US Postal Service

Original Release Date: 12/4/2018

Summary

A security researcher discovered a flaw in the US Postal Service (USPS) website, usps[.]com, which allowed any logged in user to access the information of over 60 million other user accounts by conducting a simple query. The exposure stemmed from an application programming interface (API) used to support USPS’s Informed Visibility service, a program that provides real-time tracking of mail. Potentially accessed information includes email address, username, user ID, account number, address, and phone number. USPS fixed the issue on November 20th of this year.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.