the tech buzz

SUBSCRIBE
AIEnterpriseDealsSecurityCrypto
Newsletter

the tech buzz

Your premier source for technology news, insights, and analysis. Covering the latest in AI, startups, cybersecurity, and innovation.

FOLLOW US

THE DAILY

Get the latest technology updates delivered straight to your inbox.

Company

  • About Us
  • Editorial Team
  • Write For Usnew
  • Contact Us
  • Advertisenew

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Disclaimer
  • EULA
  • AI Code of Conduct

Resources

  • Newsletters
  • RSS Feeds
  • Subscribe
  • Pricing & Packages
  • Sitemap
  • Archives
  • TechBuzz Pressnew

PUBLISH WITH US

Reach 1.1M+ subscribers via TechBuzz Press.

TechBuzz Press

HAVE A TIP?

Send us a tip using our anonymous form.

Send a tip

HAVE QUESTIONS?

Reach out to us on any subject.

Ask Now

Browse by Category

AIBlockchainCloudSecurityDataDealsInvestmentsEnterpriseVenturesIoTMobileRoboticsSoftwareStartupsAppleMetaMicrosoftOpenAiGoogleTesla

© 2026 The Tech Buzz. All rights reserved.

the tech buzz

Top iPhone app Neon exposes user call recordings in security breach

ArticlesNewsletters
ArticlesNewsletters
cybersecurity/privacy violation

Top iPhone app Neon exposes user call recordings in security breach

Viral call-recording app shut down after flaw exposed phone numbers and private calls

by The Tech Buzz

PUBLISHED: Thu, Sep 25, 2025, 9:51 PM UTC | UPDATED: Thu, Sep 3, 2026, 2:25 PM UTC

Add as a preferred source on Google
Top iPhone app Neon exposes user call recordings in security breach

A catastrophic security flaw in Neon, the viral call-recording app that rocketed to the top iPhone rankings, has exposed thousands of users' phone numbers, private call recordings, and transcripts to anyone with basic technical skills. The app, which pays users to record calls for AI training data, went dark Thursday after TechCrunch discovered the breach during routine testing and alerted founder Alex Kiam.

The rapid downfall of Neon underscores the dangerous intersection of AI data collection and inadequate cybersecurity practices. Just days after the app launched with promises of paying users for their call recordings to train AI models, a fundamental server misconfiguration left the most intimate digital conversations completely exposed.

TechCrunch uncovered the vulnerability during routine security testing Thursday, using network traffic analysis tools to examine how the app communicated with backend servers. The discovery was immediate and alarming - Neon's servers weren't preventing authenticated users from accessing anyone else's data, essentially turning user authentication into a master key for the entire database.

The scope of exposed data was comprehensive and deeply personal. Phone numbers, call durations, earning amounts, complete transcripts, and direct links to raw audio files were all accessible with simple API manipulation. In some cases, the breach revealed users making lengthy calls specifically to generate revenue through covert recording of real-world conversations with unsuspecting parties.

Kiam's response reveals the concerning disconnect between rapid growth ambitions and basic security practices. After TechCrunch alerted him to the flaw, he quickly shuttered the servers but sent users a misleading notification claiming the shutdown was for "extra layers of security" during "rapid growth" - completely omitting the actual breach.

Advertisement

"Your data privacy is our number one priority," Kiam wrote to users, according to the shutdown email shared with TechCrunch. The irony wasn't lost on security experts who noted that truly prioritizing data privacy would have meant implementing basic access controls before launch.

The incident exposes critical gaps in Apple's App Store review process, which apparently missed a security flaw so fundamental that it violated basic cybersecurity principles. The app's meteoric rise - gaining 75,000 downloads in a single day and reaching top-5 rankings - happened despite lacking elementary security measures that any competent developer should implement.

This isn't Apple's first challenge with problematic apps. The App Store has previously hosted apps with serious security issues, including Tea (a dating companion app that exposed 72,000 user images and identity documents) and location-tracking vulnerabilities in Bumble and Hinge that allowed stalkers to pinpoint users within two meters.

The broader implications extend beyond Neon's immediate user base. The app represents a growing trend of AI companies seeking conversational data for model training, often with minimal transparency about security practices. Users attracted by the promise of earning money for their voice data had no way to assess whether their most private conversations would remain secure.

