the tech buzz

SUBSCRIBE
AIEnterpriseDealsSecurityCrypto
Newsletter

the tech buzz

Your premier source for technology news, insights, and analysis. Covering the latest in AI, startups, cybersecurity, and innovation.

FOLLOW US

THE DAILY

Get the latest technology updates delivered straight to your inbox.

Company

  • About Us
  • Editorial Team
  • Write For Usnew
  • Contact Us
  • Advertisenew

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Disclaimer
  • EULA
  • AI Code of Conduct

Resources

  • Newsletters
  • RSS Feeds
  • Subscribe
  • Pricing & Packages
  • Sitemap
  • Archives
  • TechBuzz Pressnew

PUBLISH WITH US

Reach 1.1M+ subscribers via TechBuzz Press.

TechBuzz Press

HAVE A TIP?

Send us a tip using our anonymous form.

Send a tip

HAVE QUESTIONS?

Reach out to us on any subject.

Ask Now

Browse by Category

AIBlockchainCloudSecurityDataDealsInvestmentsEnterpriseVenturesIoTMobileRoboticsSoftwareStartupsAppleMetaMicrosoftOpenAiGoogleTesla

© 2026 The Tech Buzz. All rights reserved.

the tech buzz

Tile's 88M Users Face Mass Surveillance Risk From Unencrypted Tags

ArticlesNewsletters
ArticlesNewsletters
Security

Tile's 88M Users Face Mass Surveillance Risk From Unencrypted Tags

Security researchers expose critical flaws in Tile tracking system allowing stalking

by The Tech Buzz

PUBLISHED: Mon, Sep 29, 2025, 10:04 AM UTC | UPDATED: Thu, Sep 3, 2026, 8:33 PM UTC

Add as a preferred source on Google
Tile's 88M Users Face Mass Surveillance Risk From Unencrypted Tags

Georgia Tech researchers just exposed serious security flaws in Tile's tracking network that could enable mass surveillance of its 88 million users worldwide. The team found that Tile transmits unencrypted location data, MAC addresses, and device IDs - giving stalkers and potentially law enforcement the ability to track users despite the company's privacy claims. This puts Tile users at significantly higher risk than competitors like Apple AirTags.

The tracking device industry just got hit with a bombshell security report that exposes how Tile's popular location tags create a massive surveillance risk for their 88 million users worldwide. Georgia Tech researchers Akshaya Kumar, Anna Raymaker, and Michael Specter spent months reverse-engineering Tile's system and found fundamental design flaws that competitors like Apple, Google, and Samsung specifically avoid.

The core problem is encryption - or rather, the lack of it. While Apple's AirTags and Google's Find My Device network encrypt all broadcast data and location reports, Tile transmits everything in plaintext. Each Tile tag continuously broadcasts its MAC address and unique ID unencrypted, allowing anyone with a Bluetooth antenna or modified Tile app to intercept and track these signals.

"An attacker only needs to record one message from the device to fingerprint it for the rest of its lifetime," Kumar told WIRED. This creates what the researchers call "systemic surveillance" risk for anyone carrying a Tile device or Tile-enabled products from Dell, Bose, and Fitbit.

The surveillance capability extends far beyond individual bad actors. Law enforcement could potentially use this vulnerability to identify anyone in a specific area who carries a Tile device, while the company itself appears to maintain the technical capability to track all users despite privacy policy claims stating "you are the only one with the ability to see your Tile location."

The researchers believe location data gets stored unencrypted on Tile's servers, transforming what should be a simple lost-item finder into what they describe as "Tile's infrastructure into a global tracking network." This stands in stark contrast to competitors who use end-to-end encryption specifically to prevent companies from accessing user location data.

Advertisement

Apple, Google, and Samsung have "designed their system intentionally such that they aren't able to recover your location," researcher Michael Specter explained. "Because they don't want to be in the business of knowing where all people are at all times."

But Tile's security problems go deeper than just encryption. The researchers discovered that Tile's anti-stalking protection - designed to alert users when unknown tracking devices follow them - can be easily circumvented through the company's anti-theft feature. When a Tile owner enables anti-theft mode to hide their tag from potential thieves, it also becomes invisible to anti-stalking scans, effectively allowing stalkers to hide their tracking devices.

This creates a unique vulnerability that other tracking device makers avoid by simply not offering anti-theft modes. "That's a compromise that these companies are willing to make in order to have stronger anti-stalking properties," Kumar noted.

The anti-stalking system itself has significant limitations compared to competitors. While Apple and Google devices continuously scan for unknown trackers and automatically alert users, Tile's "Scan and Secure" feature requires manual activation, runs for only 10 minutes, and must be periodically restarted by users who remember to do so.

