Identity thieves exploited a security weakness in Experian's website to access credit reports by bypassing multiple-choice questions about a person's financial history. The vulnerability was discovered by a security researcher who found that editing the URL in the browser could grant access to anyone's credit report. Experian has since patched the issue, but the duration of the vulnerability is unclear. The incident highlights concerns about the credit bureau's cybersecurity and data protection practices.