Mercedes Benz Leaks Customers’ Social Security Numbers and Other Personal Data in a Breach

  • By Dawna M. Roberts
  • Published: Jul 14, 2021
  • Last Updated: Mar 18, 2022

 Luxury car brand Mercedes Benz just released a public announcement notifying customers of a data breach which included driver’s license details, dates of birth, social security numbers, and payment card details.

What Happened?

The notification mentions that on June 11, 2021, a vendor of Mercedes Benz notified them that information on customers and interested buyers stored in a cloud service was accidentally exposed and potentially accessed by an unauthorized party. The matter came to light when a cybersecurity researcher discovered the information and notified Mercedes Benz.

The carmaker reassured customers by saying, “It is our understanding the information was entered by customers and interested buyers on dealer and Mercedes-Benz websites between January 1, 2014, and June 19, 2017. No Mercedes-Benz system was compromised as a result of this incident, and at this time, we have no evidence that any Mercedes-Benz files were maliciously misused.”

“The vendor reports that the personal information for these individuals (less than 1,000) is comprised mainly of self-reported credit scores as well as a very small number of driver license numbers, social security numbers, credit card information, and dates of birth. To view the information, one would need knowledge of special software programs and tools - an Internet search would not return any information contained in these files,” the company further explained.

How Did Mercedes Benz Handle the Situation?

The original stash of information contained more than 1.6 million records; however, the investigation revealed that only around 1,000 had personally identifiable information (PII) that hackers could use for identity theft and fraud.

Mercedes Benz’s vendor assured the carmaker that the issue has been fixed and cannot reoccur. Although there is no evidence indicating that any unauthorized person accessed or copied the information, it is unclear how long it was exposed.

The company has been notifying customers in writing and is offering 24 months of credit monitoring services to those affected customers and interested buyers.

InfoSecurity Magazine spoke with Tom Garrubba, CISO at risk management firm  Shared Assessments who commented that “With all the cyber-incidents that have been reported recently, it is refreshing to see that swift action taken by Mercedes Benz USA in addressing the incident with their cloud service provider and ultimately, with their customers,” he added.

“The reported breach of 1000 existing and prospective customers via their cloud storage vendor’s platform should raise awareness of the importance of proper due diligence and understanding as to how your cloud service providers are protecting your data.”

What to Do After a Data Breach

Following a data breach, customers are typically notified by the company responsible for leaking the information. If your information was exposed in a data breach, it is critical to take swift action to protect yourself against identity theft and fraud. Some tips for doing so are:

  • Change all your current passwords.
  • Never use the same passwords on multiple websites.
  • Do not click links or download attachments in emails. Often, after a data breach, cybercriminals use phishing emails to try and steal additional information.
  • Review all monthly credit card and bank statements looking for unauthorized transactions.
  • Get a copy of your credit report.
  • Sign up for credit and identity theft protection
  • Be careful of any unsolicited calls where people ask you for information.
  • Keep strong antivirus software on all your devices and run deep scans often. Once hackers have your email address and other data, they may target you.
  • Use common sense, and if something sounds too good to be true, it probably is, walk away.

About the Author
IDStrong Logo

Related Articles

Instagram Vulnerability Allowed Hackers Access to Control Your Phone

Security experts Check Point Research discovered a critical vulnerability while examining Instagra ... Read More

Alien Malware Infects More than 226 Mobile Apps and Steals Bank Data

As reported on September 24, 2020, by ZDNet and ThreatPost, a new strain of malware named “A ... Read More

Universal Health Systems Hit by Ransomware Attack

Universal Health Systems (UHS), a Fortune 500 company owning more than 400 hospitals across the co ... Read More

Exchange Server Bug Exposes a Big Risk to Hackers

Months after Microsoft released a patch to fix a serious flaw in MS Exchange Server, more than 61% ... Read More

Clients’ Bank Data Exposed in Blackbaud Ransomware Attack

Blackbaud software was victim to a ransomware attack last May, and new information suggests that c ... Read More

Latest Articles

What You Need to Know about the Episource Data Breach

What You Need to Know about the Episource Data Breach

Episource is a California-based healthcare services and technology company that provides risk adjustment and medical coding services to healthcare plans, doctors, and several other types of healthcare organizations.

What you need to know about the Krispy Kreme Data Breach

What you need to know about the Krispy Kreme Data Breach

The popular doughnut and coffeehouse chain Krispy Kreme was established in 1937 in Winston-Salem, North Carolina. It has grown over the years and currently operates 1,500 shops and 17,900 points of access in 40 nations.

What You Need to Know about the Ocuco Data Breach

What You Need to Know about the Ocuco Data Breach

Ocuco is a Dublin-based organization that specializes in optical software solutions. Established in 1993 by Leo Mac Canna, the company initially developed software for independent optometrists.

What You Need to Know about the TxDOT Data Breach

What You Need to Know about the TxDOT Data Breach

The Texas Department of Transportation (TxDOT) is responsible for designing, planning, operating, building, and maintaining the state's transportation system to deliver a reliable and safe transportation system.

What You Need to Know about the AT&T Data Breach

What You Need to Know about the AT&T Data Breach

AT&T, one of the largest telecommunications providers in the United States and the fourth-largest telecommunications company in the world by revenue, experienced a significant data leak, which became public in June 2025.

What You Need to Know about the Mainstreet Bank Data Breach

What You Need to Know about the Mainstreet Bank Data Breach

MainStreet is a community-oriented bank in Fairfax, Virginia. Established in 2004, it is under the MainStreet Bancshares Incorporated, a small-cap financial holding organization.

Featured Articles

How to Buy a House with Bad Credit

How to Buy a House with Bad Credit

Buying your own home is the American Dream, but it might seem out of reach to those with bad credit. However, the good news is, if your credit is less than perfect, you do still have options and in most cases, can still buy a home.

How Secure Is Your Password? Tips to Improve Your Password Security

How Secure Is Your Password? Tips to Improve Your Password Security

Any good IT article on computers and network security will address the importance of strong, secure passwords. However, the challenge of good passwords is that most people have a hard time remembering them, so they use simple or obvious ones that pose a security risk.

Top 10 Senior Scams and How to Prevent Them

Top 10 Senior Scams and How to Prevent Them

Senior scams are becoming a major epidemic for two reasons. First, seniors often have a lot of money in the bank from a life of working hard and saving.

Notice

By proceeding with this scan, you agree to let IDStrong run a Free Scan of supplied parameters of your personal information and provide free preliminary findings in compliance with our Terms of Use and Privacy Notice. You consent to us using your provided information to complete the Free Scan and compare it against our records and breach databases or sources to provide your Free preliminary findings report.

Rest assured: IDStrong will not share your information with third parties or store your information beyond what is required to perform your scan and share your results.

Free Identity Threat Scan
Instantly Check if Your Personal Information is Exposed
All fields below are required
Please enter first name
Please enter last name
Please enter a city
Please select a state
Please enter an age
Please enter an email address
Close