TSLA455.2500.77%
GM75.7600.475%
F13.1500.01%
RIVN18.2200.16%
CYD36.0400.55%
HMC29.555-0.108%
TM196.575-1.7625%
CVNA399.2400.39%
PAG162.640-0.98%
LAD323.570-1.44%
AN214.070-1.06%
GPI408.330-0.02%
ABG234.9901.09001%
SAH64.870-0.03%
TSLA455.2500.77%
GM75.7600.475%
F13.1500.01%
RIVN18.2200.16%
CYD36.0400.55%
HMC29.555-0.108%
TM196.575-1.7625%
CVNA399.2400.39%
PAG162.640-0.98%
LAD323.570-1.44%
AN214.070-1.06%
GPI408.330-0.02%
ABG234.9901.09001%
SAH64.870-0.03%
TSLA455.2500.77%
GM75.7600.475%
F13.1500.01%
RIVN18.2200.16%
CYD36.0400.55%
HMC29.555-0.108%
TM196.575-1.7625%
CVNA399.2400.39%
PAG162.640-0.98%
LAD323.570-1.44%
AN214.070-1.06%
GPI408.330-0.02%
ABG234.9901.09001%
SAH64.870-0.03%
Dealers' #1 source for auto industry news, content, coaching & analysis

700Credit’s Ken Hill on recent data breach and what dealers need to know

700Credit, a credit check and compliance provider, suffered a significant data breach in late October, affecting nearly 18,000 dealerships and more than 5.6 million customers. On today’s episode of Inside Automotive, 700Credit Managing Director Ken Hill discusses what happened and how the company is responding.

700Credit communicates with over 200 integration partners through APIs. One of those partners was compromised in July, but the company did not notify 700Credit. Hackers took over that partner’s system and gained access to communications logs, which exposed an API used to pull consumer information. The breach revealed a vulnerability in 700Credit’s validation process.

Sign up for CBT News’ daily newsletter and get the latest industry stories delivered straight to your inbox.

On Oct. 25, hackers launched a sustained velocity attack that continued for more than two weeks. Although 700Credit shut down the exposed API, attackers still managed to obtain about 20% of consumer data from May to October 2025. The attack did not penetrate 700Credit’s internal systems, which remained operational throughout the incident.

"I wanted to be able to tell our customers that we've done everything we could."

Hill urges dealership groups of all sizes, particularly those with limited cybersecurity budgets, to prioritize education and adopt best practices to reduce the risk of becoming targets.

700Credit, in partnership with the National Automobile Dealers Association (NADA), coordinated with the Federal Trade Commission (FTC) to file a consolidated breach notice on behalf of all affected dealerships. The company also reported the incident to the FBI on behalf of the dealers.

The company is currently notifying state agencies and impacted consumers. All affected consumers will receive one to two years of free credit monitoring, a free credit report and access to a dedicated support line.

The company has increased its cybersecurity insurance, strengthened API inspections and is moving toward a more secure system backbone with enhanced protections.

 

Stay up to date on exclusive content from CBT News by following us on Facebook, Twitter, Instagram and LinkedIn.

Don’t miss out! Subscribe to our free newsletter to receive all the latest news, insight and trends impacting the automotive industry.

CBT News is part of the JBF Business Media family.

Jasmine Daniel
Jasmine Daniel
Jasmine Daniel is a staff writer and reporter for CBT News. She holds a BFA in Writing from the Savannah College of Art & Design and has over eight years of experience in SEO, digital marketing, and strategic communication. Her storytelling skills bring breaking news to life, delivering timely, impactful stories that resonate with readers.

Related Articles

Latest Articles

From our Publishing Partners