Advertisement

Tile attempts to address anti-theft mode abuse by requiring government ID verification and threatening users with a $1 million fine for stalking. But the company's terms contain contradictory statements about sharing user information with law enforcement - sometimes requiring warrants, other times allowing sharing "at our discretion, even without a subpoena."

The researchers also discovered that attackers could frame innocent Tile users for stalking through "replay attacks" - recording a legitimate device's unencrypted broadcasts and retransmitting them near potential victims to make it appear the original owner is stalking them.

These findings take on added significance given that a study published last year found over 40 percent of stalking victims had been tracked using Bluetooth tags hidden in cars, purses, or backpacks. The research team reported their findings to Tile's parent company Life360 in November 2024, but communication stopped in February 2025.

When WIRED contacted Life360 for comment, the company provided only a generic response stating they had "made a number of improvements" without specifying what those improvements were or whether they addressed the fundamental encryption issues.

The Tile vulnerability report highlights a growing divide in the tracking device industry between companies prioritizing user privacy and those maintaining surveillance capabilities. While competitors have moved toward zero-knowledge architectures that prevent even the companies themselves from tracking users, Tile's approach creates systemic risks for millions of people who simply want to find lost keys. For users concerned about privacy and stalking protection, the research suggests switching to encrypted alternatives from Apple, Google, or Samsung until Tile addresses these fundamental design flaws.

Advertisement

Advertisement

Trending Now

1

GoPro CEO Vows Cameras Stay Core After Starman Deal

2

Judge Splits Ruling in X vs. Twitter Rival Fight

3

Tim Cook Steps Down, Ternus Takes Apple's Helm

4

Google's Lyria 3.5 Brings AI Music to Gemini

5

Google Translate Gets Listening Mode, Live Background Mode

People Also Ask

Georgia Tech researchers discovered that Tile's 88 million tracking devices broadcast unencrypted MAC addresses and IDs, store location data in cleartext on servers, and allow anti-stalking protection to be bypassed through anti-theft mode, enabling mass surveillance and stalking risks.

Unlike Apple AirTags and Google Find My devices that encrypt all broadcast data and location reports, Tile transmits everything in plaintext and stores unencrypted location data on servers, making users vulnerable to surveillance and tracking attacks.

Yes, stalkers can bypass Tile's anti-stalking protection by enabling anti-theft mode, which hides tracking devices from detection scans. Additionally, Tile's "Scan and Secure" feature requires manual activation and only runs for 10 minutes, unlike competitors' automatic continuous scanning.

Tile's security vulnerabilities affect 88 million users worldwide who use Tile tracking devices or Tile-enabled products from companies like Dell, Bose, and Fitbit, potentially exposing them to mass surveillance and stalking risks.

Life360, Tile's parent company, initially received the security report in November 2024 but stopped responding to Georgia Tech researchers in February 2025. The company only provided generic statements about "improvements" without specifying fixes for fundamental encryption issues.

Security experts recommend switching to Apple, Google, or Samsung tracking devices because they use end-to-end encryption and zero-knowledge architectures that prevent even the companies from tracking users, unlike Tile's plaintext system that creates surveillance risks.

More in Security

ClarityCheck Exposes 9M+ Facial Images in Database Breach

ClarityCheck Exposes 9M+ Facial Images in Database Breach

Apple spyware alerts hit 'unprecedented' number of users

Apple spyware alerts hit 'unprecedented' number of users

Military Apps Expose US Troops to Foreign Code From China, Russia

Military Apps Expose US Troops to Foreign Code From China, Russia

Russia Used Cellebrite Tools After Promised Cutoff

Russia Used Cellebrite Tools After Promised Cutoff

Spotify Exploited: Fake Podcasts Boost Illegal Drug Sites

Spotify Exploited: Fake Podcasts Boost Illegal Drug Sites

7-Eleven data breach affects over 185,000 people’s personal data

7-Eleven data breach affects over 185,000 people’s personal data

More Articles

These special phone and app features can help protect you from spyware

These special phone and app features can help protect you from spyware

May 23

Adobe patches PDF zero-day exploited since November

Adobe patches PDF zero-day exploited since November

Apr 14

Hack-for-hire group exposed targeting Android and iCloud users

Hack-for-hire group exposed targeting Android and iCloud users

Apr 8

Money Transfer App Duc Exposes Thousands of IDs on Open Server

Money Transfer App Duc Exposes Thousands of IDs on Open Server

Apr 2

WhatsApp Alerts 200 Users Hit by Italian Government Spyware

WhatsApp Alerts 200 Users Hit by Italian Government Spyware

Apr 1

Iranian Hackers Breach FBI Director Kash Patel's Gmail Account

Iranian Hackers Breach FBI Director Kash Patel's Gmail Account

Mar 27