• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Home
  • About
  • Structure
  • Gradebook

ITACS 5211: Introduction to Ethical Hacking

Wade Mackey

US Postal Service Left 60 Million Users Data Exposed For Over a Year

November 28, 2018 by Brock Donnelly 1 Comment

https://thehackernews.com/2018/11/usps-data-breach.html

US Postal Service Left 60 Million Users Data Exposed For Over a Year

Even our postal service is susceptible to weak APIs…? Yeah even the government has weaknesses. What might make this worse is the cyber security researcher notified USPS of the vulnerability over a year ago and nothing was done. 60 Million USPS users data was exposed for over a year. USPS did finally do something about it and when they went to action it only took them two days. Two. 48 hours before they fixed it required a journalist contacting USPS on behalf of the researcher to initiate a response. OH, and what a silly response it is:

“We currently have no information that this vulnerability was leveraged to exploit customer records.”
“Out of an abundance of caution, the Postal Service is further investigating to ensure that anyone who may have sought to access our systems inappropriately is pursued to the fullest extent of the law.”

in other words, “we’re good” because we don’t know of any breaches.

NICE!

Filed Under: Uncategorized, Week 12: Web Services Tagged With:

Reader Interactions

Comments

  1. Xinteng Chen says

    November 28, 2018 at 5:05 pm

    Hi Brock

    Thanks for sharing the information to us. It is significant for an organization to protect customers’ information. Organizations should remain the information based on the requirements of laws. In addition, the organization should determine the reasonable methods to destroy the data based on the classification level of the information. The organization should also have data breach response plan to reduce the loses of data breach.

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (14)
  • Week 01: Overview (7)
  • Week 02: TCP/IP and Network Architecture (18)
  • Week 03: Reconnaisance (17)
  • Week 04: Vulnerability Scanning (19)
  • Week 05: System and User Enumeration (17)
  • Week 06: Sniffers (17)
  • Week 07: NetCat and HellCat (15)
  • Week 08: Social Engineering, Encoding and Encryption (21)
  • Week 09: Malware (14)
  • Week 10: Web Application Hacking (17)
  • Week 11: SQL Injection (15)
  • Week 12: Web Services (25)
  • Week 13: Evasion Techniques (8)
  • Week 14: Review of all topics (15)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in