Ford is investigating allegations that it suffered a data breach after a risk actor claimed to leak 44,000 buyer data on a hacking discussion board.
The leak was introduced on Sunday by risk actor ‘EnergyWeaponUser,’ additionally implicating the hacker ‘IntelBroker,’ who supposedly took half within the November 2024 breach.
The risk actors leaked on BreachForums 44,000 Ford buyer data containing buyer data, together with full names, bodily areas, buy particulars, seller data, and file timestamps.
The uncovered data aren’t extraordinarily delicate, however they nonetheless comprise personally identifiable data that would empower phishing and social engineering assaults concentrating on the uncovered people.
The risk actors didn’t try and promote the dataset however as an alternative supplied it to registered members of the hacker discussion board for eight credit, equal to a bit over $2.
BleepingComputer contacted Ford to validate the claims, and a spokesperson for the agency informed us they’re investigating the allegations.
“Ford is conscious and is actively investigating the allegations that there was a breach of Ford knowledge. Our investigation is energetic and ongoing,” Ford informed BleepingComputer.
The involvement of IntelBroker within the breach lends some credibility to the risk actor’s allegations based mostly on the risk actor’s current file.
The hacker has lately achieved confirmed breaches at Cisco’s DevHub portal, Nokia (by a 3rd social gathering), Europol’s EPE net portal, and T-Cell (through a vendor).
The areas talked about within the knowledge samples leaked by the risk actors are from all over the world, together with america.
To mitigate the dangers arising from this potential knowledge publicity, deal with unsolicited communications cautiously and reject requests to disclose extra data underneath any pretense.
Replace 11/20 – Ford despatched BleepingComputer a further assertion based mostly on new findings from their ongoing investigation.
Ford’s investigation has decided that there was no breach of Ford’s programs or buyer knowledge. The matter concerned a third-party provider and a small batch of publicly accessible sellers’ enterprise addresses. It’s our understanding that the matter has now been resolved. – A Ford spokesperson