Apps and Location Tracking: What Are the Consequences?

Introduction
Of the many digital traces we leave in daily life, location metadata may be the most revealing. Location tracking is common in many applications because it’s so useful – it can allow you to get directions from here to there, discover the closest restaurants near you, or tell you your local weather conditions. These perks, however, can come with large privacy risks.
Companies that you would never suspect needing so much of your data, are quietly collecting enormous amounts of data. For example, in 2020, an investigation was done on Tim Hortons, as the Tim Hortons app reportedly tracked an individual’s location more than 2,700 times in five months. Commissioners say Tim Hortons collected “vast amounts” of granular location data with the aim of delivering targeted advertising, to better promote its coffee and associated products, but that it never actually used the data for this purpose.
Some of the apps on our phone sell or share location data about their users with companies that analyze the data and sell their insights. There are many ways location data can be used, and the market for this data is huge – the location data industry is an estimated $12 billion market. Collectors, aggregators, marketplaces, and location intelligence firms are potential buyers interested in your location data.
What is being collected?
Some apps genuinely need your location to work properly, but others have different motives. Many collect location data for reasons unrelated to their main function, like targeted ads or selling it to data brokers.
Once an app collects your location data, you lose control over where it goes. It can be sold repeatedly—from data providers to aggregators that combine information from multiple sources. It could end up in the hands of a “location intelligence” firm that uses the raw data to analyze foot traffic for retail shopping areas and the demographics associated with its visitors.
You might think, “I have nothing to hide.” But location data can reveal much more than you realize, such as:
- Where you get medical treatment and what kind
- If you visit a domestic abuse shelter
- Where you worship
- Where your kids play (if they have phones)
- When you’re on vacation and where you go
- Where you shop, eat, and bank
- Who you spend time with
Even though this data isn’t directly linked to your name, experts have shown that it’s easy to match location history with other data to identify people and their habits. In 2020, a religious publication used smartphone app data to infer the sexual orientation of a high-ranking Roman Catholic official. The publication claimed it obtained “commercially available” location data from an unnamed vendor and linked it to the priest’s phone, revealing visits to gay bars and private residences while using Grindr, a dating app popular with the LGBTQ+ community.
Privacy advocates have long cautioned that advertisers gather location and personal data, which is then compiled and sold by data brokers. This information can be used to identify individuals and is not subject to regulations requiring clear consent from those being tracked.
What can I do to limit location tracking?
The quickest and easiest way to reduce tracking is to delete unnecessary apps. Both Android and Apple allow you to check which apps have access to your location and whether they track it only while in use or all the time. If you don’t use an app often, consider removing it.
Your location can be tracked through your phone, logged-in accounts, internet connection, and location services. To limit oversharing, take these steps:
- Only allow location access for apps that truly need it.
- Set location permissions to “While Using the App” instead of “Always.”
- Only share “Find My Phone” with trusted friends and family.
- Review third-party apps in location settings—you might be sharing more than you realize.
Despite these precautions, location tracking can’t be completely eliminated. It’s important to support companies that provide clear and transparent privacy policies.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.
%20(1).png)
Protect your digital life by detecting risks before they escalate
Richter Guardian gives you enterprise-level cybersecurity tailored for individuals, families, and executives.

Related posts

What happened
A Calgary investor is suing TD Waterhouse Canada Inc. after fraudsters allegedly broke into his TD Direct Investing accounts while he vacationed in Hawaii.
According to The Globe and Mail, the intruders sold his holdings and poured more than $5 million into a thinly traded Hong Kong stock.
When it collapsed, he lost roughly $4.5 million in retirement savings.
TD says he either made the trades himself or failed to secure his account. Nothing has been proven in court, but the case shows how fast wealth can vanish once login credentials fall into the wrong hands.
Why this keeps happening
This isn't an isolated incident.
TD Bank has faced other serious regulatory scrutiny in recent years, and securities fraud attorneys continue to field claims from investors who say controls failed them.
Banks guard their own core systems closely, but the real weak points are often somewhere else: the client's personal devices, account passwords, and email accounts, all sitting outside the bank's oversight and controls.
Why travel makes you a target
It's worth pausing on the timing here: the alleged fraud happened while the investor was away in Hawaii. That's not a coincidence worth overlooking.
