Dell API abused to steal 49 million customer records in data breach
ID: 30ce1212-6552-5114-ba62-a9a377e5de61
STIX ID: report--30ce1212-6552-5114-ba62-a9a377e5de61
Feed Name: Bleeping Computer
A threat actor calling themselves Menelik exploited Dell's partner portal by registering fake partner accounts and programmatically generating 7-digit service tags to scrape roughly 49 million customer records (order/warranty details, service tags, names, locations, customer numbers). The actor claims the portal lacked rate limiting, allowed 5,000 requests/minute for weeks, and sold the data on a hacking forum; Dell confirmed an investigation and engagement of third‑party forensics and law enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
