PayPal’s Venmo App Exposes Most Transactions Via Its API

Bleeping Computer

“The vast majority of Venmo transactions are being logged in a public API accessible to anyone, according to the recent investigation of a privacy advocate. The reason this happens is because the Venmo app’s default settings are set to “Public” for all users.  Unless users specifically change this value, all the transactions they make via the Venmo money-sending app are logged and made available to anyone via the Venmo public API. Data exposed via this API includes the first and last name of the sender and recipient, Venmo avatars, the date of the transaction, a comment regarding the transaction, transaction types, and more.”