then Polarsteps doesn’t adequately explain their behavior.”
Marc Schuilenburg said the consequences of the Polarsteps leak could be far-reaching: “We know that leaked data can be used to systematically harass people and even physically attack or threaten them,” says a professor of digital surveillance at Erasmus University.
These are the most read articles right now:
- Brigitte (57) suffers from fibromyalgia and is always in pain: “You never get used to it, you have to plan your whole life”
- Consumer association warns about KLM offer: a ticket for 699 euros was previously sold for 615 euros
- Investment account of Vincent (45): “Becoming a billionaire was my goal and I succeeded”
- Dutch students are living in rooms less and less, but something surprising is happening among international students
- Over Mijn Lijk’s Roy and Annick confirm relationship breakdown: ‘Losing each other along the way’










