An authentication vulnerability in DPD Group's package tracking system could allow access to its customers' personal data

See also: Critical vulnerability in WordPress plugin affects thousands of sites
DPD Group is a parcel delivery service with a global presence, shipping around two billion parcels annually around the world.
To track the status and location of their parcel, customers are expected to enter a parcel code and postal code, and if they match a valid entry in the database, they are authorized to view the shipment details.
Researchers at Pen Test Partnersexplored the system and found that they could test parcel codes in API calls and get back OpenStreetMap addresses with the recipient's location on the map.
Although the call only returned a screenshot of the map, it is quite easy to extract the zip code, in most cases using the street names depicted in the image.
By maintaining a valid parcel code and a corresponding postal code, an unauthorized person could access someone else's tracking page that displays delivery information.
See also: Windows vulnerability allows anyone to gain administrator rights

By granting the valid session token, one can view the underlying JSON data, including the full name, email address, mobile number, and other details of that person.
Pen Test Partners discovered the issue on September 2, 2021, and immediately notified DPD. The company assessed the issue for a month and eventually implemented a fix in October 2021.
Therefore, the API access vulnerability remained available for exploitation for at least a month.
Although researchers were likely the first to discover it, the scenario of “silent” long-term abuse cannot be ruled out.
The way this API attack worked is random, as one cannot guess the parcel numbers for certain identities, but it would still be useful in the hands of phishing actors.
See also: Microsoft: Blocked billions of brute-force and phishing attacks in 2021
Knowing the shipment status details and matching contact information sets the stage for a successful phishing.
Parcel delivery service providers were the type of companies most imitated by phishing campaigns in late 2021, so this is already a highly targeted sector.
