GM drivers may have had personal details revealed following phishing attack


A large number of General Motors (GM) user accounts have been breached, and their personally identifiable information (opens in new tab) stolen, the company has confirmed in a recent announcement sent to affected customers. What’s more, the cybercriminals behind the attack tried to redeem rewards points found on those accounts, for gift cards.
GM users have had their accounts compromised with a credential stuffing attack that took place between April 11 and April 29. This is a brute force type of attack, in which the attackers try numerous combinations of usernames and passwords until one works. Sometimes, the attackers will also try username/password combinations stolen from other breached services, knowing that some people reuse the same credentials across a multitude of services.
The exact number of affected customers is unknown, although just in the state of California there are thought to have been around 5,000 victims.
No credit card data stolen
GM also says that this means its infrastructure was not tampered with, nor compromised.
“Based on the investigation to date, there is no evidence that the log in information was obtained from GM itself,” GM was cited as saying in an announcement.
“We believe that unauthorized parties gained access to customer login credentials that were previously compromised on other non-GM sites and then reused those credentials on the customer’s GM account.”
In the breached accounts, the cybercriminals got access to things like full names, email addresses, physical addresses, phone numbers of family members, last known and favorite locations, as well as search and destination information. Car mileage history, service history, and emergency contracts, were also on display.
Things like Social Security numbers, driver’s license numbers, credit card information or bank account information were not compromised, as GM does not store this data, the company confirmed.
Since the attack, GM asked its users to reset their passwords (opens in new tab), and told impacted customers to request credit reports from their banks.
Just as with Zola, whose customers have had their accounts compromised following a credential stuffing attack, General Motors does not support two-factor authentication (opens in new tab), BleepingComputer states. Users can add a PIN that needs to be inputted for every purchase, though.
“Businesses need to understand passwords are the vulnerability,” commented Patrick McBride, CMO at Beyond Identity. It is no longer adequate to pass the blame off on customers because their passwords were obtained elsewhere. Businesses can mitigate the password vulnerability today, by using unphishable MFA. It is well beyond the time to blame users for the failures of businesses that don’t use adequate authentication methods when they already exist.”
Via: BleepingComputer (opens in new tab)
Audio player loading… A large number of General Motors (GM) user accounts have been breached, and their personally identifiable information (opens in new tab) stolen, the company has confirmed in a recent announcement sent to affected customers. What’s more, the cybercriminals behind the attack tried to redeem rewards points found…
Recent Posts
- Reddit is experiencing outages again
- OpenAI confirms 400 million weekly ChatGPT users – here’s 5 great ways to use the world’s most popular AI chatbot
- Elon Musk’s AI said he and Trump deserve the death penalty
- Grok resets the AI race
- The GSA is shutting down its EV chargers, calling them ‘not mission critical’
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010