• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

USPS Security Flaw Exposes Personal Data of 60 Million People

By
Chris Morris
Chris Morris
Former Contributing Writer
Down Arrow Button Icon
By
Chris Morris
Chris Morris
Former Contributing Writer
Down Arrow Button Icon
November 26, 2018, 11:02 AM ET

A security hole in a mail preview program from the U.S. Postal Service could have exposed the data of more than 60 million customers, giving third parties access to information including when critical documents and checks are scheduled to arrive in people’s mailboxes.

An anonymous researcher discovered the weakness in the “Informed Visibility” service, noting that a web component called an API allowed pretty much anyone with a USPS account to view details of other users and, in some cases, to modify those people’s account details.

The USPS says it has patched the security hole, but seemingly only did so after security expert Brian Krebs inquired about it. The anonymous researcher who alerted him claims to have alerted postal authorities about the issue more than a year ago.

Informed Visibility provides end-to-end mail tracking information for incoming mail, including checks, important documents, and more. That’s valuable information for identity thieves and common criminals.

The security flaw also let any user find the account details of other users, including email address, user ID, phone number and more, according to Krebs. The postal service says it has no information that any customer records were accessed. Officials also say they’re investigating further “out of an abundance of caution”.

The USPS has had a rough 2018. In August, it accidentally released an unredacted copy of a Congressional candidate’s personal security file and has been caught in the middle of a feud between President Donald Trump and Amazon most of the year. This PR black eye comes just over a month after the agency announced it was seeking the biggest stamp price hike in its history.

Editor’s note: An earlier version of this story incorrectly said the security weakness was tied to the USPS “Informed Delivery” service instead of “Informed Visibility”. The error has been corrected.

About the Author
By Chris MorrisFormer Contributing Writer

Chris Morris is a former contributing writer at Coins2Day, covering everything from general business news to the video game and theme park industries.

See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.