6 May 2021

Software bug exposed Peloton users private account data


Software bug exposed Peloton users private account data

A flaw in Peloton’s online service exposed sensitive users' data, making it available to anyone on the internet, even if a profile was set to private, Jan Masters, a security researcher at Pen Test Partners, has found.

Peloton makes network-connected stationary bikes and treadmills and also provides users access to live real-time classes and sessions with a coach, as well as classes for treadmill, yoga, and outdoor running.

Masters discovered that he could make unauthenticated requests to Peloton’s application programming interface (API), for user account data without it checking whether the person was allowed to request it.

The exposed information included user IDs, instructor IDs, group membership, workout stats, gender and age, weight, and if a user is in the studio or not.

The researcher said he contacted Peloton over the API bug in January and promptly received a response acknowledging the issue, however, after that the company went silent. At the beginning of February Peloton silently issued a partial fix, which addressed the issue by making user data available only to authenticated Peloton users. The researchers then informed the company of the inadequate fix but again received no response. The issue was fixed in May after Pen Test Partners directly contacted a new Peloton’s CISO.

Back to the list

Latest Posts

Cyber Security Week in Review: April 19, 2024

Cyber Security Week in Review: April 19, 2024

In brief: the LabHost PhaaS platform shut down, Russian military hackers attacked critical infrastructure in the US and Europe, and more.
19 April 2024
Ukrainian military personnel targeted via messaging apps and dating sites

Ukrainian military personnel targeted via messaging apps and dating sites

The threat actor employs a range of software in their malicious activities, including both commercial programs and  open-source tools.
18 April 2024
Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

This marks the first time Russian nation-state hackers have posed a direct threat to critical infrastructure in Western countries.
18 April 2024