Dell says data breach affecting 49 million customers poses no 'significant risk’
Dell claims customers aren’t exposed to significant risk in the wake of a major breach, but they should be wary of targeted social engineering attacks.
Dell has contacted customers warning of a data breach containing purchase information related to 49 million individuals.
The technology giant said it was currently looking into a security incident involving a Dell portal, which contains a database storing “limited types of customer information” linked to recent purchases of Dell products.
Its investigation indicated the information compromised in the breach was limited to customer names, addresses, their Dell customer info, and product information related to their purchase.
Dell said it immediately implemented its incident response procedures once it was aware of the breach, taking a number of steps to contain the incident and notifying law enforcement.
Financial or payment information, email addresses, and telephones, were not included in leaked data, according to Dell, who claimed there was not a “significant risk” to customers as a result.
On 29 April 2024, open source intelligence resource Daily Dark Web reported a threat actor with the name ‘Menelik’ was selling access to a database containing 49 million customer records on a hacking forum hosted on the dark web.
The listing stated that the database for sale contained information related to systems purchased from Dell between 2017 - 2024, and the countries with the most systems included in the breach were the US, China, India, Australia, and Canada.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Around 7 million entries were related to individual or personal purchases, with 11 million pertaining to consumer segment companies. The rest of the information was linked to enterprise customers including partners and schools.
Notification email from Dell warning customers their information was leaked in a data breach.
The type of information Menelik stated was included in the compromised database aligns with what Dell said was exposed in the data breach disclosed on 9 May.
Notably, however, a twitter account dedicated to providing intel on dark web activity, DarkWebInformer, claimed the listing created on the underground forum no longer exists, but suggested the post may still be legitimate.
ITPro contacted Dell for clarification on whether this data was the same, but at the time of writing the company has yet to respond.
Why Dell customers should be wary
Although Dell claimed it did not consider the incident exposed its customers to ‘significant risk’ as the leaked data did not include particularly sensitive information like email addresses, phone numbers, or financial data, it did advise customers to exercise caution.
RELATED WHITEPAPER
Dell’s breach notification recommended customers impacted by the incident to take steps to protect themselves against social engineering attacks using information compromised in the breach, providing tips on how to detect tech support scams in particular.
The threat from social engineering attacks has grown in recent years, in April IT security specialist Zscaler reported it had blocked around 2 billion phishing attempts in 2023, marking a 60% increase year on year (YoY).

Solomon Klappholz is a former staff writer for ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing, which led to him developing a particular interest in cybersecurity, IT regulation, industrial infrastructure applications, and machine learning.
-
The EU is charting a course to digital independence with the technological sovereignty packageNews New legislation looks to shore up digital sovereignty and reduce reliance on foreign tech
-
Anthropic warns AI is helping lower the bar for up-and-coming hackersNews AI is making it harder to differentiate between high and low-skilled actors
-
Why cyber resilience isn’t just a defence mechanism: How to create a secure foundation for innovation, tooSponsored Investing in a solid enterprise system that incorporates security by design lets you ensure business continuity while encouraging innovation at pace
-
How to achieve cyber resilience today, tomorrow, and beyondResilience in the event of an attack is a business need, not a nice-to-have
-
‘Resilience debt’ is now one of the most pressing cyber challenges for enterprises – here's what it means and how you can tackle itNews Research from Dell Technologies suggests the gap between cyber resilience and perception of readiness is getting bigger
-
Critical Dell Storage Manager flaws could let hackers access sensitive data – patch nowNews A trio of flaws in Dell Storage Manager has prompted a customer alert
-
Futurum Group endpoint security trends 2023whitepaper Protection across AI attack vectors