Dell confirmed on 10 May 2024 that around 49 million customer records had been scraped through a portal intended for partners, resellers and retailers. Reported fields are names, physical addresses and purchase details including the seven-digit service tag, system serial number, Dell customer number, order number and warranty information. Dell said no payment or financial information, email addresses or telephone numbers were involved.
Reporting describes the method as registering multiple partner accounts under fabricated company names, receiving access within about two days without verification, then generating service tags programmatically and submitting them to the lookup page from March onwards.
Authentication Worked; Authorisation Did Not
The accounts were real accounts. The portal checked that the caller was a partner and did not check whether that partner had any relationship with the customer being looked up.
Those are different controls and only one was present. Any partner could query any customer, which makes the partner tier the effective security boundary — and that tier was granted to anyone who filled in a form and waited two days.
A Seven-Digit Key Is A Small Space
The service tag identifies a machine and is short enough to enumerate exhaustively. Once a lookup accepts an identifier from that space and returns a record, the entire customer base is reachable by counting.
The same shape produced the Trello scrape in January: an identifier that is not secret, an endpoint that resolves it, and no limit on how often. Nothing was exploited here in the ordinary sense — the portal was used exactly as built, at a volume nobody bounded.
Compiled from Dell’s notification and public reporting, listed below. The account-registration method and start date come from reporting of the attacker’s own account rather than from Dell. Corrections: corrections@forensicpost.com.