How SSNs plus birthdates can still be leveraged to access tons more data via US FAFSA site, after an IRS tool with a similar flaw was disabled in March
KrebsOnSecurity has sought to call attention to online services which expose sensitive consumer data if the user knows a handful … Tweets: @briankrebs and @troyhunt Tweets: @briankrebs : Name, DoB and SSN is all it takes to get access to a mountain of personal data on tens of millions of students and their families #fafsa #idtheft http://krebsonsecurity.com/... http://twitter.com/... Troy Hunt / @troyhunt : Work out someone's SSN and DOB and you get 108 other personal data attributes in return. Seriously, this is why we have such a problem with identity verification these days: http://krebsonsecurity.com/...
Context & Ripple Effects
The FAFSA exposure is the latest entry in a pattern KrebsOnSecurity has documented for years: sites that treat name, date of birth, and SSN as proof of identity hand over far more than they verify. The Equifax breach had already crystallized the argument that SSNs are broken as unique identifiers, and the Anthem and government breaches showed how long stolen identity attributes keep paying off for attackers.
What makes this instance pointed is that the federal government has seen the exact failure mode before — the IRS pulled its own online tool in March after the same kind of lookup flaw surfaced — yet the Department of Education's student-aid portal still accepts the same three data points as a key. The related coverage shows the supply side too: marketplaces like SSNDOB sold exactly these attributes at scale, and Experian ran a comparable credit-report flaw into late 2022.
First-order effects
- Tens of millions of students and their families are exposed right now: anyone holding their SSN and birthdate can pull over a hundred additional personal data attributes from the FAFSA site, per Troy Hunt's reading of the flaw.
- The Department of Education faces immediate pressure to follow the IRS's March playbook and disable or gate the affected lookup rather than leave it open through financial-aid season.
Second-order effects
- Every site relying on the same knowledge-based authentication — Experian's was exploited for years before it was closed — now inherits the burden of proving its lookups are not the next Krebs write-up, pushing bureaus and agencies toward out-of-band verification.
- Criminal marketplaces trading bulk SSN-and-birthdate records gain a new consumption endpoint: each government portal that trusts those attributes raises the resale value of the data already circulating from breaches like National Public Data's.
Third-order effects
- If the pattern holds — IRS tool down, FAFSA exposed, bureau flaws recurring — federal systems will be forced to retire SSN-plus-birthdate as a de facto login credential, accelerating adoption of verification methods that do not depend on attributes already leaked en masse.
- The recurring exposure of the same three attributes across government and credit infrastructure strengthens the case for treating breached PII as permanently compromised, shifting liability toward operators who authenticate with it.
The trend: Identity verification built on static SSN-and-birthdate knowledge is collapsing under repeated exploitation across government portals and credit bureaus, forcing a migration toward credentials that cannot be reconstructed from breached data.