Author Topic: Identity Thieves Bypassed Experian Security to View Credit Reports  (Read 219 times)

0 Members and 1 Guest are viewing this topic.

Offline Kamaji

  • Hero Member
  • *****
  • Posts: 57,904
Identity Thieves Bypassed Experian Security to View Credit Reports

Krebs on Security
January 9, 2023

Identity thieves have been exploiting a glaring security weakness in the website of Experian, one of the big three consumer credit reporting bureaus. Normally, Experian requires that those seeking a copy of their credit report successfully answer several multiple choice questions about their financial history. But until the end of 2022, Experian’s website allowed anyone to bypass these questions and go straight to the consumer’s report. All that was needed was the person’s name, address, birthday and Social Security number.

*  *  *

Normally at this point, Experian’s website would present four or five multiple-guess questions, such as “Which of the following addresses have you lived at?”

Kushnir told me that when the questions page loads, you simply change the last part of the URL from “/acr/oow/” to “/acr/report,” and the site would display the consumer’s full credit report.

But when I tried to get my report from Experian via annualcreditreport.com, Experian’s website said it didn’t have enough information to validate my identity. It wouldn’t even show me the four multiple-guess questions. Experian said I had three options for a free credit report at this point: Mail a request along with identity documents, call a phone number for Experian, or upload proof of identity via the website.

But that didn’t stop Experian from showing me my full credit report after I changed the Experian URL as Kushnir had instructed — modifying the error page’s trailing URL from “/acr/OcwError” to simply “/acr/report”.

Experian’s website then immediately displayed my entire credit file.

*  *  *

Source:  https://krebsonsecurity.com/2023/01/identity-thieves-bypassed-experian-security-to-view-credit-reports/


Offline Kamaji

  • Hero Member
  • *****
  • Posts: 57,904
Re: Identity Thieves Bypassed Experian Security to View Credit Reports
« Reply #1 on: January 09, 2023, 07:03:47 pm »
Better check to see if your Experian credit report has been accessed.