USPTO exposed about 61,000 trademark applicants' home addresses for three years

Organization
U.S. Patent and Trademark Office (USPTO)
Exploit
Misconfiguration
Industry
Federal Government

The U.S. Patent and Trademark Office emailed 60,819 trademark filers on June 9, 2023 to tell them their private domicile addresses had been publicly retrievable for roughly three years. The exposure became public knowledge in late June 2023. The affected applicants account for close to three percent of the applications filed during the period.

Trademark applicants are required to supply a domicile address, most often a home address, as a check against fraudulent filings originating overseas. That field is meant to be hidden from public view. USPTO said the addresses were instead returned in records retrieved through some application programming interfaces attached to its Trademark Status and Document Retrieval system, and also appeared in bulk data products published on its bulk data site.

The agency said it had voluntarily begun masking the addresses in 2020 but failed to locate every technical exit point where the data was still being served. The exposure ran from February 2020 until March 2023 and was discovered internally on February 24, 2023.

USPTO reported the matter to its department's privacy and security operations center, blocked access to non-critical APIs, and withdrew the affected bulk data products until permanent fixes were in place, replacing the files with versions that omit domicile addresses. The office said that from April 1, 2023 domicile addresses were properly masked and all vulnerabilities corrected. It added that there was no evidence of data misuse, and the leak was not the result of malicious activity.

Sources