2022 Bilt Rewards — email-to-profile API disclosed names, buildings, unit numbers (press)
Data compromised
Name, residential building, and unit number tied to email per reporting—scope of exploitable addresses not standardized in public sources
Technical writeup
In June 2022, TechCrunch reported that Bilt Rewards’ web API could return a user’s full name, apartment building name, and apartment number when supplied with only an email address, without login—framed as a serious privacy and potential stalking/abuse vector. Bilt was quoted stating the data returned was already available through public records in normal cases and that the company addressed the issue; journalists and privacy advocates emphasized risks where address linkage is non-obvious from public sources alone. This entry documents a configuration/API disclosure class incident rather than a third-party mass database exfiltration.
Root cause
Information disclosure via unauthenticated or overly permissive API behavior (per press account)