Blackstone's Beam Living exposed SSN digits, DOBs, and addresses via GraphQL flaw
A Blackstone real estate company exposed SSN digits, DOBs, addresses and more

A security researcher discovered that Beam Living, a Blackstone portfolio company, left applicants' sensitive data—including the last four digits of Social Security numbers, dates of birth, addresses, and phone numbers—exposed through a GraphQL authorization flaw. Anyone with a user's email could query the API and retrieve that data. The researcher responsibly disclosed the issue, but Beam Living initially denied it and silently patched it weeks later, leading to criticism of their disclosure handling.
It is easier to find the last four digits of someone’s Social Security number than an apartment.