Start United States USA — software Credit scores of millions of Americans have been exposed online

Credit scores of millions of Americans have been exposed online

340
0
TEILEN

A lender exposed Experian’s API online making it possible for anyone to check someone’s credit score with publicly available information.
The credit scores of millions of Americans were left exposed online when a lender misused an API belonging to the credit reporting agency Experian. As first reported by Krebs on Security, independent security researcher Bill Demirkapi was shopping around for student loan vendors online when he discovered that he could easily pull up his Experian credit score just by entering only a portion of the information normally required to do so. Demirkapi was on a site that offered to check his loan eligibility just by entering his name, address and date of birth. Normally when using a credit monitoring service, Americans also need to provide their social security number to get access to their credit scores. After providing the necessary information, Demirkapi took a look at the code on the lender’s site and it was then that he found that the company had been invoking Experian’s API.

Continue reading...