Breach report
Consumer TechDell
Dell warns of data breach, 49 million customers allegedly affected
Dell warned customers in May 2024 that a portal holding purchase records had been abused, after a hacker claimed to have scraped 49 million customer records by registering fake partner accounts and hammering an API.
Reported by BleepingComputer
Records exposed
49M
About 49 million customer records
Scale vs. largest on file
- When
- 2024
- How they got in
- API abuse via fraudulent partner portal accounts (no rate limiting)
- Sector
- Consumer Tech
In May 2024, Dell began emailing customers to warn that it was investigating an incident involving a portal containing information related to purchases from the company. The notices followed a late-April post on the BreachForums hacking forum in which a threat actor using the name Menelik offered data on 49 million customers who had bought Dell systems between 2017 and 2024. The listing was later removed, suggesting the data may have been sold.
According to Dell, the exposed information included customer names, physical addresses, and hardware and order details such as service tags, item descriptions, order dates and warranty information. The company said financial and payment data, email addresses and telephone numbers were not involved. It argued there was not a significant risk to customers given the type of information, while acknowledging it had brought in forensic experts and notified law enforcement.
The hacker told reporters how the data was harvested. Menelik said they registered several accounts on Dell's partner portal under fictitious company names, a process that reportedly required little verification. Once inside, they used a script to generate seven-digit service tags and submit them to an API that returned customer details, reportedly sending about 5,000 requests a minute for nearly three weeks without being blocked. The actor said they later emailed Dell to report the weakness. Dell said it had already detected the activity and taken steps to stop it.
The breach prompted proposed class-action lawsuits accusing Dell of failing to protect customer data. Security experts disputed the company's characterization of the risk, noting that names and home addresses tied to specific purchases and warranty status could fuel convincing phishing emails, fake support calls, or even mailed scams impersonating Dell technical support.
The Dell incident is a clear example of business-logic abuse: attackers did not exploit a software bug so much as a partner process and an API that lacked rate limiting and anomaly detection. It highlights the risks of exposing customer lookup functions to external partners without strong vetting. For businesses, the lessons include verifying partner registrations, throttling high-volume queries and monitoring for enumeration patterns; for consumers, it is a reminder that unsolicited support contacts citing real order details are not proof of legitimacy.