Monday, August 3, 2026

Apps & Consumer

UStrive fixes security lapse exposing user data

UStrive has remediated a security lapse that exposed the personal information of at least 238,000 users, including children, via a vulnerable Amazon-hosted GraphQL endpoint.

UStrive fixes security lapse exposing user data

Online mentoring platform UStrive, a nonprofit organization formerly known as Strive for College, has resolved a security lapse that exposed the personal information of its users, including children. The platform, which provides online mentorship to high school and college students, allowed sensitive user data to be accessible to any other logged-in user. The exposed data included full names, email addresses, phone numbers, and other non-public information. The organization’s chief technology officer, Dwamian Mcleish, confirmed in an email on Thursday that the security exposure has been “remediated.” TechCrunch had notified the company’s executives of the security flaw by email earlier on Thursday.

According to a person who asked not to be named, the exposure stemmed from a vulnerable Amazon-hosted GraphQL endpoint—which functions as a query database interface—that allowed access to user data stored on UStrive’s servers. The unnamed person alerted TechCrunch to the security flaw last week, explaining that any logged-in user navigating the site could view streams of users’ personal information in their browser tools. The person reported that there were at least 238,000 user records at the time of discovery, with some records containing student-provided details such as gender and date of birth. For context, UStrive’s homepage states that more than 1.1 million students have opted in for a UStrive mentor. TechCrunch confirmed the data exposure after creating a new user account on the platform.

In response to inquiries, John D. McIntyre, an attorney with the Virginia law firm McIntyre Stein representing UStrive, provided a letter on Thursday stating that the organization is “currently in litigation with one of its former software engineers.” Because of this ongoing legal dispute, McIntyre stated that the company is “somewhat limited in its ability to respond” to questions regarding the incident. TechCrunch asked McIntyre if UStrive planned to notify its users about the security lapse, but McIntyre did not respond to the follow-up inquiry. Additionally, UStrive founder Michael J. Carter did not comment on the matter, and the organization did not clarify whether it plans to notify affected users about the security incident.

Why it matters

The incident highlights the critical risks of misconfigured API endpoints in platforms handling sensitive user data, particularly when those users are minors.