/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Up until late December 2022, hackers were using a flaw in Experian's site to get anyone's entire credit report using only their name, address, birthday, and SSN

Krebs on Security Brian Krebs

Context & Ripple Effects

This flaw is the latest chapter in a decade-long pattern at Experian: back in 2017 its [[a:922501|credit-freeze PIN retrieval tool authenticated users on just four pieces of basic personal information]], and mid-2022 reporting documented hijacked accounts and weaknesses in the same authentication flow. Meanwhile the raw material for abuse was already circulating — the Equifax breach exposed up to 143M consumers' birthdays and SSNs, and researchers showed those same identifiers unlocked further data via the FAFSA site even after a similar IRS tool was pulled.

What changed here is scale and persistence: until late December 2022, anyone holding a person's name, address, birthday, and SSN — precisely the combination mass-leaked in prior breaches — could pull their entire Experian credit report. A full report aggregates accounts, balances, and inquiries, turning scattered leaked fragments into a complete financial dossier.

First-order effects

  • Identity thieves with breached SSN-and-birthdate data could retrieve any consumer's full credit report from Experian, converting partial leaks into complete profiles usable for targeted fraud.
  • Experian faces renewed credibility damage on top of the 2021 PIN-reset flaws and 2022 account-hijacking reports, all pointing at the same authentication architecture.

Second-order effects

  • The episode demonstrates that knowledge-based authentication fails whenever the 'secret' answers were leaked years earlier, pressuring all three bureaus to move verification off personal-data questions toward out-of-band or document-based checks.
  • With report access trivially abusable, consumer defense shifts toward proactive freezes and locks, increasing reliance on — and scrutiny of — the bureaus' own protection tooling.

Third-order effects

  • If SSN-plus-birthday is simultaneously the key to identity verification and the most widely leaked data set in the US, the credential model underpinning consumer credit reporting is structurally obsolete — a case for regulator-mandated replacement rather than site-by-site patches.
  • A record spanning Equifax's 2017 breach through Experian's repeated authentication failures builds momentum for treating credit-report access as critical infrastructure with enforced security standards instead of voluntary fixes.

The trend: US consumer credit reporting is being forced away from SSN-and-birthday knowledge-based authentication because that data set is now effectively public.

Discussion

  • @dangillmor@mastodon.social Dan Gillmor on mastodon
    Why does “credit reporting” Experian still exist?  This rogue company and industry have demonstrated again and again that they cannot be trusted with the detailed personal and financial information it holds …
  • @artemr Artem Russakovskii on x
    How are these giant, rich companies like @Experian this incompetent? “... when the questions page loads, you simply change the last part of the URL from “/acr/oow/” to “/acr/report,” and the site would display the consumer's full credit report.” https://krebsonsecurity.com/ ...
  • @uhoelzle @uhoelzle on x
    Truly astounding history of security bugs... https://krebsonsecurity.com/ ...
  • @ax_sharma Ax Sharma on x
    🤯 Could have retrieved anyone's report all this time by simply changing the last bit of the URL and Experian goes silent. Threat actors apparently already exploited the bug. Great work by @briankrebs and Jenya Kushnir! https://krebsonsecurity.com/ ...
  • @watermanreports Shaun Waterman on x
    What the actual f—k! The invaluable @briankrebs demonstrates, yet again, that Experian are not fit to run a piss-up in a brewery, let alone guard the personal data of millions of Americans. Experian credit reports were obtainable by URL manipulation. https://krebsonsecurity.com/ …
  • @digiphile Alex Howard on x
    Dear @LinaKhanFTC @RKSlaughterFTC @CSWilsonFTC @BedoyaFTC, Are data brokers & credit bureaus doing enough to protect the privacy & security of Americans? What more can @FTC do to ensure @Experian_US @TransUnion @Equifax are good stewards of our PII? Would consent decrees help? ht…
  • @dancow Dan Nguyen on x
    A frightening number of enterprise web developers are not prepared for the scenario of “when the user knows what a URL is and how to type”: https://krebsonsecurity.com/ ... https://twitter.com/...