Peloton must remediate the API access path and assess which private account information was reachable before the issue was escalated through a reporter.
Peloton users face an immediate privacy risk from data that could be accessed without the intended account-level restriction.
Second-order effects
The episode raises the cost of relying on reporter-mediated escalation: Peloton’s security response and disclosure processes become as consequential as the API flaw itself.
Other consumer services with account APIs face added pressure to test whether identifiers or public endpoints reveal private profile data, following the same failure pattern seen at T-Mobile and USPS.
Third-order effects
Repeated API disclosures point toward privacy protection being enforced at the interface layer, where authentication and authorization controls—not merely account settings—determine what customer data can be retrieved.
As connected-product companies accumulate more user data, delayed handling of researcher reports can turn a technical defect into a broader trust and governance issue.
The trend: Consumer platforms are treating API authorization as a core privacy boundary, with disclosure handling increasingly shaping the reputational impact of failures.
New: Peloton's leaky API let anyone pull members' private user account data, even with their profiles set to private. Worse, when the bug was privately reported earlier this year, Peloton ignored researchers past their 90-day deadline. https://techcrunch.com/...
When your exercise/health data (a subset of identity data) is spread out across random apps/servers, this is what happens. Thankfully, standard Decentralized Identifiers + encrypted personal datastores Fixes This™. It's time to put you back in control, at the center of all data. …
anyone thinking about a class on #pelotonlaw? so far we've got trademark(infringement & genericide), copyright, data breach, products liability...and I think that's all in the past month https://twitter.com/...
If you have a Peloton, you private user account data may have been leaked via the API, even if your profile was set private. Peloton knew about this leak, ignored researchers for months, and won't tell us if the vulnerability was exploited. https://twitter.com/...
That friend who brags about their Pelaton? Now you can find out exactly how much exercise they ACTUALLY did. 😜 “Peloton user's age, gender, city, weight, workout statistics & ... details that are hidden when users' profile pages are set to private” https://techcrunch.com/...
“Peloton had a bit of a fail in responding to the vulnerability report, but after a nudge in the right direction, took appropriate action” sigh... https://twitter.com/...
Peloton leaked sensitive data for all users. Initially the disclosure was a mess but their lovely new CISO got it sorted fast! Full write up from our @FlyingPhishy - Tour de Peloton: Exposed user data https://www.pentestpartners.com/ ... #VulnerabilityDisclosure https://twitter.c…
Hello, start-ups, just because you're busy changing the world (🙄) that doesn't mean you don't have to do the boring shit like securing your API and looking after people's data. https://twitter.com/...