Identity thieves crack major Experian security flaw, access customer credit reports

A mysterious man holding a keyboard like a weapon
(Image credit: Shutterstock / leolintang)

The website of consumer credit reporting giant Experian carried a major privacy vulnerability that allowed hackers to obtain customer credit reports, and all it took was a little identity data, and a little tweak to the address displayed in the URL bar, experts have revealed.

Cybersecurity researcher Jenya Kushnir discovered the flaw on Telegram, after observing hackers selling stolen reports, and worked with KrebsOnSecurity to investigate it further.

The idea was simple - if you had the victim’s name, address, birthday and Social Security number (all of which might be obtained from a previous incident), you could go to one of the websites offering free credit reports, and submit the data to request one. At that point, the website would redirect you to the Experian website where you’d be required to submit more personally identifiable information, such as questions about previous addresses of living and such.

Experian hack

And here is where the flaw is exploitable. There is no need to answer any of those questions - all you’d need to do at this point is simply change the address displayed in the URL bar, from “/acr/oow/” to “/acr/report,” and you’d be presented with the report. 

While testing the concept, Krebs found that tweaking the address first redirects to “/acr/OcwError”, but trying the tweak again worked: “Experian’s website then immediately displayed my entire credit file,” the report states.

The good news (if it can be seen as such) is that Experian’s reports are filled with inaccuracies. In the case of Krebs, it held numerous phone numbers, only one of which was owned by the author, some time in the past. 

Experian remains quiet about the matter, but the problem seems to have been fixed in the meantime. We don’t know for how long the flaw was active on the site, or how many reports were fraudulently generated during that time. 

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Password
Millions of airline customers possibly affected by OAuth security flaw
Data breach
Privacy of millions worldwide compromised as huge data location broker got hacked
A person with a laptop using a credit card online.
Avery label maker confirms attack on its site, customer credit card info stolen
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
An illustration of a hooded hacker with an obscured face holding a large fingerprint against a red background.
ID theft – what happens when someone steals your identity
Latest in Security
ransomware avast
Billions of credentials were stolen from businesses around the world in 2024
ID theft
Hackers claim Orange attack, threaten to leak 1TB of data
A computer file surrounded by red laser beams
Free online file converters could infect your PC with malware, FBI warns
Close up of a person touching an email icon.
Criminals are using CSS to get around filters and track email usage
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
Latest in News
Adobe AI agents
Adobe launches 10 new AI agents to automate key marketing workflows
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
Leaked Galaxy S25 Edge pricing gives us a clearer idea of how the super-slim phone will fit into Samsung's lineup
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip SE may launch months after the Galaxy Z Flip 7
ransomware avast
Billions of credentials were stolen from businesses around the world in 2024
iPhone 12
The iPhone 17 Air could come with a key charging benefit, new leak claims
Nvidia GTC 2025
Nvidia, Google, and Disney's AI-powered Star Wars robot is absolutely the droid I've been looking for