Advertisement

Kiam's background raises additional questions about investor due diligence. His LinkedIn posts suggest backing from Upfront Ventures and Xfund, though neither firm responded to requests for comment about their investment criteria or security review processes. The silence suggests either inadequate due diligence or reluctance to associate with a portfolio company facing a major security incident.

The technical details of the breach reveal amateur-level mistakes. Network traffic analysis using standard tools like Burp Suite immediately revealed the vulnerability - something that basic penetration testing would have caught during development. The fact that publicly accessible audio file links were embedded in API responses shows a fundamental misunderstanding of data security principles.

What makes this breach particularly egregious is its preventability. Basic access control implementation - ensuring users can only access their own data - represents Security 101. The vulnerability wasn't sophisticated; it was the digital equivalent of leaving house keys in an unlocked front door.

The Neon incident serves as a stark reminder that the AI gold rush for conversational data cannot come at the expense of basic cybersecurity. As more startups chase the lucrative AI training market with user-generated content, the responsibility falls on both app store gatekeepers and investors to demand fundamental security practices before apps reach consumers. For users, this breach underscores the hidden costs of monetizing personal data - sometimes the price isn't just privacy, but complete exposure of your most private conversations to strangers with basic technical skills.

More Topics:
privacy violation

Advertisement

Advertisement

Trending Now

1

GoPro CEO Vows Cameras Stay Core After Starman Deal

2

Judge Splits Ruling in X vs. Twitter Rival Fight

3

Tim Cook Steps Down, Ternus Takes Apple's Helm

4

Google's Lyria 3.5 Brings AI Music to Gemini

5

Google Translate Gets Listening Mode, Live Background Mode

People Also Ask

Neon was a viral call-recording iPhone app that paid users to record calls for AI training data. It was shut down after a security breach exposed thousands of users' phone numbers, private call recordings, and transcripts to anyone with basic technical skills.

The Neon app gained 75,000 downloads in a single day and reached top-5 rankings in Apple's free iPhone apps before being shut down due to the security breach discovered by TechCrunch.

The breach exposed phone numbers, call durations, earning amounts, complete call transcripts, and direct links to raw audio files. Any logged-in user could access other users' private call recordings and personal information through simple API manipulation.

TechCrunch discovered the vulnerability during routine security testing using network traffic analysis tools. The flaw was immediately apparent - Neon's servers weren't preventing authenticated users from accessing anyone else's data through basic API manipulation.

No, Apple's App Store review process failed to detect the fundamental security flaw before approving Neon. The app reached top-5 rankings despite lacking basic access controls that violated elementary cybersecurity principles.

Alex Kiam is Neon's founder who took the servers offline after TechCrunch alerted him to the breach. He sent users a misleading shutdown notice claiming it was for "extra security layers" without disclosing the actual data breach.

More in cybersecurity

How To Prevent Account Takeover?

How To Prevent Account Takeover?

Coupang CEO Resigns After 34M Customer Data Breach

Coupang CEO Resigns After 34M Customer Data Breach

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes Customer Info in App Config Error

Petco Data Breach Exposes Customer Info in App Config Error

Marquis Ransomware Attack Hits 400K+ Bank Customers

Marquis Ransomware Attack Hits 400K+ Bank Customers

Okta beats Q3 earnings as AI agent push drives growth

Okta beats Q3 earnings as AI agent push drives growth

More Articles

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Dec 2

Coupang Data Breach Hits 34M Users in Months-Long Attack

Coupang Data Breach Hits 34M Users in Months-Long Attack

Dec 1

London Councils Hit by Major Cyberattack, Emergency Plans Activated

London Councils Hit by Major Cyberattack, Emergency Plans Activated

Nov 26

Tyler Technologies jury system bug exposed juror data across US

Tyler Technologies jury system bug exposed juror data across US

Nov 26

Major Banks Assess Data Theft After SitusAMC Breach

Major Banks Assess Data Theft After SitusAMC Breach

Nov 24

Corporate America ditches passwords as 92% of CISOs go passwordless

Corporate America ditches passwords as 92% of CISOs go passwordless

Nov 23