API Hole on Experian Partner Site Exposes Credit Scores

Student researcher is concerned security gap may exist on many other sites.

Dark Reading Staff, Dark Reading

April 30, 2021

1 Min Read
Dark Reading logo in a gray background | Dark Reading

A student and security researcher recently informed credit-reporting bureau Experian about a vulnerability on a partner website that lets anyone look up credit scores with only a name and mailing address.

KrebsOnSecurity is reporting the incident after receiving the tip from Rochester Institute of Technology sophomore Bill Demirkapi. The student says he discovered the leak when looking online for information on student loan vendors.

One of the lender sites offered to check his loan eligibility by entering his name, address and date of birth, Demirkapi says. He eventually discovered the code behind a page was using an application programming interface (API) that could be accessed directly without any sort of authentication. He made this discovery by entering all zeros in the “date of birth” field, which let him then pull up a person’s credit score.

Demirkapi says he alerted Experian but did not provide the name of the lender or the website where he made his discovery because he was concerned the weakness existed on similar lending sites. KrebsOnSecurity reports Experian appears to have figured out on its own which lender was exposing the API. API access appears to be disabled now.

The full report can be found here.

About the Author

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights