Misc.Aug 14, 2019
EPAM SystemsExplodingBanana

Credit Karma messed big time

TechCrunch: Credit Karma glitch exposed users to other people’s accounts. https://techcrunch.com/2019/08/14/credit-karma-glitch-accounts/

Credit Karma glitch exposed users to other people's accounts
Credit Karma glitch exposed users to other people's accounts
TechCrunch
Add a comment
IBM h0nkh0nk Aug 14, 2019

> just a glitch

Credit Karma SrfrBoi69 Aug 14, 2019

No personally identifiable information was exposed (e.g. names, SSNs, acct #s). It’s still pretty troubling.

EPAM Systems ExplodingBanana OP Aug 14, 2019

"One user told TechCrunch that after they were served another person’s full credit report, they messaged the user on LinkedIn"

Credit Karma SrfrBoi69 Aug 14, 2019

You can’t view your full credit report on Credit Karma. Lol Anyway, I’m sharing what I heard, but I understand I’m a biased source. There are a few embarrassing factual inaccuracies that should cast doubt on the Tech Crunch reporting though.

Credit Karma johnwic Aug 14, 2019

Credit karma trying to control the narratives lol

Credit Karma travolt Aug 14, 2019

We deny the data breach

Credit Karma SrfrBoi69 Aug 14, 2019

So say we all

Uber Hotwheelz Aug 14, 2019

What was the issue though? Over sight, bad experiment or untested code ?

Credit Karma LCboy Aug 15, 2019

Don't know major details but was related to incorrect session object used. You could see someone else's session but not PII, PII has extra level security. So, very few people saw someone else's credit score but they don't know whose score they were cz PII screen was blocked. This is my knowledge!

Uber Hotwheelz Aug 15, 2019

Interesting. Thanks!

Credit Karma hinger Aug 16, 2019

some PII was potentially seen