Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Polarsteps

Polarsteps Vendor Cyber Rating & Cyber Score

polarsteps.com

Polarsteps is helping millions of travelers across the globe to plan, track and relive their travels in a smart and beautiful way. Crafted by a team of avid explorers with a passion for clever technology and design, our all-in-one travel app features a travel planner, a personalized digital map and, at the end of it all, can be used to turn memories into a hold-in-your-hand Travel Book. Launched in 2015 and headquartered in Amsterdam, our fast-growing team is on a journey with a clear destination - to inspire and connect people through travel. Will you join us? Polarsteps – Make your way in the world.


Polarsteps A.I CyberSecurity Scoring

Polarsteps
Company Information
Website:https://www.polarsteps.com
Employees number:116
Number of followers:18,925
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:polarsteps.com
Polarsteps Risk Score (AI oriented)
Between 550 and 599
logo
PolarstepsTechnology, Information and Internet
Updated:
07/09/2026
590/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
Polarsteps Global Score (TPRM)
xxxx
logo
PolarstepsTechnology, Information and Internet
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

PolarstepsVery Poor
Current Score
590Ca (VERY POOR)
01000
1 incidents
-177 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
594Before Incident
SEPTEMBER 2026
767Before Incident
Breach
05 Sep 2026 • Polarsteps
Polarsteps and Dutch Ministry of Defence: Travel app Polarsteps lets people spy on soldiers

Polarsteps Travel App Exposes Sensitive Location Data of 23 Million Users, Including Military Personnel

590After Incident
CRITICAL-177
POLDUT1788784548
Polarsteps Travel App Exposes Sensitive Location Data of 23 Million Users, Including Military Personnel A major privacy flaw in the Dutch travel app Polarsteps used by over 23 million people worldwide allowed unauthorized access to users' exact locations, photos, and personal details, including those of military personnel from the U.S., U.K., France, and Belgium. Security researchers and journalists from Follow the Money (FTM) exploited weak backend protections to scrape 230 million photos and videos, along with 1 billion GPS coordinates, revealing highly sensitive movements from holiday destinations to work trips and even children’s school drop-offs. ### Key Findings - Military & High-Risk Exposure: FTM tracked over 30 military personnel, including a U.S. Space Force officer whose travels across global bases from Florida to Qatar were fully mapped. Another case involved a U.S. Air Force mechanic whose posts revealed his residence at Ramstein and Spangdahlem bases in Germany, alongside personal photos of family visits. - Non-Public Data Accessible: Even users who restricted their profiles to followers only had their data exposed. FTM accessed 1 million private trips by exploiting a loophole where users could follow others without explicit consent. - Stalking & Blackmail Risks: Experts warned the exposed data could enable stalking, espionage, or blackmail, particularly for individuals in sensitive roles. The Dutch Ministry of Defence responded by banning Polarsteps on defense devices and warning personnel about risks on personal phones. - Long-Standing Vulnerability: A French cybersecurity researcher alerted Polarsteps to the issue in December 2025, but the company dismissed concerns, stating it had "assessed" the risk and made no changes. FTM’s investigation later confirmed the flaw remained exploitable for months. ### How the Breach Happened Polarsteps’ unrestricted API allowed anyone with basic technical knowledge to extract user data, including: - GPS coordinates of photos (even if not publicly visible in the app). - Home addresses and frequented locations (e.g., schools, military bases). - Photos of military installations, colleagues, and family members. The Dutch Data Protection Authority (AP) stated that companies must prevent large-scale data scraping, even from public profiles, under GDPR regulations. Privacy experts argued Polarsteps failed to adequately inform users about how their data was exposed. ### Company Response After FTM presented its findings, Polarsteps tightened security measures, including: - Requiring manual approval for new followers by default. - Exploring ways to automatically disable location tracking when users return home. - Reducing the amount of data shared via its API. However, previously scraped data remains in circulation, posing ongoing risks. The Dutch Ministry of Defence’s decision to block the app underscores the severity of the breach, particularly for personnel in national security roles.
INCIDENT DETAILS -
TYPE
Data Exposure
MOTIVATION
Investigative reporting, vulnerability demonstration
IMPACT
Data Compromised: 230 million photos/videos, 1 billion GPS coordinates, 1 million private tripsSystems Affected: Polarsteps backend API, user data storageOperational Impact: Dutch Ministry of Defence banned the app on defense devicesBrand Reputation Impact: Significant reputational damage, loss of user trustLegal Liabilities: Potential GDPR violations, regulatory scrutinyIdentity Theft Risk: High (exposure of personal details, locations, and photos)
DATA BREACH
GPS coordinatesPhotosVideosPersonal detailsTrip itinerariesNumber Of Records Exposed: 230 million photos/videos, 1 billion GPS coordinates, 1 million private tripsSensitivity Of Data: High (military personnel movements, home addresses, family photos)Data Exfiltration: Yes (scraped by researchers)PhotosVideosPersonally Identifiable Information: Yes (names, locations, personal photos, military affiliations)
AUGUST 2026
767Before Incident
JULY 2026
767Before Incident
JUNE 2026
767Before Incident
MAY 2026
767Before Incident
APRIL 2026
767Before Incident
MARCH 2026
767Before Incident
FEBRUARY 2026
767Before Incident
JANUARY 2026
767Before Incident
DECEMBER 2025
767Before Incident
NOVEMBER 2025
767Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Polarsteps ?
?
What was Polarsteps's A.I Rankiteo Cyber Score in September 2026 ?
?
What was Polarsteps's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Polarsteps's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Polarsteps's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Polarsteps's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Polarsteps's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Polarsteps's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Polarsteps's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Polarsteps's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Polarsteps's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Polarsteps's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on Polarsteps's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Polarsteps ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Polarsteps's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?