Privacy Tip #168 – USPS Security Vulnerability Affects More Than 60 Million

Robinson+Cole Data Privacy + Security Insider
Contact

We previously commented on the risks around the United State Postal Service’s (USPS) “Informed Visibility” service, which allows customers to preview their mail to inform them when it will be delivered. Some security experts recommend that customers opt out of the program so an account cannot be opened in your name.

Last week, it was reported that an anonymous researcher discovered security vulnerabilities in the Informed Visibility service, an API that allowed anyone with a USPS account to view the information in other users’ accounts, and to potentially modify others’ accounts. This vulnerability is reported to have affected more than 60 million users.

The alarming part of the report is that criminals could potentially view and change the account details of users so that checks, statements, Social Security checks and other important documents that are sent through USPS could be diverted or picked up by fraudsters as soon as the mail is delivered.

Although USPS says it is not aware that any customer information was accessed, reviewing your account details and whether you want to participate in the program is prudent.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide