Hackers Steal Personal Data in 700Credit Breach Affecting 5.6 Million
好,我现在要帮用户总结这篇文章的内容。用户的要求是用中文,控制在100字以内,不需要特定的开头,直接描述文章内容。 首先,我需要通读整篇文章,抓住主要信息。文章讲的是700Credit公司发生的数据泄露事件。他们为大约18,000家美国汽车经销商提供信用报告和身份验证等服务。这次泄露影响了至少560万人的个人信息,包括姓名、地址、社会安全号码和出生日期。 泄露的原因是黑客入侵了700Credit的一个合作伙伴的网络,利用获取的信息攻击了700Credit的系统。这个合作伙伴在夏季被入侵,但没有通知700Credit。攻击者通过API获取了数据,导致漏洞暴露。 700Credit在10月发现了数据泄露,并采取措施关闭了API。他们联系了FBI和FTC,并开始通知受影响的客户,提供一年的信用监控服务。此外,他们还与国家汽车经销商协会合作。 文章还提到密歇根州总检察长敦促受害者不要忽视信件,并采取措施保护个人信息。公司高管指出中型和小型企业可能缺乏足够的安全措施,并建议加强供应链中的沟通。 总结一下,主要内容包括:数据泄露事件、影响人数、原因、处理措施以及对企业的建议。我需要将这些信息浓缩到100字以内,确保涵盖所有关键点。 </think> 一家为美国约1.8万家汽车经销商提供信用报告和身份验证服务的公司发生数据泄露事件,导致至少560万人的个人信息被盗。黑客通过入侵该公司合作伙伴的网络并利用获取的信息攻击其系统,导致姓名、地址、社会安全号码等敏感数据外泄。公司已联系执法机构并开始通知受影响客户,建议采取防范措施以应对潜在欺诈风险。 2025-12-15 18:6:49 Author: securityboulevard.com(查看原文) 阅读量:7 收藏

A data breach at a company that offers credit reports, identity verification, and other services for about 18,000 auto dealerships and similar businesses in the United States exposed the personal information of at least 5.6 million people.

According to executives with 700Credit, hackers earlier this year compromised the network of one of the company’s partners and used the information gleaned from that breach to attack 700Credit’s systems. Among the personal information stolen from customers of the Southfield, Michigan-based company’s clients were names, addresses, Social Security numbers, and dates of birth, according to the company.

The unnamed partner company was compromised during the summer, and 700Credit in October discovered that the unidentified threat actors had stolen personal data collected by its dealers.

According to 700Credit Managing Director Ken Hill, the company – which also serves RV, powersports, and marine dealerships – has more than 200 integration partners that it communicates with via APIs. The partner that was compromised earlier this year didn’t notify 700Credit about its data breach.

That firm’s “systems were compromised and taken over and the threat actors got hold of their communication logs to us,” Hill said during an interview with CBTNews. “It exposed an API that our partner used to pull down consumer information because they didn’t want to store it on their system. It exposed the vulnerability that we had. We weren’t validating the consumer reference site we used to the original requester.”

He said that during the attack, the bad actors were “pinging us, pinging us millions and millions of times. We shut it down. They continued to attack us for probably more than two weeks. We had shut down the API that was the exposure. They got about 20% of our data from May to October.”

‘Kind of Spooky’ Note from Hackers

That said, forensic teams brought in by 700Credit found that the attackers hadn’t penetrated the company’s systems, but that the breach was in its application layer. After finally shutting down the attack, Hill said the cybercriminals sent them a note, which “was kind of spooky.”

In a statement, 700Credit said it had notified the FBI and Federal Trade Commission (FTC) about the data breach and was also getting in touch with state attorneys general around the country. The company is also taking the lead in notifying and helping the customers, starting December 22, of its dealers, including offering them one year of credit monitoring services through TransUnion, it said in a planned letter to affected customers filed with the state of Maine.

700Credit is also working with the National Automobile Dealers Association. (NADA).

Don’t Ignore a 700Credit Letter

In an advisory, Michigan Attorney General Dana Nessel warned victims that “if you get a letter from 700Credit, don’t ignore it. It is important that anyone affected by this data breach takes steps as soon as possible to protect their information. A credit freeze or monitoring services can go a long way in preventing fraud.”

Nessel also advised people to be on the lookout for phishing emails, to harden or change passwords, get rid of unnecessary data or files, and to use multifactor authentication on devices and accounts. She also said they should review their credit report often, not only with TransUnion but also Equifax and Experian.

Hill said that in the course of the investigation into the breach and notifying clients, he said some of the major dealerships had decent cybersecurity infrastructure in place, including frameworks, monitoring, and red teams that attack their own companies’ defense to test their strength.

The worry is with mid-level and smaller companies that might not have the budget or people to put some protections in place, he added. He urged dealerships to educate themselves about the threats and how to defend against them, and to survey what security capabilities their partners have in place.

Communication in the Supply Chain is Key

He criticized the partner whose compromise led to the attack on 700Credit, saying the intrusion “could’ve been avoided if we’d been notified because we could’ve shut it down.”

Hill said the company last year increased its cybersecurity insurance, noting that “if we hadn’t, we’d be in a lot of trouble.” He said 700Credit had a plan in place to handle a situation like the data breach, but that he and other executives didn’t understand the obstacles when such an attack takes place, including inaccurate communications by others inside and outside of the industry meant to cause panic.

“We didn’t plan for that,” he said, adding that lawsuits already are being filed by customers harmed by the attack even before the company has sent out notices to affected individuals. “Our whole organization is replying to those types of questions that dealers have and concerns that dealers have.”

Law firms that handle class action lawsuits, such as Edelson Lechtzin LLP, are investigating data privacy claims resulting from the data breach and urging those affected to contact them.

Recent Articles By Author


文章来源: https://securityboulevard.com/2025/12/hackers-steal-personal-data-in-700credit-breach-affecting-5-6-million/
如有侵权请联系:admin#unsafe.sh