The U.S. Postal Service fixed a security weakness that allowed anyone who has an account at usps.com to view account details for some 60 million other users. The problem stemmed from an authentication weakness in a USPS Web component known as an application program interface or API. No special hacking tools were needed to pull this data, other than knowledge of how to view and modify data elements processed by a regular Web browser like Chrome or Firefox. The API in question was tied to a Postal Service initiative called Informed Visibility”]
Source: https://krebsonsecurity.com/2018/11/usps-site-exposed-data-on-60-million-users/

