Ford is investigating allegations that it suffered a knowledge breach after a risk actor claimed to leak 44,000 buyer data on a hacking discussion board.
The leak was introduced on Sunday by risk actor ‘EnergyWeaponUser,’ additionally implicating the hacker ‘IntelBroker,’ who supposedly took half within the November 2024 breach.
The risk actors leaked on BreachForums 44,000 Ford buyer data containing buyer data, together with full names, bodily places, buy particulars, vendor data, and report timestamps.
The uncovered data aren’t extraordinarily delicate, however they nonetheless comprise personally identifiable data that might empower phishing and social engineering assaults focusing on the uncovered people.
The risk actors didn’t try to promote the dataset however as an alternative provided it to registered members of the hacker discussion board for eight credit, equal to just a little over $2.
BleepingComputer contacted Ford to validate the claims, and a spokesperson for the agency instructed us they’re investigating the allegations.
“Ford is aware and is actively investigating the allegations that there has been a breach of Ford data. Our investigation is active and ongoing,” Ford instructed BleepingComputer.
The involvement of IntelBroker within the breach lends some credibility to the risk actor’s allegations primarily based on the risk actor’s current report.
The hacker has just lately achieved confirmed breaches at Cisco’s DevHub portal, Nokia (via a 3rd celebration), Europol’s EPE internet portal, and T-Cell (by way of a vendor).
The places talked about within the knowledge samples leaked by the risk actors are from world wide, together with the USA.
To mitigate the dangers arising from this potential knowledge publicity, deal with unsolicited communications cautiously and reject requests to disclose extra data beneath any pretense.
Replace 11/20 – Ford despatched BleepingComputer an extra assertion primarily based on new findings from their ongoing investigation.
Ford’s investigation has decided that there was no breach of Ford’s programs or buyer knowledge. The matter concerned a third-party provider and a small batch of publicly accessible sellers’ enterprise addresses. It’s our understanding that the matter has now been resolved. – A Ford spokesperson