Desk live·
ForensicPost
Breaches/API/File 24-0510

Dell Partner Portal API Gave Up 49 Million Records to Fake Resellers

Someone registered partner accounts under invented company names, waited two days for approval, then generated seven-digit service tags and queried them in bulk. Dell confirmed 49 million records on 10 May 2024.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetDell
ActorUnattributed
D. Kennedy9 min readConfidence: high2 sources reviewed

Dell confirmed on 10 May 2024 that around 49 million customer records had been scraped through a portal intended for partners, resellers and retailers. Reported fields are names, physical addresses and purchase details including the seven-digit service tag, system serial number, Dell customer number, order number and warranty information. Dell said no payment or financial information, email addresses or telephone numbers were involved.

Reporting describes the method as registering multiple partner accounts under fabricated company names, receiving access within about two days without verification, then generating service tags programmatically and submitting them to the lookup page from March onwards.

Authentication Worked; Authorisation Did Not

The accounts were real accounts. The portal checked that the caller was a partner and did not check whether that partner had any relationship with the customer being looked up.

Those are different controls and only one was present. Any partner could query any customer, which makes the partner tier the effective security boundary — and that tier was granted to anyone who filled in a form and waited two days.

A Seven-Digit Key Is A Small Space

The service tag identifies a machine and is short enough to enumerate exhaustively. Once a lookup accepts an identifier from that space and returns a record, the entire customer base is reachable by counting.

The same shape produced the Trello scrape in January: an identifier that is not secret, an endpoint that resolves it, and no limit on how often. Nothing was exploited here in the ordinary sense — the portal was used exactly as built, at a volume nobody bounded.

How we reported this

Compiled from Dell’s notification and public reporting, listed below. The account-registration method and start date come from reporting of the attacker’s own account rather than from Dell. Corrections: corrections@forensicpost.com.

Sources
  1. Dell API abused to steal 49 million customer records in data breachBleepingComputer
  2. Dell: 49 million customer records exposed in 1 automated attackBarracuda
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary