Virtual Event: Threat Detection & Incident Response Summit - Watch Now
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Ford Blames Third-Party Supplier for Data Breach

Ford has completed its investigation into recent data breach claims and determined that its systems and customer data have not been compromised.

Ford data breach

Ford has completed an investigation launched after hackers claimed to have stolen customer information. 

Hackers named IntelBroker and EnergyWeaponUser claimed in a post on the BreachForums cybercrime forum on November 17 that they had obtained 44,000 Ford customer records, including names, physical addresses, and information on acquisitions.  

As SecurityWeek pointed out in its initial article, the data sample made public by the hackers represented the physical addresses of car dealers from around the world, which is not considered sensitive information and is likely already public. 

Ford has confirmed this, telling SecurityWeek on Tuesday that its investigation has determined that there was no breach of its systems or customer data, noting that the leaked information originated from a third-party supplier.

“The matter involved a third-party supplier and a small batch of publicly available dealers’ business addresses,” Ford said. 

It added, “It is our understanding that the matter has now been resolved.”

Advertisement. Scroll to continue reading.

IntelBroker has been known to leak data belonging to high-profile organizations, and while most victims have confirmed suffering some type of data breach, many of them suggested that the hacker’s claims were exaggerated.     

Related: Unpatched Vulnerabilities Allow Hacking of Mazda Cars: ZDI

Related: Millions of Kia Cars Were Vulnerable to Remote Hacking

Related: Ford Says Wi-Fi Vulnerability Not a Safety Risk to Vehicles

Related: AutoCanada Hit by Cyberattack

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.