Skip to content
FeaturesPricingAffiliateBlogHelpAboutContact
Get StartedSign In
Back to Blog
industry2026-05-236 min read

"Is this email registered?" — how your signup endpoint leaks PII to phishing bots

Attackers use the signup endpoint as an email-enumeration oracle: 409 vs 200 distinguishes registered from new emails, leaking the affiliate user list to phishing bots. thMenu's PR #560 SS F6 fix: uniform 202 response + 150-250ms randomized timing equalizer.

th

thMenu Team

thmenu.com

Found this helpful? Share it.