🚨 Gravy Analytics Breach: The Unfolding Story and Lessons Learned So Far
The unfolding story of the Gravy Analytics breach has captured global attention, particularly with reports of potential sensitive data exposure, including geolocation information tied to millions worldwide. As we continue to monitor developments, here’s a recap and some insights:
Timeline of Events:
🗓️ [January 4, 2025] Gravy Analytics identified unauthorized access to its AWS cloud storage, attributed to a "misappropriated access key."
🗓️ [January 5, 2025] A user, “nightly,” on the Russian-speaking XSS forum, notified others of the alleged breach and shared purported data samples as evidence. Shortly afterward, data leak samples, the post and the entire thread vanished.
🗓️ [January 10, 2025] Gravy Analytics confirmed the incident through a non-compliance report submitted to the Norwegian Data Protection Authority. The report stated that some files were accessed, but the investigation into their contents (and whether personal data is included) remains ongoing.
🗓️ [January 13, 2025] "nightly" dismissed the breach claim, calling it disinformation. They alleged someone impersonated their alias, stating: “They just wrote my nickname using the element code. Disinformation.”
🔍 Baptiste Robert (
@fs0c131y ), the CEO of the
@PredictaLabOff conducted a detailed assessment of the leaked dataset samples. Based on his investigation, the dataset contained over 30 million location data points, including devices located at The White House in Washington D.C., the Kremlin in Moscow, Vatican City, and military bases worldwide. (Baptiste's thread:
x.com/fs0c131y/status/187697…)
🔍 This leak and claim of impersonation by “nightly” adds a complex twist. Whether intentional or not, this could be a calculated move by actors to amplify pressure on Gravy Analytics by fueling public scrutiny.
Actors know forums like XSS are closely monitored and use them strategically - whether for legitimate claims or disinformation - to draw attention to their claims, amplifying their impact.
The alleged posting of stolen data on a ransomware data leak site, or in this case on a Dark Web forum, highlights a recurring tactic: leveraging sensitive data for coercion and applying pressure on victims.
⁉️ Unknowns Remain: No additional data samples have been leaked by the actors, and no known ransomware groups have claimed responsibility (publicly) so far. This leaves questions about the actors behind the breach and its true nature.
💡 This incident serves as a critical reminder: organizations must remain vigilant against evolving threats. From bolstering cybersecurity measures to maintaining transparency during incidents, every step matters.
Stay informed, stay alert with
@Analyst1 🦅
Hackers claim to have breached Gravy Analytics, a US location data broker selling to government agencies.
They shared 3 samples on a Russian forum, exposing millions of location points across the US, Russia, and Europe.
It's OSINT time! 👇