[ad_1]
A threat actor who previously claimed to have obtained the addresses of 49 million Dell clients has now accessed more sensitive data, according to recent insights acquired by TechCrunch.
The additional data breach involves a range of personal customer details obtained from Dell’s service reports. The exposed information encompasses customer names, phone numbers, and email addresses. These service reports also detail hardware replacement, engineers’ comments, dispatch numbers, and occasionally customers’ diagnostic logs.
TechCrunch reviewed multiple reports that also showed pictures uploaded to Dell for analyzing technical issues. A few of these contained geolocation metadata that showed the exact location where pictures were captured by customers.
The authenticity of the compromised personal information has been confirmed through verification by TechCrunch.
Following Dell’s recent notification to its clientele of a breach concerning customer purchase information, this serves as the second security issue brought to light within a short period.
The initial set of stolen data consisted of customer names, physical addresses, Dell hardware, order info—even warranty details. Dell initially minimized the impact of this breach, stating that it didn’t believe the disclosed data presented a critical risk and that it didn’t involve highly sensitive information like email addresses or phone numbers.
The person believed to be responsible for both breaches operates under the pseudonym Menelik. Menelik showcased a fraction of the stolen data to TechCrunch, affirming the legitimacy of the hack. He has also been in direct contact with Dell regarding the breaches, email evidence suggests.
Menelik disclosed another vulnerability within a different Dell portal, which he exploited to harvest additional customer details.
Despite revealing his ability to access email and phone number details, Menelik indicated his reluctance to misuse the data immediately, preferring first to assess Dell’s reaction to the ongoing situation.
A request for comment to Dell from TechCrunch did not receive a response.
Menelik claims the exploitation of around 30,000 U.S. customers’ data, attributing his success to vulnerabilities similar to those used in the prior 49 million record breach. This current flaw, however, hinders the rate at which he can gather the data, in comparison to the earlier breach.
Initially, Menelik was reportedly able to extract customer data through a portal by masquerading as a “partner” affiliated with Dell. Once approved, brute-forcing customer service tags enabled him to access the data. He later advertised the stolen data for sale on a well-known hacking forum. The listing has since vanished, with Menelik claiming the data is sold, although details of the sale are undisclosed.
While still undecided about the future usage of the newly acquired data, Menelik’s actions have raised significant privacy concerns, particularly that of EU-based customers.
TechCrunch has reached out to the national data protection authority in Ireland for comments on the breach, but hasn’t received an immediate response.
Contact Us
If you have more information about this Dell security incident or have knowledge of similar breaches, please reach out to Lorenzo Franceschi-Bicchierai through secure means. You can use Signal (+1 917 257 1382), Telegram, Keybase, Wire (@lorenzofb), or email. TechCrunch also offers SecureDrop for confidential data submissions.
[ad_2]
FAQs About the Recent Dell Customer Data Exposures
- What type of customer information has been leaked?
- Names, phone numbers, email addresses, details on hardware replacements, engineers’ remarks, dispatch numbers, diagnostic logs, and in some cases, geolocation metadata from uploaded images have been leaked.
- How has the attacker managed to gain access to Dell’s data?
- The attacker, Menelik, claimed to obtain data through vulnerabilities in Dell’s partner portal and another Dell portal, which he then exploited to scrape customer data.
- Did the data stolen in the first breach include highly sensitive information?
- No, the first breach involved names, addresses, and hardware and order information, but did not include highly sensitive data such as email addresses and phone numbers. However, the subsequent breach has included such information.
- Has Dell acknowledged the breach?
- While Dell notified customers after the initial breach, they have not responded to requests for comment on the latest claims of additional data scraping involving more sensitive information.
- What are the potential risks for affected customers?
- Affected customers may be at risk of phishing attacks, identity theft, and privacy invasion, especially since some images uploaded to Dell contained precise GPS coordinates.
Conclusion
The disclosure of two serious breaches involving Dell customer data within a short span highlights the persistent cyber risks facing major corporations. These breaches do not only compromise personal information but also raise questions about the measures put in place to safeguard customer privacy. As threat actors continue to exploit vulnerabilities, both companies and individuals must remain vigilant in protecting themselves against data theft and potential misuse of personal information. More information may emerge as investigations continue, but the digital safety of individuals and the responsibility of organizations to protect this remain paramount.










































