Hunters International claimed in a post on its extortion portal last week that it had exfiltrated terabytes of data from the auto dealership company, including its network-attached storage images, databases, financial documents, databases, and human resource files.
Despite the shutdown of both chatbots — which provided free access to up to 20 data samples from 31.2 million datasets and PDF-based claim documents — more have emerged to distribute the stolen data.
Dell had its internal files claimed to be compromised by the threat actor "grep" just days after the same actor admitted to stealing 10,863 employee records from a breach earlier this month.
Aside from failing to remove data from former users, most of the said platforms also had no safeguards for data belonging to youths ages 13 to 17, according to the Federal Trade Commission.
Information leaked by grep on BreachForums included Dell employees' full names, IDs, active status, department numbers, and internal identifiers, as well as two email addresses with the "dell.com" domain but no plain text credentials or personally identifiable information.
Included among the files in the unsecured 193 GB database were information regarding fuel and petroleum shipments, invoices, and delivery tickets to and from companies, pipelines, and industries across several states, including California, Colorado, Oklahoma, Oregon, and Texas between 2019 and August 2024.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.