← Bilt Rewards

2022 Bilt Rewards — email-to-profile API disclosed names, buildings, unit numbers (press)

2022 Unknown records affected Share on X

Data compromised

Name, residential building, and unit number tied to email per reporting—scope of exploitable addresses not standardized in public sources

Technical writeup

In June 2022, TechCrunch reported that Bilt Rewards’ web API could return a user’s full name, apartment building name, and apartment number when supplied with only an email address, without login—framed as a serious privacy and potential stalking/abuse vector. Bilt was quoted stating the data returned was already available through public records in normal cases and that the company addressed the issue; journalists and privacy advocates emphasized risks where address linkage is non-obvious from public sources alone. This entry documents a configuration/API disclosure class incident rather than a third-party mass database exfiltration.

Root cause

Information disclosure via unauthenticated or overly permissive API behavior (per press account)

References