UStrive security lapse exposed personal data of its users, including children

UStrive security lapse exposed personal data of its users, including children

UStrive, an online mentoring platform, has recently addressed a significant security vulnerability that compromised the personal information of its users, including minors. The breach exposed sensitive data such as full names, email addresses, and phone numbers, which were accessible to any authenticated user on the site. Originally established as Strive for College, UStrive aims to facilitate mentorship connections for high school and college students. However, the organization has remained silent on whether it intends to notify affected users about this security incident. A whistleblower alerted TechCrunch to the flaw, revealing that by simply logging in and browsing the platform, any user could access streams of personal information through their browser’s developer tools. The source of the vulnerability was linked to an insecure Amazon-hosted GraphQL endpoint, which allowed unauthorized access to vast amounts of user data stored on UStrive’s servers. At the time of the breach, there were approximately 238,000 user records at risk, with some entries containing detailed information such as gender and date of birth. Despite UStrive claiming on its homepage that over 1.1 million students have sought mentorship through their platform, the security lapse raised significant concerns. TechCrunch confirmed the data breach by creating a new account on UStrive and subsequently notifying the company's executives. An attorney representing UStrive, John D. McIntyre, mentioned in correspondence that the organization is currently embroiled in litigation with a former software engineer, which may limit their responses regarding the incident. In response to inquiries about the breach, UStrive's Chief Technology Officer, Dwamian Mcleish, stated that the security issue had been resolved. However, further questions about user notification, potential unauthorized access to data, and whether a security audit had been conducted went unanswered. Founder Michael J. Carter did not provide any comments regarding the situation.

Sources : TechCrunch

Published On : Jan 20, 2026, 21:25

Computing
Growing Concerns: Americans Increasingly Skeptical of Data Centers' Impact

A recent survey by the Pew Research Council has unveiled a troubling trend among Americans regarding data centers. As th...

Business Insider | Mar 13, 2026, 18:35
Growing Concerns: Americans Increasingly Skeptical of Data Centers' Impact
Science
Unraveling the Mystery of Superluminous Supernovae: The Role of Magnetars

Type I superluminous supernovae are among the most intense explosions observed in the universe, capturing the attention ...

Ars Technica | Mar 13, 2026, 16:00
Unraveling the Mystery of Superluminous Supernovae: The Role of Magnetars
AI
Nvidia Poised to Launch Revolutionary AI Chip in Ambitious $20 Billion Investment

Nvidia is gearing up for a major announcement regarding a groundbreaking AI chip, a venture that represents a staggering...

CNBC | Mar 13, 2026, 17:05
Nvidia Poised to Launch Revolutionary AI Chip in Ambitious $20 Billion Investment
Computing
Adobe Agrees to $75 Million Settlement Over Subscription Cancellation Practices

In a recent legal development, Adobe has reached a settlement with the Department of Justice regarding allegations of mi...

Ars Technica | Mar 13, 2026, 18:55
Adobe Agrees to $75 Million Settlement Over Subscription Cancellation Practices
Cybersecurity
New Wave of Supply-Chain Attacks: Invisible Code Targets GitHub and More

Cybersecurity experts have uncovered a sophisticated supply-chain attack that is inundating code repositories, including...

Ars Technica | Mar 13, 2026, 20:25
New Wave of Supply-Chain Attacks: Invisible Code Targets GitHub and More
View All News