PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Venmo Continues to Release Consumer Transactional Data a Year after Being Notified

By Tim Sloane
June 17, 2019
in Analysts Coverage, Credit, Debit, Fraud & Security, Mobile Payments, P2P, Personal Data, Security
0
7
SHARES
0
VIEWS
Share on LinkedIn
Venmo Continues to Release Consumer Transactional Data a Year after Being Notified

Venmo Continues to Release Consumer Transactional Data a Year after Being Notified

A fintech is not a bank yet the public is apparently unaware of the difference. A bank would never knowingly release private consumer information, but fintechs will. This TechCrunch article shows that a year after being caught leaking hundreds of million consumer transaction details, Venmo is still doing it:

“A computer science student has scraped seven million Venmo  transactions to prove that users’ public activity can still be easily obtained, a year after a privacy researcher downloaded hundreds of millions of Venmo transactions in a similar feat.

Dan Salmon said he scraped the transactions during a cumulative six months to raise awareness and warn users to set their Venmo payments to private.

The peer-to-peer mobile payments service faced criticism last year after Hang Do Thi Duc, a former Mozilla fellow, downloaded 207 million transactions. The scraping effort was possible because Venmo payments between users are public by default. The scrapable data inspired several new projects — including a bot that tweeted out every time someone bought drugs.

A year on, Salmon showed little has changed and that it’s still easy to download millions of transactions through the company’s developer API without obtaining user permission or needing the app.

Using that data, anyone can look at an entire user’s public transaction history, who they shared money with, when, and in some cases for what reason — including illicit goods and substances.

“There’s truly no reason to have this API open to unauthenticated requests,” he told TechCrunch. “The API only exists to provide like a scrolling feed of public transactions for the home page of the app, but if that’s your goal then you should require a token with each request to verify that the user is logged in.”

He published the scraped data on his GitHub page.

Venmo has done little to curb the privacy issue for its 40 million users since the scraping effort blew up a year ago. Venmo reacted by changing its privacy guide and, and later updated its app to remove a warning when users went to change their default privacy settings from public to private.

Instead, Venmo has focused its effort on making the data more difficult to scrape rather than the underlying privacy issues.

When Dan Gorelick first sounded the alarm on Venmo’s public data in 2016, few limits on the API meant anyone could scrape data in bulk and at speed. Other researchers like Johnny Xmas  have since said that Venmo restricted its API to limit what historical data can be collected. But Venmo’s most recent limits still allowed Salmon to spit out 40 transactions per minute. That amounts to about 57,600 scraped transactions each day, he said.”

Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group

7
SHARES
0
VIEWS
Share on LinkedIn

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    BNPL, BNPL for everyday expenses

    Hard Times, Easy Money: BNPL Now Finances Rent and Utilities

    August 21, 2026
    faster payments fraud prevention

    Beyond Compliance: Rewiring Fraud Prevention for Faster Payments

    August 20, 2026
    embedded finance for banks, instant payments

    Embedded Finance: Banks’ New Growth Channel

    August 19, 2026
    digital gift card experience

    How Leading Brands Are Building Better Digital Gift Card Experiences

    August 18, 2026
    AI fraud prevention for credit unions

    When AI Changes Fraud, Trust Becomes Everything

    August 17, 2026
    fednow

    How the Evolving Role of the CFO Is Changing Payments Strategy

    August 14, 2026
    real-time payment fraud prevention, alternative payment fraud liability

    How Innovation Is Transforming Payment Fraud Prevention

    August 13, 2026
    phygital payments

    Why People Still Want Physical Things in a Digital World

    August 12, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result