“Gotta Catch em All” – Pokemon Go’s Huge Cyber Vulnerability

Pokemon Go | Nintendo Mobile App

The Pokemon Go phenomena is real. Players of the mobile device augmented reality “scavenger hunt” app are out on the streets in droves hunting down Pikachu, Psyduck, Bulbasaur, Charmander and other elusive Nintendo based cartoon characters. Chances are you or someone you know is playing the game…don’t lie, you’re playing it aren’t you? The mobile game developed by Nintendo partner Niantic has caused Nintendo’s stock to jump 36% adding $7 billion to its market cap.

This week, news broke that the app may actually contain a gaping hole in its security settings that allows the developer (Niantic Labs) to read and send Google emails, view, edit, delete docs in Google Drive, and see Google browser history details. Apparently, Niantic used an outdated Google shared sign-services version during the development of the app in order to make the account creation more convenient for players. Niantic by-passed the step that allows users to customize the permissions in the app and simply warned players that the app had “full access” to their accounts.

Don’t rush to delete the app. Your Pokemon hunting days are not yet over.  Niantic has confirmed that the wording “full access” is misleading and only basic data such as user ID and email are being collected and that Google will soon change the app so it notes that it is only collecting “basic” Google profile information.

Last week I published the blog “Is your Mobile Device Putting Your Company at Risk?” noting that this very scenario could lead to a major cyber breach. Many mobile applications will contain security vulnerabilities or exploitable holes in their development allowing hackers a way into your network or access to your or your clients confidential data.

As I also mentioned in that prior blog, mobile security practices must be included in your cyber risk mitigation strategies.

Click here if you’d like help with structuring your Cyber Risk program or to request more information about The ALS Group.

Our areas of expertise include:

  • Enterprise Risk Management (ERM)
  • Cyber Security & Cyber Liability Insurance
  • Construction Management
  • Customized Risk Management Assessments (RMAs)

Subscribe to our articles

blog posts form
Form Submission Response

Dear [field id="name"],

Thank you for subscribing to The ALS Group articles! We are so excited to have you on board and look forward to providing you with valuable insights, risk management advice, and industry news.

As a subscriber, you will be the first to receive our latest blog posts straight to your inbox. In addition to the blog content, we have a wealth of resources on our website that we believe will be useful to you.

If you have any questions or require any risk management advice, please contact Albert Sica, Managing Principal, at [email protected] or at 732-395-4251.

Thank you,

The ALS Group

Skip to content