Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

General Motors Customer Data Leaked By Credential Stuffing Attacks

General Motors Customer Data Leaked By Credential Stuffing Attacks

Randy Hall By Randy Hall Updated Jul 2024 2 min read Share

Do you own a Chevrolet, Buick, GMC, or Cadillac?  If so, be aware that GM recently acknowledged that they fell victim to a credential stuffing attack a little over a month ago.

The attack exposed some customer information to the attackers and allowed them to redeem an undisclosed number of rewards points for gift cards.

The company said that they detected suspicious network activity between April 11th and April 29th of 2022.  In a letter sent to those impacted by the breach, GM indicated that they would be restoring rewards points for everyone who was impacted.

While it's small consolation, it's worth noting that this isn't a case of the company being hacked.  Credential stuffing attacks see the threat actors use many different usernames and passwords purchased from the Dark Web in a wholesale attempt to find a combination that will work on a given website.  The company stressed that there is no evidence the attackers gained this information from GM's network itself.

If you were among the impacted customers, be aware that the following information was exposed:

  • Customer first and last name
  • Personal email address
  • Personal physical address
  • Username and phone number for registered family members tied to the account
  • Last known and saved favorite location information
  • Currently subscribed OnStar package (if applicable)
  • Family members' avatars and photos (if uploaded)
  • Profile picture
  • And search & destination information

The attackers may have also gained access to less useful information such as car milage history, service history, Wi-Fi Hotspot settings, emergency contact information and the like.

As breaches go, this one wasn't as bad as many of the others we've heard about thus far this year. However, armed with the information above, a hacker would certainly have enough details to steal someone's identity. So be warned and stay vigilant.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime