Breaking news

Strava Enhances Data Security To Curb Aggressive AI Scraping

AI’s Data Appetite Spurs Strava’s Strategic Response

Strava is tightening access to user data and introducing new charges for developers as artificial intelligence companies increasingly seek large datasets to train their models. As AI firms collect growing volumes of online information, often bypassing mechanisms such as robots.txt, the fitness platform is introducing measures aimed at limiting unauthorized scraping and strengthening control over its data.

Securing Data With Stringent Authentication

Previously, Strava users could view a range of information, including public profiles and fitness club listings, without signing in. The company is now requiring authentication to access certain data, making it more difficult for third parties to collect information at scale. The move reflects a broader industry trend as online platforms seek to protect intellectual property, preserve site performance and maintain control over user-generated content.

Revising Developer Access And API Protocols

Strava is also changing how developers access its API. Under the previous model, developers could access the platform through a tiered system that expanded as applications grew. Going forward, all developers will be required to pay a flat fee of $11.99 per month, although pricing may vary by region. The company noted that its developer community has grown from 185,000 to 241,000 members over the past year. At the same time, Strava plans to continue supporting developers through updates, including compatibility with the emerging Model Context Protocol (MCP).

Balancing Innovation With Security

Alongside the new pricing structure, Strava is retiring certain API endpoints and limiting some API calls as part of its broader effort to protect user data. The changes follow earlier policy decisions that prohibited the use of Strava data for AI model training and restricted some third-party data displays. To help developers adjust, the company will provide a 90-day transition period before the new rules take full effect.

Industry Impact And Investor Confidence

Michael Martin, CEO of Strava, warned of the broader consequences: “AI companies are ruthlessly scraping public websites, given their endless need for training data, which is degrading site performance across the board. We have witnessed multiple incidents of diminished website performance, and further attempts to exploit our API have been met with firm resistance.” Martin emphasized that while some developers may accept the subscription fee, discontinuing certain API endpoints will inevitably affect dependent applications. The decision also sends a confident signal to prospective investors, particularly as Strava previously filed confidentially for an IPO.

Contextualizing Data Discipline In A Competitive Landscape

Strava’s approach differs from that of some larger technology platforms. While Reddit’s API pricing changes drew criticism from developers who argued that access had become prohibitively expensive, Strava’s flat-fee structure is intended to preserve access while strengthening control over platform data. By reinforcing ownership of user-generated information, the company is seeking to balance developer access with growing concerns around AI training and large-scale data collection.

Looking Ahead

As AI adoption accelerates, technology companies are increasingly reassessing how their data is accessed, shared and monetized. Strava’s latest changes highlight the growing tension between supporting open developer ecosystems and protecting platform data in an era of expanding demand for AI training resources.

Google Warns Of Vishing Campaign Targeting Financial Firms

Cybercriminals are increasingly relying on a simple tactic to breach major financial institutions: convincing employees to hand over their own login credentials.

In a new report, Google said several hacking groups have been targeting large financial and investment firms in the United States through voice phishing, or “vishing”, before stealing sensitive corporate data and using it to extort victims.

Employees Are The Primary Target

According to Google’s researchers, attackers contact employees on their personal mobile phones while posing as colleagues or IT support staff. Victims are then directed to fake websites, where they are tricked into entering login credentials and multi-factor authentication codes.

Google tracks the groups under the names Falcon, Helix, Pink and Redact, although researchers believe they may be linked to a broader threat cluster known as UNC6671.

Some of the groups operate leak websites, where they threaten to publish stolen data unless companies agree to pay a ransom.

Financial Sector In The Spotlight

While previous attacks targeted industries including manufacturing, healthcare, insurance, technology and hospitality, Google said the hackers have increasingly shifted their focus to financial institutions and law firms.

Researchers believe organisations involved in mergers, acquisitions and capital markets are particularly attractive targets because of the highly confidential information they hold.

Google estimated that one cryptocurrency wallet linked to the operation received around $10 million in bitcoin during the first few months of the year. Ransom demands typically range from $750,000 to $3 million.

The report highlights that despite rapid advances in AI-driven cyberattacks, traditional social engineering techniques remain among the most effective ways for attackers to gain access to corporate networks.

The Future Forbes Realty Global Properties
Uol
Aretilaw firm
eCredo

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter