logo

BLU settles with FTC over unauthorized transmission of personal customer data to China

ID: bef15f4d-9804-5640-a99b-43831d388b38

STIX ID: report--bef15f4d-9804-5640-a99b-43831d388b38

Feed Name: Security Ledger

Threat Score
72/100

Date Published: 2018-05-01

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

Security firm Kryptowire found that ADUPS firmware preinstalled on BLU phones periodically transmitted sensitive user data — including full text message content, real‑time location, call/text logs with numbers, contact lists, and app usage — to servers in China; because the update software ran with elevated permissions it could also reprogram devices and contained vulnerabilities that could allow full device compromise. The FTC investigated and filed a complaint, alleging BLU failed to adequately oversee its third‑party provider and misled consumers, and the company agreed to a proposed settlement requiring long‑term security controls and third‑party assessments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.