Dell says data breach affecting 49 million customers poses no 'significant risk’
Dell claims customers aren’t exposed to significant risk in the wake of a major breach, but they should be wary of targeted social engineering attacks.
Dell has contacted customers warning of a data breach containing purchase information related to 49 million individuals.
The technology giant said it was currently looking into a security incident involving a Dell portal, which contains a database storing “limited types of customer information” linked to recent purchases of Dell products.
Its investigation indicated the information compromised in the breach was limited to customer names, addresses, their Dell customer info, and product information related to their purchase.
Dell said it immediately implemented its incident response procedures once it was aware of the breach, taking a number of steps to contain the incident and notifying law enforcement.
Financial or payment information, email addresses, and telephones, were not included in leaked data, according to Dell, who claimed there was not a “significant risk” to customers as a result.
On 29 April 2024, open source intelligence resource Daily Dark Web reported a threat actor with the name ‘Menelik’ was selling access to a database containing 49 million customer records on a hacking forum hosted on the dark web.
The listing stated that the database for sale contained information related to systems purchased from Dell between 2017 - 2024, and the countries with the most systems included in the breach were the US, China, India, Australia, and Canada.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Around 7 million entries were related to individual or personal purchases, with 11 million pertaining to consumer segment companies. The rest of the information was linked to enterprise customers including partners and schools.
Notification email from Dell warning customers their information was leaked in a data breach.
The type of information Menelik stated was included in the compromised database aligns with what Dell said was exposed in the data breach disclosed on 9 May.
Notably, however, a twitter account dedicated to providing intel on dark web activity, DarkWebInformer, claimed the listing created on the underground forum no longer exists, but suggested the post may still be legitimate.
ITPro contacted Dell for clarification on whether this data was the same, but at the time of writing the company has yet to respond.
Why Dell customers should be wary
Although Dell claimed it did not consider the incident exposed its customers to ‘significant risk’ as the leaked data did not include particularly sensitive information like email addresses, phone numbers, or financial data, it did advise customers to exercise caution.
RELATED WHITEPAPER
Dell’s breach notification recommended customers impacted by the incident to take steps to protect themselves against social engineering attacks using information compromised in the breach, providing tips on how to detect tech support scams in particular.
The threat from social engineering attacks has grown in recent years, in April IT security specialist Zscaler reported it had blocked around 2 billion phishing attempts in 2023, marking a 60% increase year on year (YoY).

Solomon Klappholz is a former staff writer for ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing, which led to him developing a particular interest in cybersecurity, IT regulation, industrial infrastructure applications, and machine learning.
-
Why Microsoft paused Patch Tuesday updates for some Dell devicesNews Select devices running Intel Innovation Platform Framework drivers encountered “poor performance”
-
5 top features of Dell PowerProtect One: The world’s most comprehensive cyber resilience platformWith PowerProtect One, organizations can capitalize on a unified, centralized cyber resilience platform
-
Why cyber resilience isn’t just a defence mechanism: How to create a secure foundation for innovation, tooSponsored Investing in a solid enterprise system that incorporates security by design lets you ensure business continuity while encouraging innovation at pace
-
US cyber resilience insights -
Resilient pharmacy care, safeguarding vital health services -
Dell PowerProtect Data Manager -
How to achieve cyber resilience today, tomorrow, and beyondResilience in the event of an attack is a business need, not a nice-to-have
-
‘Resilience debt’ is now one of the most pressing cyber challenges for enterprises – here's what it means and how you can tackle itNews Research from Dell Technologies suggests the gap between cyber resilience and perception of readiness is getting bigger

