HeadlinesBriefing favicon HeadlinesBriefing.com

Blackstone's Beam Living Exposes SSN Data via GraphQL

Hacker News •
×

Finding housing in NYC is hard. But it is easier to find the last four digits of someone’s Social Security number than an apartment. A researcher applying for a lease on Beam Living, a Blackstone portfolio company, noticed suspicious activity while monitoring network traffic.

While submitting personal details, the user inspected GraphQL queries sent to pd-dlcore.beamliving.com/graphql. The query structure allowed fetching extensive contact information, including income verification, credit scores, addresses, dates of birth, and Social Security data, by simply providing a contact ID or email.

Testing revealed that entering a friend’s email exposed their sensitive application data. This vulnerability affected multiple communities, including 8 Spruce, Stuy Town, Peter Cooper Village, Kips Bay Court, and Parker Towers. Any applicant whose record remained in the shared portal had their private information accessible to anyone who knew their email address.

The researcher disclosed the flaw to Beam Living. Despite initial denial, the issue was silently patched after further pressure. The incident highlights significant security risks in modern leasing portals and the potential for widespread data exposure through improper API authorization checks.