top of page

Live Trail Data Breach: What Runners Need to Know (and Do Right Now)

  • 2 days ago
  • 7 min read

Published September 2026 | Written by Andy Hood


Live Trail app data breach, runner checking phone with trail race tracking app
Live Trail suffered a data breach, notifying users in Septemeber

A week does not seem to pass without me receiving an email about a data breach from a company that I trust with my personal information. And it makes me stop and consider whether I should be opening up new accounts and trusting companies, as they seem to have a lackadaisical approach to cyber security. My suspicion is the budget priorities each year go something like this: sales, marketing, product development, the Christmas party, tea and coffee, and then, somewhere down at the bottom, cyber security. Because it seems to be that they are all sipping tea and dunking their digestives rather than taking the securing of my data as seriously as if it were their own.


Except in this case, Live Trail are a French company, so it's probably coffee and a croissant or pain au chocolat instead. I watched enough of that going on in a café in Chamonix last week to know it's a serious national pastime. Fair enough, but I'd still rather they spent a bit more of that time on their server security.


This time it's a Live Trail data breach, the live race tracking app used by trail and ultra runners (and their support crews) all over the world, including at UTMB events. So here's what's actually happened, what Live Trail has said about it, and what you should do if you've got an account.



What Happened in the Live Trail Data Breach?


Live Trail has told affected users it detected unauthorised access to part of its server, which allowed someone to extract data linked to user accounts. The company says the data involved is limited to:


  • The email address used to log in

  • The password associated with the account, stored in hashed form rather than as plain text


Hashed passwords are more secure than passwords stored openly, but "hashed" doesn't automatically mean "harmless". A hash can still potentially be cracked, particularly if the password was short, common, or one you've used on other sites too.


There's quite a bit Live Trail hasn't said. The exact date of the intrusion, how long the access lasted, how many accounts were affected, and how the attacker got in have all been left out of the notification. No hacking group has claimed responsibility, and there's no sign of a ransom demand.


Who Are Live Trail?


LiveTrail tracking app used at UTMB, trail runner data breach

If you've raced a UTMB World Series event, chances are you've used Live Trail without giving much thought to who's actually behind it. The tracking system started life as a volunteer project, refined year on year until 2009, before being officially founded as a company, Live Trail SARL, in 2013.


Since then it's grown into what it calls the world's leading live tracking platform for long distance endurance events, used in more than 18 countries, including France, Spain, China and the US, across over 400 races. It supports every event on the UTMB World Series circuit alongside plenty of other race organisers, and the app now bundles in live rankings, checkpoint notifications, GPS beacons, SOS alerts and pacing tools. All useful stuff, but all of it relies on runners handing over a fair bit of personal and location data to actually use it.


What Has Live Trail Said About the Breach?


To be fair to them, Live Trail seems to have moved reasonably quickly on containment and telling people. According to the notification sent to affected users, the company says it has:


  • Closed off the access point used in the incident

  • Strengthened its security measures

  • Forced a password reset for affected accounts

  • Increased monitoring of its systems


Live Trail is urging anyone affected to change their password straight away (a reset link has been sent to impacted accounts) and, just as importantly, to change that same password anywhere else they've used it. It's also warned users to be wary of phishing attempts: unusual emails, texts or calls referencing Live Trail and asking for personal information or anything out of the ordinary. Now that whoever did this knows these email addresses belong to real, active Live Trail users, that alone makes it easier for them to send a convincing scam message.



What Is a Data Breach, and Why Should Runners Care?


A data breach is any incident where personal or sensitive information is accessed, copied or stolen without permission. Usually it's down to hacking, but it can also happen through a lost device or a poorly secured database.


For runners, even a breach that sounds fairly small can cause real headaches:


Account takeover

If your password is weak, or you've used it elsewhere, whoever has it can try it on your other accounts. Email, banking, social media, all of it.


Phishing and impersonation

Knowing your email is tied to a specific service makes a scam message far more convincing.


Identity theft

This becomes a bigger risk when a breach includes names, addresses or dates of birth alongside emails. That's not confirmed here, but it's still worth staying alert to.


Loss of trust

Even a limited breach leaves you feeling a bit uneasy, especially when the app in question has also been tracking your GPS during a race.


