HomeSecurityGeneral Motors (GM): Credential stuffing attack exposed customer data

General Motors (GM): Credential stuffing attack exposed customer data

American automaker General Motors (GM) has revealed that it fell victim to a credential stuffing attack that exposed customer and allowed attackers to redeem reward points for gift cards.

GM customer data

General Motors has an online platform that helps owners of Chevrolet, Buick, GMC and Cadillac manage their accounts, services and redeem reward points.

See also: Clearview AI: Fined by the UK for data collection

Car owners can redeem GM Rewards points for vehicles , car service, accessories and with the purchase of OnStar service plans.

General Motors Credential stuffing

General Motors (GM): Credential stuffing attack

According to the company, the malicious activity was detected between April 11 and 29, 2022.

“We are writing as a follow-up to our email [DATE] to you, informing you of an incident involving the detection of a recent redemption of your reward points that appears to have been made without your authorization,” explains a data breach notification sent to affected customers.

The automaker says it will reinstate reward points for all customers affected by this incident.

See also: Predator spyware infected Android devices using zero-days

According to the company, these breaches are not the result of a hack of General Motors, but were caused by credential stuffing attacks targeting customers on its platform. In these types of attacks, criminals use username and password combinations that have been leaked from old data breaches of other websites. Using these combinations, attackers try to gain access to user accounts on a website. After all, it is not uncommon for users to use the same credentials on multiple different accounts.

“Based on the investigation to date, there is no evidence that the login information was obtained by GM itself,” explains a different data breach notification from General Motors.

“We believe that unauthorized users gained access to customer credentials that had been previously compromised on other non-GM websites, and those credentials were reused on GM accounts“.

General Motors is asking users to reset their passwords before logging back into their accounts.

General Motors (GM): Credential stuffing attack exposed customer data

General Motors: Customer data breach

Once hackers successfully breach a GM account, they can access certain information stored on the site. This information includes:

  • First and last name,
  • personal email address,
  • personal home address,
  • username and phone number for registered family members associated with the account,
  • OnStar package (if available),
  • avatars and photos of family members (if uploaded),
  • profile picture,
  • search and destination information

Additionally, hackers who compromise GM accounts can access a car's mileage history, service history, emergency contacts, Wi-Fi (including passwords), and more.

See also: Russian Turla group carries out attacks against Austria and Estonia

GM accounts do not contain information such as birth dates, social security numbers, driver's license numbers, credit card information, or bank account information. Therefore, this information has definitely not been compromised.

Unfortunately, the General Motors website does not support two-factor authentication, which could prevent successful credential stuffing attacks. However, it is possible to add a PIN that customers must use for all purchases.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS