Polarsteps A.I CyberSecurity Scoring
Polarsteps
Company Information
Website:https://www.polarsteps.com
Employees number:116
Number of followers:18,925
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:polarsteps.com
Polarsteps Risk Score (AI oriented)
Between 550 and 599
PolarstepsTechnology, Information and Internet
Updated:
07/09/2026
07/09/2026
590/1000
Very Poor
Ca
Polarsteps Global Score (TPRM)
xxxx
PolarstepsTechnology, Information and Internet
Score locked

PolarstepsVery Poor
Current Score
590Ca (VERY POOR)
01000
1 incidents
-177 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
594
SEPTEMBER 2026
767
Breach
05 Sep 2026 • Polarsteps
Polarsteps and Dutch Ministry of Defence: Travel app Polarsteps lets people spy on soldiers
Polarsteps Travel App Exposes Sensitive Location Data of 23 Million Users, Including Military Personnel
590
CRITICAL-177
POLDUT1788784548
Polarsteps Travel App Exposes Sensitive Location Data of 23 Million Users, Including Military Personnel
A major privacy flaw in the Dutch travel app Polarsteps used by over 23 million people worldwide allowed unauthorized access to users' exact locations, photos, and personal details, including those of military personnel from the U.S., U.K., France, and Belgium. Security researchers and journalists from Follow the Money (FTM) exploited weak backend protections to scrape 230 million photos and videos, along with 1 billion GPS coordinates, revealing highly sensitive movements from holiday destinations to work trips and even children’s school drop-offs.
### Key Findings
- Military & High-Risk Exposure: FTM tracked over 30 military personnel, including a U.S. Space Force officer whose travels across global bases from Florida to Qatar were fully mapped. Another case involved a U.S. Air Force mechanic whose posts revealed his residence at Ramstein and Spangdahlem bases in Germany, alongside personal photos of family visits.
- Non-Public Data Accessible: Even users who restricted their profiles to followers only had their data exposed. FTM accessed 1 million private trips by exploiting a loophole where users could follow others without explicit consent.
- Stalking & Blackmail Risks: Experts warned the exposed data could enable stalking, espionage, or blackmail, particularly for individuals in sensitive roles. The Dutch Ministry of Defence responded by banning Polarsteps on defense devices and warning personnel about risks on personal phones.
- Long-Standing Vulnerability: A French cybersecurity researcher alerted Polarsteps to the issue in December 2025, but the company dismissed concerns, stating it had "assessed" the risk and made no changes. FTM’s investigation later confirmed the flaw remained exploitable for months.
### How the Breach Happened
Polarsteps’ unrestricted API allowed anyone with basic technical knowledge to extract user data, including:
- GPS coordinates of photos (even if not publicly visible in the app).
- Home addresses and frequented locations (e.g., schools, military bases).
- Photos of military installations, colleagues, and family members.
The Dutch Data Protection Authority (AP) stated that companies must prevent large-scale data scraping, even from public profiles, under GDPR regulations. Privacy experts argued Polarsteps failed to adequately inform users about how their data was exposed.
### Company Response
After FTM presented its findings, Polarsteps tightened security measures, including:
- Requiring manual approval for new followers by default.
- Exploring ways to automatically disable location tracking when users return home.
- Reducing the amount of data shared via its API.
However, previously scraped data remains in circulation, posing ongoing risks. The Dutch Ministry of Defence’s decision to block the app underscores the severity of the breach, particularly for personnel in national security roles.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
767
JULY 2026
767
JUNE 2026
767
MAY 2026
767
APRIL 2026
767
MARCH 2026
767
FEBRUARY 2026
767
JANUARY 2026
767
DECEMBER 2025
767
NOVEMBER 2025
767
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Polarsteps ??
What was Polarsteps's A.I Rankiteo Cyber Score in September 2026 ??
What was Polarsteps's A.I Rankiteo Cyber Score in August 2026 ??
What was Polarsteps's A.I Rankiteo Cyber Score in July 2026 ??
What was Polarsteps's A.I Rankiteo Cyber Score in June 2026 ??
What was Polarsteps's A.I Rankiteo Cyber Score in May 2026 ??
What was Polarsteps's A.I Rankiteo Cyber Score in April 2026 ??
What was Polarsteps's A.I Rankiteo Cyber Score in March 2026 ??
What was Polarsteps's A.I Rankiteo Cyber Score in February 2026 ??
What was Polarsteps's A.I Rankiteo Cyber Score in January 2026 ??
What was Polarsteps's A.I Rankiteo Cyber Score in December 2025 ??
What was Polarsteps's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on Polarsteps's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Polarsteps ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Polarsteps's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?