logo

UStrive security lapse exposed personal data of its users, including children

ID: 8d4f1544-89bf-522e-b9a3-63a47f6ecf62

STIX ID: report--8d4f1544-89bf-522e-b9a3-63a47f6ecf62

Feed Name: TechCrunch Security News

Threat Score
55/100

Date Published: 2026-01-20

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

TechCrunch reported that UStrive (formerly Strive for College) had a security lapse where a misconfigured GraphQL endpoint exposed personal information—full names, emails, phone numbers, gender, date of birth and other user-provided data—of at least 238,000 accounts (including children) to any logged-in user; UStrive says the issue was remediated but has not confirmed user notification or whether data was accessed maliciously.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.