EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2024-dell-customer-data-leak
098/430

File EL-0333HighResolvedData Breach / Account Scraping / API Abuse

Dell Customer Data Leak

Also filed as Dell API Abuse · Dell Data Breach 2024

A threat actor scraped approximately 49 million Dell customer records by exploiting an API vulnerability in Dell's partner portal. Exposed data included names, physical addresses, email addresses, and purchase history.

  • #dell
  • #technology
  • #pii
  • #api-abuse
  • #data-scraping
  • #customer-data
Notoriety8/10
Event
25 Apr 2024
Disclosed
25 Apr 2024
Target
Dell Technologies
Actor
Menelik
Scale
49.0M people
Status
Resolved

01Summary

In April 2024, a threat actor known as 'Menelik' scraped approximately 49 million customer records from Dell by abusing an API endpoint in Dell's partner portal. The API was intended for warranty lookups but lacked rate limiting and authentication controls, allowing enumeration of customer IDs. Exposed data included full names, physical addresses, email addresses, phone numbers, and detailed purchase history. Dell confirmed the breach but downplayed the severity as no financial data was exposed.

02Background

Dell Technologies is one of the world's largest technology companies, selling computers, servers, and IT solutions to consumers and enterprises worldwide. Its customer database spans decades of sales data.

03Key revelations

  1. 01Major tech company lacked basic API security controls
  2. 02Sequential customer IDs made mass enumeration trivial
  3. 03Dell's partner portal API had no rate limiting or authentication

04Technical analysis

The attacker exploited an unauthenticated API endpoint in Dell's partner portal used for warranty validation. The API accepted numeric customer IDs that were sequential and predictable, allowing the attacker to enumerate millions of IDs without authentication or rate limiting. This is a classic example of insecure direct object reference (IDOR) combined with missing rate limiting.

05Threat actor

Menelik is an individual threat actor known for exposing security vulnerabilities through public data dumps rather than financial extortion. Their motivations appear focused on demonstrating security failures rather than monetary gain.

Aliases

  • Menelik Hacker

Known members

  • Menelik

Attribution sources

  • BreachForums posts
  • Menelik statements
  • Dell official disclosure

06Victims and impact

The leak exposed millions of customers to targeted phishing and social engineering attacks. Dell faced reputational damage and scrutiny over its API security practices.

Evidence of breach

Menelik posted the full dataset on BreachForums, offering it for free or as a demonstration of Dell's poor security. The data was verified by multiple cybersecurity researchers.

Countries affected

  • United States
  • Canada
  • United Kingdom
  • Australia
  • India
  • Global

07Data exposed

Data types

  • Full Names
  • Physical Addresses
  • Email Addresses
  • Phone Numbers
  • Purchase History
  • Order Details
  • Service Tags
  • Product Descriptions

08Financial damage

Primarily reputational damage and regulatory scrutiny. No direct ransom demand.

09Timeline

  1. 2024-04-01Estimated start of API enumeration by attacker
  2. 2024-04-25Menelik posts 49M records on BreachForums
  3. 2024-04-25Dell confirms breach in public statement
  4. 2024-05-10Dell completes API remediation
  5. 2024-05-15Dell begins notifying affected customers

10Reaction and fallout

Public reaction

Significant concern among Dell customers about the ease with which their data was scraped, leading to increased phishing awareness.

Political impact

Contributed to discussions about API security regulations and data protection obligations for large technology companies.

11Legal

No major legal action publicly reported. Dell faced potential GDPR and CCPA scrutiny.

12Aftermath

Policy changes

  • Dell implemented API rate limiting and authentication requirements

Security improvements

  • Rate limiting on API endpoints
  • Authentication requirements for partner portal access
  • Removal of sequential customer IDs from public-facing APIs

13Significance and legacy

Significance

The Dell breach exemplified the danger of relying on security-through-obscurity (sequential IDs) and missing basic API protections at a Fortune 500 company.

Legacy

Served as a case study in API security failures and the importance of rate limiting, authentication, and non-predictable identifiers in customer-facing APIs.

14Disclosure and media

Authentication
Independent verification by cybersecurity researchers and journalists

Publishing organisations

  • BleepingComputer
  • The Register
  • TechCrunch
  • Wired

15Field notes

  1. 01The attacker Menelik claimed the API was so poorly protected that a simple Python script could scrape thousands of records per minute.
  2. 02Dell is one of many companies that have suffered from 'sequential ID' enumeration attacks, a vulnerability class that has existed for decades.

16Resolution

Dell patched the vulnerable API endpoint, implemented rate limiting, and added authentication requirements. Affected customers were notified.

17Sources

Official documents

  • Dell data breach notification to affected customers

References

  1. [1]BleepingComputer
  2. [2]The Register
  3. [3]TechCrunch
  4. [4]Dell official statement
Fact sheetEL-0333

Dates

Event
25 Apr 2024
Started
1 Apr 2024
Ended
25 Apr 2024
Duration
25 days
Discovered
25 Apr 2024
Disclosed
25 Apr 2024
Resolved
10 May 2024
Ongoing
No

Target

Organisation
Dell Technologies Inc.
Type
Technology Company
Sector
Technology
Country
United States

Actor

Name
Menelik
Type
Solo Actor
Motivation
Notoriety and demonstration of security vulnerabilities
Attribution
High
Arrested
No
Convicted
No

Data

People
49,000,000
Sensitivity
Confidential
Published
Yes
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.