Dell is warning customers of a data breach after a threat actor claimed to have stolen information for approximately 49 million customers.
The computer maker began emailing data breach notifications to customers yesterday, stating that a Dell portal containing customer information related to purchases was breached.
Dell hardware and order information, including service tag, item description, date of order, and related warranty information.
The company stresses that the stolen information does not include financial or payment information, email addresses, or telephone numbers and that they are working with law enforcement and a third-party forensics firm to investigate the incident.
While BleepingComputer has not been able to confirm if this is the same data that Dell disclosed, it matches the information listed in the data breach notification.
The Breach Forum's post has since been deleted from the site, which could indicate that another threat actor purchased the database.
As the stolen information does not include email addresses, threat actors could target specific people with physical mailings that contain media to install malware on targets' devices.
While this may sound far-fetched, threat actors have conducted similar attacks in the past, physically mailing tampered Ledger hardware wallets that stole cryptocurrency or sending gifts with USB drives that installed malware.
As the database is no longer being sold, there is a good chance a threat actor is attempting to monetize it in some way through attacks.
Be wary of any physical mailings or emails you receive that claim to be from Dell asking you to install software, change passwords, or perform some other potentially risky action.
If you receive an email or physical mailing, you should instead contact Dell directly to confirm it is legitimate.
AT&T confirms data for 73 million customers leaked on hacker forum.
AT&T says leaked data of 70 million people is not from its systems.
AT&T now says data breach impacted 51 million customers.
Home Depot confirms third-party data breach exposed employee info.
US cancer center data breach exposes info of 827,000 patients.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Thu, 09 May 2024 15:25:06 +0000