Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - USPS Site Exposed Data On 60 Million Users
News & Analysis

USPS Site Exposed Data On 60 Million Users

ISBuzz TeamBy ISBuzz TeamNovember 24, 2018Updated:July 5, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Police
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Researchers have revealed details on the U.S. Postal Service (USPS) fixing a security weakness that allowed anyone who has an account at usps.com to view account details for roughly 60 million other users and in some cases to modify account details on their behalf.

The problem stemmed from an authentication weakness in a USPS Web component known as an “application program interface,” or API — a set of tools defining how various parts of an online application such as databases and Web pages should interact with one another.

Commenting on the news are the following security professionals:

Paul Bischoff, Privacy Advocate at Comparitech:

“APIs can be a very effective way for a business to allow third parties to build useful tools and applications around that business’ data, but they must be properly secured. In this case, basic access controls were not properly implemented, so anyone logged into a USPS account could, with a bit of know-how, access the details of 60 million other account holders. Furthermore, they could request changes be made to those accounts, although those changes required confirmation via email. While we’re not sure whether anyone actually took advantage of the vulnerability, it did reportedly exist for a whole year, so we should assume the worst. Informed Visibility, a USPS program tied to the API intended to be used for advanced parcel tracking, has had other security incidents in the past, so it was likely already a target for hackers.”

Mayur Upadhyaya, Managing Director, EMEA at Janrain:

“Exposing APIs can create security risks, and as such, do require a level of additional diligence. One of the challenges faced by many IT landscapes is enhancing legacy systems with additional capabilities to enable the sort of digital services that the USPS strived to deliver to its consumers. There will always be a trade-off between turn-key/off the shelf as a service software, that should provide a higher level of assurance over DIY/homegrown software, and the flexibility that organisations are seeking. Going forward, I believe we will see a greater trend to bolt-on assurance services such as API gateways and web application firewalls that can check the requesting party is authenticated and authorised to make the API call.”

Tim Mackey, Senior Technical Evangelist at Synopsys:

“With applications increasingly dependent upon third party APIs, this report highlights the risks organisations have without proper vetting of the services. Understanding the data transmitted to an API and a method to validate the sanity of the returned data should be part of the review process in all development and procurement teams. Armed with this information, API consumers can then monitor for any security disclosures associated with their API usage. When you consider the US Senate Commerce Committee is hearing briefs on a national data protection law similar to CCPA and GDPR, organisations should view tracking of API dependencies as a core strategy in reducing risks associated with potential data breaches.”

Martin Jartelius, CSO at Outpost24:

“These flaws are very common, and even more so today as APIs and modularization becomes more common and well established.

When building an API or a module in a service oriented infrastructure, each module or API must enforce authentication and authorization, either themselves or preferably by calling a centralized well defined module for this purpose.

As technical scanners have become more accurate, and as developers are more aware of security, or more inclined to use well established functions to manage secure inputs into application, attacks such as SQL injections are decreasing in frequency. However, logical issues remain not only at the same level as previously, but at an alarming rate more, a trend we have been picking up on from the rather a substantial base of clients for whom we monitor and test web application security.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}