USPS site’s vulnerability exposes 60 million users’ data

Date:

Share post:

A security vulnerability in the United States Postal Service (USPS) exposed more than 60 million customers’ personal information to all the users who have an account with the USPS.com. The USPS is an independent mail service agency in the United States and authorized by the United States Constitution.

However, the mail service provider patched the vulnerability recently after Brian Krebs, an investigating reporter, flagged the issue. The security flaw was first identified by an independent researcher a year ago, but USPS never patched it until this week, Krebs stated in his blog KrebsonSecurity.

Krebs stated that he was contacted by an anonymous researcher, who discovered the problem, and said he informed the USPS about his finding a year ago but never received a response. After confirming the research findings, Krebs contacted the USPS officials to report the problem.

The research findings revealed an authentication weakness in the USPS website’s API (Application Program Interface) that lets any usps.com user access other users’ information such as email address, username, user ID, account number, street address, phone number, authorized users, and mailing campaign data.

In a statement shared with KrebsOnSecurity, the USPS stated the information shared by Krebs helped them to immediately mitigate the issue. “Computer networks are constantly under attack from criminals who try to exploit vulnerabilities to illegally obtain information.  Similar to other companies, the Postal Service’s Information Security program and the Inspection Service uses industry best practices to constantly monitor our network for suspicious activity,” the UPSC added. “Any information suggesting criminals have tried to exploit potential vulnerabilities in our network is taken very seriously. Out of an abundance of caution, the Postal Service is further investigating to ensure that anyone who may have sought to access our systems inappropriately is pursued to the fullest extent of the law.”

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

Stop Reviewing Faster: A Practical Model for AppSec at AI Speed

By Aparna Ash Himmatramka A developer using an AI assistant can ship a feature in an afternoon. In many...

Why I Go to the Dark Web Every Day

By Alex Holden, Chief Information Security Officer Hold Security For nearly two decades I made the Dark Web a...

The Cyber Security EXPO is the only dedicated recruitment event for Cyber Security Professionals

Located in the heart of London at the QEII Centre, the Cyber Security EXPO London offers a prime...

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...