Urgent.News

What's breaking now, across thousands of outlets.

Tech

A Blackstone real estate company exposed SSN digits, DOBs, addresses and more

Securing a rental in New York City can be challenging. Acquiring someone's Social Security number digits is as easy as obtaining an apartment in this bustling metropolis. One individual, who is cautious about online security, discovered this while applying for a lease at Beam Living, a company owned by Blackstone. While completing the online application, the reporter noticed a GraphQL query that was processing their Social Security number.

Initially, the issue did not seem alarming, but upon further investigation, the reporter found that submitting an email address in a certain GraphQL query revealed sensitive data. This unexpected result led the reporter to test the vulnerability using a friend's email address. The results were alarming: the reporter obtained the friend's Social Security number, date of birth, home address, IP address, phone number, and other application information.

The vulnerability was not limited to the reporter's application or building; Beam Living utilized this leasing portal across its communities, making all application data accessible to anyone with the email address. The reporter immediately reported the issue to Beam Living via email and phone. The company claimed there were no issues with their system, but the reporter decided to attempt the exploit again.

To their relief, the vulnerability had been patched. Despite the issue being resolved, the reporter expressed disappointment in how companies, particularly those owned by large conglomerates like Blackstone, handled the disclosure process.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at alexschapiro.com →

More in Tech

More from Monday 24 August →