Credit scores of millions of Americans have been exposed online

Banking
(Image credit: Shutterstock)

The credit scores of millions of Americans were left exposed online when a lender misused an API belonging to the credit reporting agency Experian.

As first reported by Krebs on Security, independent security researcher Bill Demirkapi was shopping around for student loan vendors online when he discovered that he could easily pull up his Experian credit score just by entering only a portion of the information normally required to do so.

Demirkapi was on a site that offered to check his loan eligibility just by entering his name, address and date of birth. Normally when using a credit monitoring service, Americans also need to provide their social security number to get access to their credit scores.

After providing the necessary information, Demirkapi took a look at the code on the lender's site and it was then that he found that the company had been invoking Experian's API. He provided more details on the significance of his discovery in a statement to Krebs on Security, saying:

“No one should be able to perform an Experian credit check with only publicly available information. Experian should mandate non-public information for promotional inquiries, otherwise an attacker who found a single vulnerability in a vendor could easily abuse Experian’s system.” 

Exposing Experian's API

To make matters worse, Demirkapi also found that the Experian API being invoked on this particular lender's website could be accessed without any sort of authentication. In fact, he was even able to enter all zeros on the site's date of birth field to pull a person's credit score.

From here, Demirkapi built his own command-line tool to speed up these lookups which he named “Bill's Cool Credit Score Lookup Utility”. Besides being able to pull a person's credit score, the Experian API also provides information on up to four “risk factors” that could explain why their score isn't higher.

In the end, Demirkapi reached out to Experian and the company was able to discover which lender was exposing its API online. In a statement, Experian explained that it takes data security and matters such as this very seriously, saying:

“We have been able to confirm a single instance of where this situation has occurred and have taken steps to alert our partner and resolve the matter. While the situation did not implicate or compromise any of Experian’s systems, we take this matter very seriously. Data security has always been, and always will be, our highest priority.”

Via Krebs on Security

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Data leak
Popular online bill paying site leaks data of thousands of users
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
This widely-used instant loan app leaks nearly 30 million files of user data
Data leak
Top collectibles site leaks personal data of nearly a million users
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring