Skip to main content
  1. Home
  2. Phones
  3. Mobile
  4. News

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

This vaccine passport app data breach is a cautionary tale

A security blunder by proof-of-vaccination app Portpass provides a reminder that third-party apps may not protect your privacy and security. According to CBC News, Portpass exposed potentially hundreds of thousands of users’ personal information on its unsecured website.

After receiving a tip that the user profiles on the app’s website were accessible by members of the public, CBC verified the claim. While on the website, CBC was able to see users’ personal information, email addresses, blood types, birthdays, phone numbers, and photo identification, including driver’s licenses and passports.

Recommended Videos

This came after the company’s CEO, Zakir Hussein, denied that the app had security issues and “accused those who raised concerns about it of breaking the law.”

CBC gave Hussein and his company time to fix the lapse before publishing its article. The following morning when Hussein addressed the issue, he claimed that the breach only lasted for a few minutes, despite CBC reviewing the personal information for more than an hour —  after someone tipped them off. In light of this, it’s unclear how long the information was exposed.

Security problems expert saw coming

When CBC interviewed cybersecurity analyst Ritesh Kotah about the Portpass security problems, he shed some light on the issue.

“These were exactly the privacy and security concerns I’ve previously raised when it comes to third-party apps. You’ve gotta ask yourself, ‘Where’s the data housed? Who has access to it? Is it encrypted?’” Kotak said. He also addressed the risks to users whose information was exposed: “It opens them up to fraud, identity theft, and a whole other world of potential issues.”

But people do have to prove their vaccination status sometimes, and since there is no official proof-of-vaccination app for Alberta, Canada, residents, they get funneled toward third-party apps. More than 200,000 Canadians preregistered for Portpass by mid-June. Three months later, Portpass has more than 650,000 registered users, according to Hussein.

The Calgary Sports and Entertainment Corporation recommended Portpass to ticket-holders for games at Scotiabank Saddledome and McMahon Stadium. The recommendation has been removed, but in a Reddit post dated five days before CBC learned of the breach, one user warned against downloading the app. They pointed out that Portpass’ privacy policy didn’t guarantee adherence to Alberta’s Health Information Act or other federal legislation, stating only that they use the “highest security.” The user concluded: “Using this service and trusting them to properly protect your personal health care information would be a huge mistake.”

What now?

Users who fear their information may have been compromised should notify the Office of the Privacy Commissioner of Canada. According to IT World Canada, Alberta privacy commissioner’s office is in communication with Portpass as the company investigates the breach.

Sandra Stafford
Sandra Stafford is a Mobile team writer. She has three years of experience writing about consumer technology. She writes…
You could soon ask ChatGPT how healthy your week really was
A rumored Apple Health integration would let AI read your activity and sleep data.
Apple iPhone with Apple Watch Using both

What’s happened? Even though Apple might be moving on to Gemini soon, leaks suggest that ChatGPT hasn't given up on Apple, yet. Recent code analysis of the ChatGPT iPhone app revealed a hidden Apple Health icon, which could be a clue that OpenAI may soon let ChatGPT access data from Apple Health. Though the feature isn’t active yet, the hidden “connector” suggests it could roll out as early as 2026. If implemented, this would allow ChatGPT to read metrics like activity, sleep, diet, breathing, and more (with your permission), and tailor responses based on real health data.

As noted by MacRumors, Strings inside the app reference health categories such as activity, sleep, diet, breathing, and hearing, suggesting the range of data that could be shared.

Read more
Samsung Galaxy Z TriFold is cool, but I’m more psyched about the future it teases
It's an eye-catching Android experiment, but it's a sign of better things to come in the near future.
Two formats of Galaxy Z TriFold

Samsung has just given us a demo of what the future is going to look like, if you’re willing to pay a fittingly high amount. The new Galaxy Z TriFold takes the concept of foldable phones, adds an extra fold to it, and changes the device into a proper tablet.

It’s surreal to see a device like that come to life. At least on the global stage. Huawei has already done it a couple of times with the dual-folding Mate XT pair, but that device leaves an exposed screen edge, runs a non-Android experience, and remains far away from the Western markets, including the US.

Read more
Google Photos Recap is here and the 2025 edition has a narcissism meter too
Your 2025 photo stats now include a selfie count too
Google-photos-recap-2025

What’s happened? Google Photos is rolling out its 2025 Recap, a personalized time capsule that uses Google’s Gemini model to sift through your photos and shape them into a summary of your year. It does more than show your best moments by pulling out hidden trends, quirky stats, and even shows how obsessed you were with selfies.

Gemini scans your library to identify themes, milestones, trips, and things you photographed often.

Read more