While reviewing my own promotion records in a Department of Defense web application, I noticed sensitive identifiers being passed in backend requests. Acting as a fully authenticated but non-privileged user, this curiosity revealed a widespread access control failure within an internal personnel system. This talk examines how common vulnerabilities—such as indirect object reference flaws and over-trusted authenticated users—can expose massive amounts of Personally Identifiable Information without exploits, malware, or elevated access. Limited, ethical testing demonstrated access paths to sensitive records across multiple DoD populations. All findings were responsibly disclosed through official vulnerability channels. Rather than focusing on specific technologies, the presentation highlights repeatable failure patterns in internal applications, why “trusted user” assumptions break down, and how curiosity-driven analysis uncovers issues that compliance testing often misses. Attendees will leave with a stronger mindset for evaluating internal systems, improving defensive testing programs, and understanding why internal vulnerability discovery is critical to modern security.