Peloton security bug could expose user data
Exposed API could let hackers access customer data


A flaw in how Peloton fitness bikes communicate with the company’s servers could have inadvertently allowed anyone to access customers’ private data.
According to investigations carried out by Pen Test Partners, the mobile, web application, and back-end APIs had several endpoints that revealed users’ information to authenticated and unauthenticated users.
Jan Masters, a security researcher at Pen Test Partners, spotted the vulnerability in January. He discovered he could make unauthenticated requests to the fitness firm’s API for account data. According to Masters, there were no checks to ensure he was allowed to request the data.
The exposed API allowed the researcher to access a range of information, such as a user’s age, gender, location, weight, workout stats, and birthday, even when a user makes their profile page private.
Master notified Peloton of his findings via its vulnerability disclosure program in the middle of January with a 90-day deadline to fix the issues. That deadline came and went with Peloton only acknowledging the problem and not fixing it.
In early February, Peloton quietly and partly resolved the unauthenticated API endpoint issue. Still, Masters pointed out this meant user data was now only available to all authenticated Peloton users who had taken out a monthly subscription to the service.
Master then asked for an update, given that Peloton had made a partial fix, but Peloton didn’t respond.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
After 90 days, Master contacted a journalist at TechCrunch, who then broke the story. “This started a constructive conversation and resulted in the vulnerabilities being largely resolved,” said Masters.
“A full investigation should be conducted by Peloton to improve their security, especially now that famous individuals are openly using this service,” added Masters.
Since contacting the press, Peloton’s new CISO has remained in contact with him over the flaws. The company fixed most of them in a week.
“It’s a shame that our disclosure wasn’t responded to in a timely manner and also a shame that we had to involve a journalist in order to get listened to,” he added.
The Peloton bike has gained popularity over the years to keep fit at home, especially since the coronavirus pandemic hit the world last year. Earlier this year, President Biden was prevented from bringing his Peloton into the White House over concerns that it could be a security risk. It seems now that those concerns were well-founded.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
Capita tells pension provider to 'assume' nearly 500,000 customers' data stolen
Capita told the pension provider to “work on the assumption” that data had been stolen
By Ross Kelly Published
-
Gumtree site code made personal data of users and sellers publicly accessible
News Anyone could scan the website's HTML code to reveal personal information belonging to users of the popular second-hand classified adverts website
By Connor Jones Published
-
Pizza chain exposed 100,000 employees' Social Security numbers
News Former and current staff at California Pizza Kitchen potentially burned by hackers
By Danny Bradbury Published
-
83% of critical infrastructure companies have experienced breaches in the last three years
News Survey finds security practices are weak if not non-existent in critical firms
By Rene Millman Published
-
Identity Automation launches credential breach monitoring service
News New monitoring solution adds to the firm’s flagship RapidIdentity platform
By Praharsha Anand Published
-
Neiman Marcus data breach hits 4.6 million customers
News The breach took place last year, but details have only now come to light
By Rene Millman Published
-
Indiana notifies 750,000 after COVID-19 tracing data accessed
News The state is following up to ensure no information was transferred to bad actors
By Rene Millman Published
-
Pearson fined $1 million for downplaying severity of 2018 breach
News The SEC found the London-based firm made “misleading statements and omissions” about the intrusion
By Rene Millman Published