RevolutionParts, which provides e-commerce infrastructure to automotive dealerships, suffered a breach in July 2026 exposing data described at more than five million records.
None of those customers has heard of the company. They bought a part from a dealership, on what appeared to be that dealership’s website.
White-Label Platforms Aggregate Invisibly
The commercial proposition of a white-label platform is that the customer never perceives it. Each dealership presents its own brand, and the shared infrastructure behind them is deliberately unadvertised.
That works well until disclosure. The affected person has a relationship with a dealership, will likely be notified by the dealership, and has no basis for understanding that the same event affected several million people across hundreds of unrelated businesses.
Independent Businesses, Correlated Risk
From each dealership’s perspective this was a supplier incident. From the platform’s perspective it was one incident. From a regulator’s perspective it is potentially hundreds of separate notification obligations, discharged inconsistently and on different days.
It is the KDDI pattern from 26-0623 in a different industry: correlated failure with uncorrelated disclosure, which reliably understates the scale of what happened.
Compiled from public reporting, listed below. The number of downstream dealerships affected has not been disclosed. Corrections: corrections@forensicpost.com.