1.6 million hit in possible Mercedes-Benz data breach — what you need to know

Mercedes EQS
(Image credit: Daimler)

Mercedes-Benz USA yesterday (June 24) disclosed a data leak on the part of a third-party vendor that exposed the personal information of up to 1.6 million prospective and actual customers, including names, street addresses, email addresses and phone numbers.

In addition, said Mercedes-Benz USA, "less than 1,000" people had very sensitive personal information — such as "driver's license numbers, Social Security numbers, credit-card information and dates of birth" — exposed. Mercedes-Benz said it would provide free credit monitoring and identity-theft protection to those individuals.

If the data was indeed stolen (there's no evidence yet that it was), then those 1,000 or so individuals are at elevated risk of identity theft. A full name, street address, date of birth and Social Security number are often all you need to open accounts in someone else's name. 

Anyone told by Mercedes-Benz USA that that very sensitive information was exposed should consider accepting the credit-monitoring offer, though be sure to read the fine print as signing on may limit your options for legal action in the future. Alternately, you might want to consider paying for one of our best identity theft protection services.

You should also notify one of the Big Three credit-reporting agencies to place a fraud alert on your credit file, and that agency will notify the other two of the Big Three. You may want to consider instituting a credit freeze as well, though that can have some unexpected side effects. Here are instructions on how to place a fraud alert and credit freeze.

Mercedes-Benz USA said it was told by the unnamed vendor on June 11, as "part of an ongoing investigation" into an "issue ... uncovered through the dedicated work of an external security researcher," that the data "was inadvertently made accessible on a cloud storage platform." 

This just happened to Volkswagen too

On that same day, June 11, Volkswagen of America disclosed that it too had had the personal data of 3.3 million prospective and actual Audi customers exposed on an unnamed third-party vendor's database. Some of the Audi data later showed up for sale in an online cybercrime marketplace. 

The timing and striking similarities between the two incidents involving the North American branches of German luxury carmakers may be only circumstantial.

For the moment, it's not clear whether any of the Mercedes-Benz data was stolen from the database before its unprotected state was discovered and fixed. 

"We have no evidence that any Mercedes-Benz files were maliciously misused," the company said. "No Mercedes-Benz system was compromised as a result of this incident."

The company said that anyone trying to view the exposed data "would need knowledge of special software programs and tools" and that "an internet search would not return any information contained in these files."

The data was entered into Mercedes-Benz USA dealer and company websites by customers and prospective buyers between Jan. 1, 2014 and June 19, 2017, the company said.

If you have concerns, you can call Mercedes-Benz USA at (800) 367-6372.

Read next: The Mercedes EQE SUV has just been announced, and here's everything you need to know

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
A picture showing different credit cards stacked on top of each other on a table
5 million Americans just had their credit card details leaked online — what to do now
An open lock depicting a data breach
3.5 million hit in major law firm data breach — full names, SSNs, dates of birth, addresses and more exposed
Image of man on computer with data security ecosystem
Over 900,000 Americans just had their personal and health info exposed in medical data breach — names, phone numbers, treatments and SSNs
An open lock depicting a data breach
More than 3.3 million people hit by employee screening data hack — what you need to know
Globe Life insurance company logo on a cell phone in front of a monitor display the About page for the company. Shadowy hand holds the phone.
850,000 people exposed in massive insurance data breach — full names, dates of birth and SSNs
An open lock depicting a data breach
Massive healthcare data breach just exposed the personal info of 1 million Americans — what to do now
Latest in Online Security
and image of the Google Chrome logo on a laptop
Google Chrome at risk from shape-shifting browser extensions — how to stay safe
Green skull on smartphone screen.
Over 1 million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
An Android bot next to an Android TV remote
Millions of Android TVs hijacked in massive botnet — how to see if yours is at risk
Poster of Elon Musk saying "I am stealing from you"
Elon Musk's DOGE blocked from accessing your data – and 3 in 4 Americans agree
A fake text message on a smartphone being held by both hands.
Toll road scams are worse than ever — what to look for and how to stay safe
Latest in News
NYTimes Connections
NYT Connections today hints and answers — Sunday, March 9 (#637)
Prime Gaming's selection of free games for March 2025
Amazon Prime is giving away these 20 games in March — get Fallout, Saints Row 3, and more free games now
Hugh Grant as Mr. Reed in "Heretic"
Max top 10 movies — here’s the 3 worth watching right now
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #371 (Sunday, March 9 2025)
Nintendo Switch 2
Nintendo Switch 2 price rumors and predictions — everything we've heard so far
Samsung Galaxy S25 Edge back
Samsung Galaxy S25 Edge latest leak hints at good news for pricing