Blackstone's Beam Living exposed SSN digits, DOBs, and addresses via GraphQL flaw

A Blackstone real estate company exposed SSN digits, DOBs, addresses and more

Blackstone's Beam Living exposed SSN digits, DOBs, and addresses via GraphQL flaw

A security researcher discovered that Beam Living, a Blackstone portfolio company, left applicants' sensitive data—including the last four digits of Social Security numbers, dates of birth, addresses, and phone numbers—exposed through a GraphQL authorization flaw. Anyone with a user's email could query the API and retrieve that data. The researcher responsibly disclosed the issue, but Beam Living initially denied it and silently patched it weeks later, leading to criticism of their disclosure handling.

It is easier to find the last four digits of someone’s Social Security number than an apartment.

More from this day

2026-08-24