Vacations pull people out of their normal routines on purpose, and that's exactly what makes them good for rest, and terrible for security.
At home, most people have habits without even thinking about them: checking accounts over morning coffee, noticing a strange email between meetings, recognizing when something on a statement looks off.
Travel disrupts every one of those habits at once:
- You're on hotel or airport Wi-Fi, which is rarely as secure as your home network.
- You're checking email and banking apps quickly, often on borrowed time between activities, so a suspicious login alert can get skimmed past instead of read carefully.
- Time zone changes mean notifications may arrive at 3 am and get dismissed unread.
Many people intentionally "unplug" from their finances while traveling, treating vacation as a break from monitoring entirely.
Fraudsters understand this pattern well. Account takeovers cluster around known absences: holidays, long trips and/or business travel.
A window of even a few days without anyone watching an account closely is often all it takes to sell off holdings and move funds into a single volatile position, which is exactly what allegedly happened in this case.
None of this means people shouldn't travel or unplug — they should. It means the monitoring can't rely on the account owner remembering to check in from a beach in Hawaii.
Steps you can take right now
Basic habits, especially before and during travel, meaningfully reduce your own risk:
- Turn on multi-factor authentication for every brokerage, banking, and email account.
- Use a unique, strong password for each financial account — never reuse them.
- Avoid logging into financial accounts on public or hotel Wi-Fi while traveling.
- Set up account alerts for trades, withdrawals, and login attempts before you leave.
- Designate someone you trust to glance at statements while you're away.
- Review account activity closely in the days right after returning.
- Ask your brokerage about limiting or freezing margin trading if you rarely use it.
Where personal habits aren't enough
Even careful people get targeted, especially the moment they step away from their routine.
This is a gap Richter Guardian is built to close.
Corporate and bank-side security stops at the workplace door — it doesn't watch the personal phone, laptop, or email account a fraudster actually needs.
Richter Guardian's monitoring and prevention service watches continuously, including while clients travel, for compromised credentials and suspicious activity. If something looks wrong, clients aren't left to figure it out alone.
Our incident response team, the Cyber Defence Desk, is reachable via phone, email, video or a mobile app to explain what's happening and guide next steps.
The bottom line
Vacations should mean rest, not vigilance. For high-net-worth individuals and families with complex accounts and multiple devices, someone still needs to be watching while you're not. Protection shouldn't stop where your routine does.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Cheaper Cyber Insurance, Costlier Risk: The Family Office Coverage Gap
The cyber insurance market is softening just as the threats driving demand for it accelerate.
Premiums are falling, yet more than 40% of cyber claims are now denied — most often because controls attested to on the application were never actually in place.
For family offices, with their informal governance and concentrated wealth, a cheaper policy is increasingly a policy that will not pay.
The defensible position for family offices is verifiable security controls, not a lower premium.
The market contradiction
Reporting from the Family Office Cybersecurity Forum in New York describes a market where competition is outpacing risk. New entrants including major carriers have pushed prices down, and average premiums were projected to fall a further 11% in 2026.
Buyers are being advised to shop around — but price is now the least important variable.
The frequency and severity of losses continue to climb even as rates drop, and the early signs suggest the rate of decline is starting to slow.
By the numbers
- ~50% of US family offices were hit by a cyberattack in 2025.
- 40%+ of cyber insurance claims are currently being denied — driven by missing controls, late notification and absent policy provisions, not exclusions.
- ~75% of carriers now run external attack surface scans during underwriting, replacing self-attestation.
- $713K average global ransomware claim in 2025 — nearly double the $374K recorded in 2024.
- 60% of family offices are confident their staff can detect and prevent AI-powered attacks.
- 2,137% rise in deepfake-driven fraud attacks since 2022; now 6.5% of all fraud.
Why family offices are uniquely exposed
Forum specialists characterized family offices as structurally vulnerable in ways that standard commercial cyber exposure does not capture.
The same traits that make a family office efficient make it exploitable:
- Cultures of informal approval and trust-based authorization.
- Heavy reliance on personal assistants and a small circle of staff.
- A bias toward speed over documented process.
- Multi-generational structures that widen the attack surface and blur accountability.
Layered on top is an AI-driven threat surface: deepfake voice impersonation of principals, AI-generated phishing, and business email compromise.