Runners race on a wet road, their legs and colorful jerseys reflected in puddles; bib numbers visible.

Live Trail Isn't Alone. Other Data Breaches in the Running World


Unfortunately Live Trail joins a growing list of fitness and running apps that have had security incidents of their own.


MyFitnessPal (Under Armour), 2018


One of the biggest fitness app breaches on record. Under Armour disclosed that the data of over 150 million MyFitnessPal users had been exposed, including usernames, emails and hashed passwords, though payment details and government ID numbers weren't affected. Sound familiar? It's a strikingly similar profile to Live Trail's breach, just on a vastly bigger scale.


Garmin, 2020


A very different kind of incident. Garmin was hit by a ransomware attack using a tool called WastedLocker, which knocked out its website and Garmin Connect app for days and reportedly led to a $10 million ransom payment, though Garmin said customer payment data wasn't compromised. A good reminder that breaches aren't always about stolen data. Sometimes it's about being locked out of your own account entirely.


Strava, 2018 heatmap privacy issue


Not a hack as such, but a privacy design failure worth knowing about. Researchers discovered that Strava's public activity heatmaps were inadvertently revealing the locations of military bases, because personnel using the app hadn't realised their data was public. Strava overhauled its privacy controls afterwards.


Fitness apps generally, an ongoing weakness


A 2021 security review of popular apps, including Strava, Runkeeper, MapMyRun, Nike Run Club and Runtastic, found most still lacked basic protections like two factor authentication. This isn't a one off problem. It's a pattern across the whole sector.


AllTrails, 2023 to 2024


A security researcher was able to track the movements of a former senior US government official through his AllTrails activity, simply because the app's tracking data is public by default. A stark example of how "just" location data can become a real world safety risk.



Top 5 Tips for Dealing With a Data Breach


  1. Change your password immediately, and everywhere else you've reused it. Reused passwords are exactly what attackers rely on when they get hold of a stolen credential list.

  2. Turn on two factor authentication (2FA) wherever it's offered, so a stolen password alone isn't enough to get someone into your account.

  3. Watch for phishing attempts. Be suspicious of any unexpected email, text or call referencing the breached company, especially if it asks you to "verify" something or click a link.

  4. Use a password manager to generate and store a unique, strong password for every account you hold, so a breach on one service can't spread to all the others.

  5. Check whether your data has turned up elsewhere, using a breach checking service such as Have I Been Pwned, and keep an eye on your accounts and bank statements for anything odd in the weeks after.


For fuller official guidance, the NCSC (National Cyber Security Centre) has a good breakdown of what to do after a data breach.



Should We Be More Cautious About the Apps We Sign Up To?


I wonder if this will ultimately make us more cautious about opening new accounts with companies. Downloading an app, clicking register, having the account opened, and transferring lots of your personal data, it all takes less than ten seconds. Do you really consider how much information you've just handed over, and what their IT team is doing with it?


No, nor do I. But I think I will.


FAQ


Is Live Trail safe to use after this breach?


Live Trail says it has closed the access point used in the incident, forced a password reset, and increased system monitoring. As with any breach, the safest thing to do is reset your password straight away, use a unique password going forward, and keep an eye out for phishing attempts referencing Live Trail.


What data was exposed in the Live Trail data breach?


Live Trail says the exposed data was limited to login email addresses and passwords stored in hashed, not plain text, form.


Do I need to change my password if I use Live Trail?


Yes. Change your Live Trail password immediately, and if you've used the same password anywhere else, change that too.


Was my GPS or race data affected?


Live Trail's notification refers specifically to account login data, meaning email addresses and hashed passwords, not race tracking or GPS data. That said, the company hasn't gone into full technical detail about exactly what was accessed.


How can I check if my email has appeared in other data breaches?


Free services like Have I Been Pwned let you check whether your email address has turned up in known data breaches, including this one once it's indexed.


Are running and fitness apps more prone to data breaches than other apps?


Not necessarily more prone, but they do collect a distinctive mix of personal and location data, and several, including MyFitnessPal, Garmin, Strava and AllTrails, have had significant breaches or privacy failures in recent years. It suggests security isn't always top of the priority list in this sector either.


Runna marathon training plans free trial code ANDY2

Comments


bottom of page