Data leak
Tile / Life360 Data Breach and Extortion
Primary Source βIncident Details
An attacker gained access to Tile’s customer support system using credentials belonging to a former employee, then scraped millions of customer records and attempted to extort Life360 (Tile’s parent company). Exposed data included names, physical addresses, email addresses, phone numbers, and Tile device IDs β no financial data, passwords, or location history was compromised. The attacker had access to tools for processing law enforcement data requests. Life360 reported the extortion attempt to law enforcement.
Technical Details
- Initial Attack Vector
- Threat actor used stolen credentials of a former Tile/Life360 employee to access the customer support platform; inactive credentials not revoked after employee departure
- Vendor / Product
- Tile customer support platform
Timeline
- 2024-06-01 Breach occurred
- 2024-06-11 Publicly disclosed
- 2024-06-12 Customers notified