[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzlow40dq8pym":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":26,"seoTitle":15,"seoTitleEn":27,"seoDescription":15,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":30,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda48825271","life360","Life360 Data Breach","life360.com","2024-03-01T00:00:00.000Z","2024-07-20T21:40:31.000Z","2026-07-03T23:05:21.539Z","2026-07-18T23:53:15.463Z","Third party breach","",[],442519,"known",null,"unknown","High",[23,24,25],"Email addresses","Names","Phone numbers","\u003Cp>The Life360 data breach is related to the collection and subsequent sharing of user contact information belonging to the family safety and location sharing service in March 2024. The scope is approximately 442,519 unique email addresses. This record was treated as a contact data breach that does not include location history; to avoid giving users the wrong perception about accounts, brands, or data fields, the company, country, industry, website, and data class fields were checked individually. In this record, location history, passwords, or payment information were not verified.\u003C\u002Fp>\u003Cp>The text was stripped of old template headings and transferred to a structure that directly conveys risk, scope, and action to the user. The website field was kept in the format life360.com; since the protocol was not added, the format that would cause https to appear twice on the link side was not preserved. The sector was shifted from general technology to the context of family safety and location sharing; however, data fields were limited only to verified contact information.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record are email addresses, names, and phone numbers. The password field was not verified; the main risk is fake account reporting, family group invitation, and phone-based social engineering. These fields were evaluated individually; unverified payment card, bank account, government ID, private message, health record, or additional profile fields were not added to the data class list.\u003C\u002Fp>\u003Cp>Since the Life360 brand is known for location sharing, users may be more likely to believe messages about fake devices, family circles, or security alerts. While an email address alone poses a risk of spam and phishing, when combined with name, phone, address, IP, date of birth, or occupational information, it makes it easier for an attacker to prepare a more personalized message. Therefore, the risk assessment was carried out not only based on the number of records but also on the usability of the fields together.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope was confirmed with the email address 442.519 dated March 2024. Verified data fields were retained while unconfirmed fields were excluded. Thus, the user is informed about the current record without being unduly alarmed, but without underestimating the actual risk.\u003C\u002Fp>\u003Cp>Because location history or details of family members were not verified in this record, these fields were not included in the description. If there are other incidents resembling the record by name, they were not merged into a single large incident. Domain name, company name, and industry information were kept in the narrowest correct context possible; this prevents duplicate or incorrectly associated breaches from being added.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk are those who have a Life360 account or users whose contact information is associated with the service. Matched users should consider not only the account in the relevant service but also other accounts where the same email, username, or password pattern is used.\u003C\u002Fp>\u003Cp>Parents and individuals managing a family account may face a higher social engineering risk in fake device verification and family group messages. For those registered with a corporate email address, the risk may extend beyond the individual account; attackers can send more convincing messages by using information such as name, role, phone, address, purchase, gaming ID, or professional profile. Therefore, users should not see the match as a problem limited to a single site.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should log in to their Life360 account directly through the app or the known website address and check their communication and security settings. For accounts with a password field, all accounts using the same password should be updated; for accounts without a password field, the focus should be on the risk of email, phone, and fake notifications. In both cases, the email account should be protected with a strong and unique password.\u003C\u002Fp>\u003Cp>Instead of clicking on the links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Messages such as verification codes received by phone, password reset requests, shipment, job offer, support, subscription, or security notifications should not be accepted without verification through an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In family safety practices, old phone numbers should be removed, account recovery emails should be protected, and family members should be informed about the rule of not sharing verification codes. Old accounts, unused phone numbers and address fields, recurring usernames, and identical password patterns should be regularly cleaned. Users should use a unique password for each service and enable two-factor authentication wherever possible.\u003C\u002Fp>\u003Cp>From the perspective of service providers, minimal data retention, strong password protection, monitoring of access logs, deletion of unnecessary profile fields, and user notification after a breach are fundamental requirements. In applications that provide location services, even communication data carries a high context of security. In such cases, accurate scope communication is as important as technical correction; exaggerated or incomplete information can mislead the user into taking the wrong action.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should first verify with the email address in this record. If a match is found, it should be assumed that name and phone information may be present in some records, and messages related to family and device security should also be verified. The absence of a match does not completely rule out repeated old passwords or the use of different emails associated with the same service; therefore, critical accounts should be reviewed separately.\u003C\u002Fp>\u003Cp>This record remained verified; however, the sensitive flag was left off because the verified fields did not contain location or password. In this arrangement, the data fields were left as English canonical classes, the description visible to the user was written in Turkish and original, unverified fields were not included, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","Life360 Data Breach (442.5 Thousand Reported Records)","Life360 Data Breach. 442.5 Thousand reported records were reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Flife360_com.webp",false,{"name":32,"sector":33,"country":34,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Life360","Family Safety \u002F Location Sharing","United States"]