The FBI logged a 37% rise in AI-assisted BEC incidents using cloned executive voices, and attackers can now sit undetected inside a compromised environment for 100 days or more.
The regulatory squeeze
Family offices and their advisers face a tightening regulatory environment that mirrors what insurers already demand.
Amendments to the SEC's Regulation S-P took effect for smaller registered investment advisers on June 3, 2026, introducing a written incident response program, a 30-day customer breach notification obligation, and expanded vendor oversight.
The SEC's examiners have named S-P compliance a 2026 priority.
The controls the regulator now mandates are in most cases, the same controls cyber insurers require for a claim to be honored. One program satisfies both.
How Richter Guardian can help family offices
- Controls verification and attestation readiness — ensuring what you tell underwriters is true and evidenced.
- External attack surface assessment aligned to carrier underwriting scans.
- Regulation S-P alignment: written incident response program, breach notification readiness, vendor risk oversight.
- Human-layer defence against deepfake and AI-enabled social engineering, including principal and staff awareness.
- Ongoing managed monitoring so that controls stay in place between renewals.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

Understanding Business Email Compromise: Why Trusted Emails Still Need Verification
Business Email Compromise, or BEC, is a targeted scam in which a criminal impersonates someone you trust. They may pose as an executive, lawyer, vendor, advisor, employee, or family member and ask you to send money, change banking details, or share sensitive information.
The message may come from a lookalike email address or a real account that has been compromised. This can make the request appear normal and include details that only a trusted person would seem to know.
Executives, high-net-worth individuals and their families, and anyone able to move money or release sensitive information are valuable criminal targets. AI-written emails and voice cloning can make these scams even more convincing.
How it works
An attacker sends a message that appears to come from someone you know. It is designed to seem routine or urgent so that you act before confirming the request another way.
If a real email account has been compromised, the attacker may review conversations, invoices, contacts, and travel details. They can use this information to create a convincing request at the right time.
The risk works both ways. You may receive a fraudulent message, or your own account may be taken over and used to contact others in your name.
Why BEC is a major threat
According to the FBI Internet Crime Complaint Center’s 2025 Annual Report, BEC led to 24,768 reported complaints and more than $3 billion in reported losses in 2025. Only investment fraud caused greater reported losses that year.
BEC is also becoming harder to identify. AI can create professional messages without the spelling mistakes or awkward wording often linked to scams. Voice cloning may also make a call or voice message sound like someone you know.
Warning signs of business email compromise
Watch for:
- Urgency combined with secrecy
- New or changed payment or banking details
- A reply-to address that differs from the sender’s address
- A request that skips the normal approval process
- Pressure to move the conversation to text or WhatsApp
- An unusual request for sensitive information
A message from a compromised account may not show any of these signs. Verifying the request is more reliable than deciding whether the email looks suspicious.
How to protect yourself
Confirm every new payment instruction, banking change, or urgent transfer by calling the person directly. Use a number saved in your contacts, shown on a previous statement, or obtained from another trusted source.
Never use a number provided in the same email as the request.
During the call, confirm the payment amount, recipient, bank, account details, and reason for the transaction. Be especially careful if any information has changed.
Require approval from a second trusted person for payments above a set amount. Everyone involved should be expected to pause and verify a request, even if this causes a short delay.
Protect every email account including personal accounts, with a strong, unique password and multi-factor authentication. Keep recovery information current and check for unfamiliar forwarding rules, filters, connected applications, or signed-in devices. Do not reuse your email password on other services.
If you have been targeted
If you sent money or shared banking information, contact your financial institution immediately. Ask whether the payment can be stopped, recalled, or frozen. Keep the original emails, messages, and payment records.
If you believe your email account was compromised:
- Change the password from a trusted device.
- Sign out of other active sessions.
- Review the account’s security and recovery settings.
- Remove unfamiliar rules or connected applications.
- Notify anyone who may have received a fraudulent message from your account.
How Richter Guardian can help you
Richter Guardian can help reduce BEC risk by monitoring for exposed credentials and identifying impersonation attempts, including lookalike domains, websites, or accounts created in your name.
We can also help secure your accounts, review suspicious requests, and provide guidance if you believe an account has been compromised.
If you receive a suspicious email, payment request, banking change, or request for sensitive information, contact us before taking action.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.
.png)
