US police app SweepWizard, built by ODIN, leaked data, including location and names, on officers, 5,770 suspects, and others due to a simple misconfiguration
SweepWizard, an app that law enforcement used to coordinate raids, left sensitive information about hundreds of police operations publicly accessible. Tweets: @justinhendrix , @dmehro , @matthewkeyslive , and @dellcam Tweets: Justin Hendrix / @justinhendrix : SweepWizard. It's called.... SweepWizard. Good lord. https://twitter.com/... Dhruv Mehrotra / @dmehro : NEW: An app used by the LAPD exposed the details of hundreds of confidential law enforcement raids likely before they happened. https://www.wired.com/... Matthew Keys / @matthewkeyslive : A law enforcement tool used to coordinate police raids was removed from the Apple and Google app stores after @wired found that it was leaking information about suspects before the raids occurred. https://www.wired.com/... Dell Cameron / @dellcam : Scoop by @dmehro at WIRED about an app leaking information about police raids — before they happen https://www.wired.com/...
Context & Ripple Effects
SweepWizard, built by vendor ODIN and used by departments including the LAPD, coordinated raids through a consumer-style mobile app — and a simple misconfiguration left officer names, locations, and records on 5,770 suspects openly accessible, apparently before some operations were even carried out.
The leak fits a documented pattern: local police have adopted third-party tools like the Fog Reveal phone-tracking service with little security or warrant scrutiny, and days after this report hackers went further, breaching ODIN's servers themselves and dumping raid plans, confidential reports, and AWS private keys.
First-order effects
- Officers whose names and locations were exposed face immediate operational risk — raid targets could learn of operations in advance, undermining ongoing investigations.
- Departments using SweepWizard, including the LAPD, must audit what their personnel uploaded and decide whether to keep coordinating sensitive operations on an app that failed at basic configuration.
Second-order effects
- The follow-on breach of ODIN's servers compounds the damage for every agency on its customer list, turning one misconfiguration into a full compromise of the vendor's own infrastructure.
- Police technology buyers now face pressure to apply procurement-grade security review to small-vendor apps, the same scrutiny already demanded over tools like Fog Reveal used without warrants.
Third-order effects
- If the pattern holds across SweepWizard, Fog Reveal, and Intrepid Response, lightly governed third-party software becomes a systemic weak point in US policing, likely drawing state-level procurement rules and legislative oversight of law-enforcement tech vendors.
The trend: US law enforcement is adopting third-party surveillance and coordination apps faster than any security, procurement, or legal framework can govern them.