700Credit data breach impacts 5.8 million vehicle dealership customers
嗯,用户让我总结一下这篇文章的内容,控制在100个字以内,而且不需要用“文章内容总结”之类的开头。首先,我得仔细阅读文章,抓住主要信息。 文章讲的是700Credit公司发生了数据泄露事件,影响了超过580万人。攻击者在7月份入侵了他们的一个集成合作伙伴,发现了获取客户信息的API。但这个合作伙伴没有通知700Credit。直到10月25日,公司才注意到系统中的可疑活动,并展开调查。 泄露的数据包括姓名、地址、出生日期和社会安全号码。700Credit是美国最大的信用报告和身份验证服务提供商之一。他们已经向 FTC 提交了泄露通知,并为受影响的客户提供了一年的免费身份保护服务。 所以,我需要把这些关键点浓缩到100字以内。注意不要遗漏主要信息:数据泄露、人数、攻击方式、泄露数据类型、公司影响和应对措施。 可能的结构是:公司名称 + 数据泄露 + 影响人数 + 攻击方式 + 泄露数据 + 公司应对措施。这样既简洁又全面。 再检查一下字数,确保不超过限制。最后,确保语言流畅自然。 </think> 美国金融技术公司700Credit发生数据泄露事件,超580万人受影响。攻击者通过未受保护的API获取客户信息,包括姓名、地址、出生日期和社会安全号码等敏感数据。公司已向受影响客户提供免费身份保护服务,并向相关部门提交通知。 2025-12-15 17:1:18 Author: www.bleepingcomputer.com(查看原文) 阅读量:6 收藏

700Credit data breach impacts 5.8 million vehicle dealership customers

700Credit, a U.S.-based financial services and fintech company, will start notifying more than 5.8 million people that their personal information has been exposed in a data breach incident.

The cyberattack occurred after a threat actor had breached one of 700Credit's integration partners in July and discovered an API for obtaining customer information. However, the partner did not inform 700Credit of the compromise.

700Credit noticed suspicious activity on its systems on October 25 and launched an investigation, with assistance from third-party computer forensic specialists.

"The investigation determined that certain records in the web application relating to customers of its dealership clients were copied without authorization," 700Credit says in the notification to affected individuals.

According to 700Credit Managing Director Ken Hill, the attacker managed to steal around 20% of consumer data from May to October before the company terminated the exposed API.

The threat actor was able to exfiltrate data due to a security vulnerability in the API, a failure to validate consumer reference IDs against the original requester.

The data types that have been exposed include:

  • Full name
  • Physical address
  • Date of birth
  • Social Security Number (SSN)

700Credit is one of the largest providers of credit reporting, identity verification, and fraud and compliance services for automotive dealers across the United States. According to the company, it provides credit reports and soft pull solutions to more than 23,000 automotive, RV, Powersports, and Marine dealer customers.

    It is worth noting that the company filed with the Federal Trade Commission (FTC) a breach notification on its behalf and a consolidated one on behalf of all its affected dealer clients.

    700Credit customers impacted by the breach no longer have to file a notice with the FTC or with state attorney general's Offices, as the company will do it on their behalf as well.

    700Credit also informed the National Automobile Dealers Association (NADA) about the incident to raise awareness.

    A dedicated page on the company's website provides general details about the data breach and the type of information impacted.

    To help affected individuals mitigate the risk, 700Credit is offering a 12-month free-of-charge identity protection and credit monitoring service through TransUnion, with a 90-day to enrollment period.

    Recipients of the data breach notification are advised to monitor their accounts closely and consider placing a security freeze.

    At the time of writing, no ransomware groups claimed the attack. BleepingComputer has contacted 700Credit to learn more about the incident, but a comment wasn’t immediately available.

    tines

    Break down IAM silos like Bitpanda, KnowBe4, and PathAI

    Broken IAM isn't just an IT problem - the impact ripples across your whole business.

    This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.


    文章来源: https://www.bleepingcomputer.com/news/security/700credit-data-breach-impacts-58-million-vehicle-dealership-customers/
    如有侵权请联系:admin#unsafe.sh