API Hole on Experian Partner Site Exposes Credit ScoresAPI Hole on Experian Partner Site Exposes Credit Scores
Student researcher is concerned security gap may exist on many other sites.
April 30, 2021
A student and security researcher recently informed credit-reporting bureau Experian about a vulnerability on a partner website that lets anyone look up credit scores with only a name and mailing address.
KrebsOnSecurity is reporting the incident after receiving the tip from Rochester Institute of Technology sophomore Bill Demirkapi. The student says he discovered the leak when looking online for information on student loan vendors.
One of the lender sites offered to check his loan eligibility by entering his name, address and date of birth, Demirkapi says. He eventually discovered the code behind a page was using an application programming interface (API) that could be accessed directly without any sort of authentication. He made this discovery by entering all zeros in the “date of birth” field, which let him then pull up a person’s credit score.
Demirkapi says he alerted Experian but did not provide the name of the lender or the website where he made his discovery because he was concerned the weakness existed on similar lending sites. KrebsOnSecurity reports Experian appears to have figured out on its own which lender was exposing the API. API access appears to be disabled now.
The full report can be found here.
About the Author(s)
You May Also Like
How to Combat the Latest Cloud Security ThreatsNov 06, 2023
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
SecOps & DevSecOps in the CloudNov 06, 2023
What's In Your Cloud?Nov 30, 2023
Everything You Need to Know About DNS AttacksNov 30, 2023