Slide 1 of 28
Part 1 · What Is It?Slide 1
PART 1
What Is It?
Slides 1–8 · From story to definition
Slide 1 · The Setup
You changed one number.
That's all it took.
The Scenario

It's 2021. You download the Peloton app to track your workouts. You notice that your profile URL ends with a number — your user ID.

Out of curiosity, you change the number. You hit enter.

Someone else's profile loads. Their age. Their weight. Their location. Their workout history. Everything.

You didn't hack anything. You didn't write any code. You changed one number in a URL.

The Scale

This wasn't a one-off. Every single Peloton account — over 4 million users — had their private data exposed this way. The vulnerability existed for months before anyone reported it. Peloton took another 3 months to fix it after being told.

Before we name it

You didn't need to know what this vulnerability is called to exploit it. All you needed was curiosity and a browser. That's what makes it the #1 API security risk in the world.

What is this called? →