A Blackstone real estate company exposed SSN digits, DOBs, addresses and more

A security researcher discovered that a Blackstone real estate portfolio company, Beam Living, exposed sensitive user data including Social Security numbers through its GraphQL API. The vulnerability allowed unauthorized access to personal information submitted during the housing application process.
Why it matters
This incident highlights the ongoing risks of insecure API implementations in web applications that handle highly sensitive personal identifiable information.
Update: This post received some attention on Hacker News — see the discussion thread .
Finding housing in NYC is hard. Everyone knows that. But what not everyone knows is that it is easier to find the last four digits of someone’s Social Security number than an apartment…
I was applying for a lease on Beam Living , a Blackstone portfolio company . I went through the normal flows, but (as a security-conscious individual) I always have my network tab open as I browse the web to make sure I am not putting my sensitive information into a website that a script kiddie (or GLM-5.2) could easily break into.
As I was submitting my Social Security number, I figured I should check out the GraphQL (rip, used to be the hot thing) queries that were processing it.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in