← Latest briefing

Technology

Beam Living patches security flaw that exposed applicant personal data

A GraphQL authorization vulnerability in the Blackstone real estate company's leasing portal allowed access to partial Social Security numbers, dates of birth, and home addresses.

The short version

  • A security researcher discovered a GraphQL authorization flaw in Beam Living's leasing portal that exposed applicant data to anyone who submitted a user's email address.
  • Exposed records contained sensitive personal information, including the last four digits of Social Security numbers, dates of birth, home addresses, IP addresses, and phone numbers.
  • The vulnerability impacted applicants across several New York residential communities managed by Beam Living, including StuyTown, 8 Spruce, and Peter Cooper Village.
  • Beam Living patched the vulnerability on July 9 following multiple disclosure attempts by the researcher beginning in mid-June.

Key facts

  • A GraphQL authorization flaw in Beam Living's leasing portal allowed unauthorized access to sensitive applicant records using only an email address.[Hacker News]
  • Exposed information included partial Social Security numbers, dates of birth, home addresses, phone numbers, IP addresses, and screening application details.[Hacker News]
  • The portal vulnerability affected multiple properties under the Beam Living umbrella, including 8 Spruce, StuyTown, Peter Cooper Village, Kips Bay Court, and Parker Towers.[Hacker News]
  • The researcher first attempted to contact Beam Living regarding the vulnerability on June 14, and the issue was patched on July 9 after a phone call with the resident experience team.[Hacker News]

What remains uncertain

  • It remains unknown whether any malicious actors exploited the vulnerability or how many total applicants' data was accessed prior to the fix.[Hacker News]

Sources