logo

The Dell API Breach: It could have been prevented

ID: 2edfc1bb-b0a7-5f48-a123-15a020d89451

STIX ID: report--2edfc1bb-b0a7-5f48-a123-15a020d89451

Feed Name: Security Boulevard

Threat Score
80/100

Date Published: 2024-05-17

Date Updated: 2026-04-22

Author: Hadar Freehling

...
...

The report reviews an incident where an attacker created a partner account and exploited a Dell partner-facing API and business-logic weakness to enumerate and harvest 49 million customer records by sending thousands of randomized seven-character service-tag queries per minute. The theft was enabled by lack of partner vetting, absent rate limiting and API monitoring; the report uses the case to illustrate API protection gaps and recommends using Salt's behavioral/ML-based API defense to detect and prevent similar scraping attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.