Tech & AI News
Hacker News

A Blackstone real estate company exposed SSN digits, DOBs, addresses and more

The Beam Living leasing portal’s GraphQL endpoint let any user retrieve another applicant’s personal data using only an email address. It exposed the last four digits of Social Security numbers, dates of birth, home and IP addresses, phone numbers, and other details. The vulnerability affected all tenants who applied through the shared portal for properties including 8 Spruce, StuyTown, Peter Cooper Village, Kips Bay Court, and Parker Towers, compromising every stored record.