Australian “rent-tech” platforms used by real estate agents to collect and store renter/landlord documentation were reported to have serious security vulnerabilities that left millions of sensitive lease-related documents accessible on the open web. A researcher’s analysis of seven platforms found documents (including lease agreements, identity documents, payslips, and references) could be retrieved through hyperlinks that did not require authentication, could be discovered by web crawlers, and in some cases could be accessed through predictable URL patterns (e.g., incrementing/decrementing an identifier) or guessable links created via URL shorteners; one workflow reportedly issued an authentication cookie after access, potentially exposing broader rental histories and maintenance records.
The reporting also highlighted the broader privacy impact on renters who are effectively compelled to use these platforms throughout the rental lifecycle (applications, payments, maintenance portals, chatbots), despite the data sensitivity involved. When companies were alerted, only two of seven reportedly responded with commitments to add security measures, raising concerns about governance and accountability in the sector. A separate opinion piece about AI/children’s privacy discussed general risks of data aggregation and surveillance but did not provide incident-specific details tied to the rent-tech exposure.

Map this exposure pattern across your cloud, code, and identities.
7 events from the most recent confirmed update back to the earliest known activity.
A follow-up commentary citing the Guardian's reporting said only two of the seven companies contacted indicated they would implement additional security measures. It also highlighted that renters had little practical ability to avoid these platforms despite the privacy risks.
Australia's Office of the Australian Information Commissioner said it had not received breach notifications from the platforms mentioned in the reporting. The regulator also said scrutiny of rent-tech platforms would be a priority in 2026.
Guardian Australia reported that analysis of seven Australian rental platforms indicated millions of leasing-related documents could be accessed by threat actors through predictable or guessable links. The report also said exposed links could be scanned by web crawlers and cached, increasing discoverability.
Inspection Express said it improved its security in January 2026 after being notified earlier, adding expiring links and additional restrictions to document access. This was one of the few concrete remediation steps described by a platform.
Inspection Express said it was alerted to the document exposure problem in the previous year. The company later disputed some of the findings about public discoverability and indexing.
The researcher attempted responsible disclosure by notifying affected rent-tech companies and the Australian Information Commissioner about the document exposure issues. According to later reporting, many of the vulnerabilities remained unresolved months afterward.
An anonymous security researcher found that sensitive renter and landlord documents on multiple Australian rent-tech platforms had been accessible through unauthenticated links, with some exposed files dating back to 2017. The materials included lease agreements, identification documents, payslips, and references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
theguardian.com
Open sourcetheguardian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.