1.6 million hit in possible Mercedes-Benz data breach — what you need to know

Mercedes-Benz USA yesterday (June 24) disclosed a data leak on the part of a third-party vendor that exposed the personal information of up to 1.6 million prospective and actual customers, including names, street addresses, email addresses and phone numbers.
In addition, said Mercedes-Benz USA, “less than 1,000” people had very sensitive personal information — such as “driver’s license numbers, Social Security numbers, credit-card information and dates of birth” — exposed. Mercedes-Benz said it would provide free credit monitoring and identity-theft protection to those individuals.
If the data was indeed stolen (there’s no evidence yet that it was), then those 1,000 or so individuals are at elevated risk of identity theft. A full name, street address, date of birth and Social Security number are often all you need to open accounts in someone else’s name.
Anyone told by Mercedes-Benz USA that that very sensitive information was exposed should consider accepting the credit-monitoring offer, though be sure to read the fine print as signing on may limit your options for legal action in the future. Alternately, you might want to consider paying for one of our best identity theft protection services.
You should also notify one of the Big Three credit-reporting agencies to place a fraud alert on your credit file, and that agency will notify the other two of the Big Three. You may want to consider instituting a credit freeze as well, though that can have some unexpected side effects. Here are instructions on how to place a fraud alert and credit freeze.
Mercedes-Benz USA said it was told by the unnamed vendor on June 11, as “part of an ongoing investigation” into an “issue … uncovered through the dedicated work of an external security researcher,” that the data “was inadvertently made accessible on a cloud storage platform.”


