Dalil, a caller ID Android app for Saudi and other Arabian users with 5M+ downloads, has exposed user data, including some GPS coordinates, for more than week
Catalin Cimpanu / ZDNet : Tweets: @zdnet , @cipherstorm , @lukasstefanko , and @zackwhittaker Tweets: @zdnet : Saudi caller ID app leaves data of 5+ million users in unsecured MongoDB server https://zd.net/2ThZHoL by @campuscodi @cipherstorm : Saudi caller ID app leaves data of 5+ million users in unsecured MongoDB server: Database is still available online after failed attempts to contact the app maker. http://www.zdnet.com/... http://twitter.com/... Lukas Stefanko / @lukasstefanko : “Dalil App” with over 5,000,000 installs leaks over 585,7GB of users data through not secured MongoDB. Leaks: phone numbers user names emails IP GPS location call logs ... Developer didn't fix the issue, maybe it's time to start using different app. http://www.zdnet.com/... http://twitter.com/... Zack Whittaker / @zackwhittaker : Wow, fuck. http://www.zdnet.com/...
Context & Ripple Effects
Dalil is the latest entry in a recurring failure mode: popular Android apps that harvest contact and location data and then leave it on an open cloud database. The template was set by the AI.type keyboard leak, which spilled 577GB from 31M users including hundreds of millions of phone numbers, and repeated with Family Locator's weeks-long real-time location exposure just weeks after this story.
First-order effects
- Over 5 million users — largely in Saudi Arabia and other Arabian countries — have their phone numbers, emails, IP addresses, call logs and some GPS coordinates sitting on a publicly reachable MongoDB server.
- The developer has not responded to researcher contact attempts, so the database remained live for more than a week after disclosure, meaning anyone could have copied the full dataset before a fix.
Second-order effects
- Call logs paired with GPS coordinates make this leak directly usable for doxing, phishing and surveillance of identifiable individuals, not just spam lists — raising the stakes beyond the AI.type-style contact dump.
- Google Play's review of high-permission utility apps faces pressure: caller ID apps justify broad call and location access on functionality grounds, and each incident like Dalil's makes that trade harder to defend.
Third-order effects
- If the pattern holds, misconfigured cloud storage becomes the dominant leak vector for mobile apps' richest data — contacts, calls, movement — pushing regulators toward rules on where and how consumer apps may store collected data.
- Exposed location-and-call datasets feed the broader market for granular human-movement data documented in the US military's purchase of app-derived location data, turning one developer's security lapse into raw material for third-party buyers.
The trend: Consumer Android apps that collect contacts, call logs and location keep leaking them through unsecured cloud databases, with unresponsive developers stretching each exposure window from days into weeks.