a Blackstone real estate company exposed SSN digits, DOBs, addresses and more
Summary
A security disclosure-by-blog post describes a GraphQL authorization flaw at Beam Living (Blackstone portfolio) that exposed sensitive applicant data including SSNs, dates of birth, addresses, and more. The piece outlines how the flaw was discovered, the exposure impact across multiple communities, the disclosure timeline, and the patch applied, along with ongoing remediation plans. It highlights the importance of secure GraphQL endpoints and responsible disclosure practices.