Slide 15 of 28
Part 3 · Attack ScenariosSlide 15
Slide 15 · Scenarios 4–6
Fitness apps. Dating apps. Deliveries.
BOLA follows you into everyday life.
SCENARIO 04 · Fitness App
Your private workout data is anyone's to read.

A fitness tracking app stores workouts at /api/users/9921/workouts. Any logged-in user can change the ID and read another user's full activity history — weight, body stats, location of workouts, daily routine. This is exactly what happened with Peloton.

Why it matters: Workout location data reveals your home, your gym, your daily schedule. Combined with body stats, it's a detailed personal profile most people consider deeply private.
SCENARIO 05 · Dating App
A blocked user can still read your profile.

A dating app returns profile data at /api/profiles/7741. Even if user 7741 has blocked the requester, the API doesn't factor that in — it only checks "are you logged in?" Bumble had this exact issue in 2020. Researchers could also retrieve exact GPS coordinates.

Why it matters: Location data on a dating app is a safety issue. Stalking, harassment, and physical danger are real outcomes when someone's precise location leaks to someone they've blocked.
SCENARIO 06 · Delivery Service
You track someone else's package — and learn their address.

A delivery platform exposes tracking at /api/shipments/SH-40021. Changing the shipment ID returns another customer's name, delivery address, and package contents. Automated enumeration of shipment IDs maps thousands of real home addresses in minutes.

Why it matters: A home address tied to a specific delivery date tells a potential thief exactly when a package will arrive — and when someone will be home to receive it.
← Back Three more →