Popular Wi-Fi Hotspot Finder App Leaks Over 2 Million Wi-Fi Network Passwords: Report

Advertisement
By Harpreet Singh | Updated: 23 April 2019 15:18 IST
Highlights
  • A free, popular Android app stored millions of Wi-Fi network passwords
  • The database was taken down by the app's web host DigitalOcean
  • The app even displays private Wi-Fi network passwords in plain text

The Android app lets users upload their Wi-Fi network passwords and displays them in plain text

A popular Android app used for finding nearby Wi-Fi hotspots seems to have exposed over two million wireless networks. The app allows users to locate nearby public Wi-Fi hotspots so they can save their precious mobile data. Users can also upload their own Wi-Fi passwords to the app's database to share their network with others. It appears that over two million Wi-Fi network passwords were stored in plain text on a server, letting anyone download the database.

As reported by TechCrunch, an Android app based in China had collected more than two million Wi-Fi passwords from users across the globe. The app called 'WiFi Finder' has over 100,000 users, according to its listing on the Google Play Store.

This database of Wi-Fi networks includes the network name, geolocation data, and passwords stored in plain text, apart from other details.

Advertisement

'WiFi Finder' claims to offer public Wi-Fi hotspot details to its users, but it seems like the app has also been collecting passwords to home networks in residential areas.

Advertisement

The database was first discovered by Sanyam Jain, a security researcher, according to TechCrunch. Both Jain and TechCrunch tried to reach out to the Chinese company which created the app but were unsuccessful. They ended up asking DigitalOcean, which hosts the app, and they took down the database quickly.

The free 'WiFi Finder' app displays wireless network passwords in plain text

Advertisement

 

We tried out the app for ourselves and found numerous private Wi-Fi networks listed on the app, along with passwords displayed in plain text. There were some public Wi-Fi hotspots as well, but you could still easily make out residential Wi-Fi networks.

Advertisement

The 'WiFi Finder' app lists hundreds of Indian personal Wi-Fi networks as well. One can easily navigate across a map and locate Wi-Fi networks with passwords presented in plain text. The owner of the Wi-Fi network doesn't need to grant users any additional permissions. It's likely that all these users uploaded their private Wi-Fi networks via the app.

If someone gets access to your network, they can easily modify your router's settings, read unencrypted traffic on your network, switch DNS servers, and more.

We were able to spot Wi-Fi networks belonging to a police station, a public sector bank, several residential areas, apart from public Wi-Fi networks. However, some of these networks may have switched passwords or become unavailable over time. We haven't tested if these passwords actually work.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. OnePlus 15R Confirmed to Come With 32-Megapixel Selfie Camera
  1. Kepler and TESS Discoveries Help Astronomers Confirm Over 6,000 Exoplanets Orbiting Other Stars
  2. Supernatural Thriller Jatadhara Arrives on OTT: Where to Watch Sonakashi Sinha-Starrer Film Online?
  3. OnePlus 15R Confirmed to Come With 32-Megapixel Selfie Camera, 4K Video Recording Support
  4. Rocket Lab Clears Final Tests for New 'Hungry Hippo' Fairing on Neutron Rocket
  5. Apple Rolls Out iOS 26.2 Update for iPhone With Liquid Glass Customisation, Changes to Apple Music, and More
  6. Aaromaley Now Streaming on JioHotstar: Everything You Need to Know About This Tamil Romantic-Comedy
  7. Astronomers Observe Star’s Wobbling Orbit, Confirming Einstein’s Frame-Dragging
  8. Galaxy Collisions Found to Activate Supermassive Black Holes, Euclid Data Shows
  9. JWST Detects Oldest Supernova Ever Seen, Linked to GRB 250314A
  10. Chandra’s New X-Ray Mapping Exposes the Invisible Engines Powering Galaxy Clusters
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.