One Dark Web Listing. 13,347 BMW Hong Kong Customer Records Exposed.
HEROIC analysts identified a database breach affecting BMW Concessionaires in Hong Kong, with records surfacing on July 18, 2024. The breach exposed 13,347 customer records containing phone numbers, first names, and last names. The data originated from a customer database associated with the official BMW dealership operation in Hong Kong, affecting individuals who had provided their contact details to the company.
With 13,347 customer phone numbers paired with full names, attackers can launch targeted SMS phishing campaigns that address victims by their real names, dramatically increasing the likelihood of a successful deception. Name and phone number combinations also enable SIM-swapping attempts and social engineering calls impersonating BMW representatives, financial institutions, or government agencies. The fact that this data came from a premium automotive brand means the victims are statistically more likely to be high-value targets for financial fraud.
What Was Exposed
- Phone Number (Mobile)
- First Name
- Last Name
Why This Matters
Name and phone number exposure enables highly targeted vishing and smishing attacks where criminals contact victims directly by name, impersonating trusted brands or institutions. SIM-swapping attacks become possible when enough personal identifiers are available to convince a mobile carrier to transfer a phone number to an attacker-controlled SIM, bypassing SMS-based two-factor authentication on banking and email accounts. Identity theft and fraud are direct downstream risks, and the personal nature of this data makes it useful for building profiles that can be sold or combined with other leaked datasets to produce even more complete victim records.
How Database Breaches Work
Database breaches targeting customer relationship management systems occur when an attacker exploits a vulnerability in a web application, an exposed database endpoint, or compromised administrative credentials to gain direct access to stored customer records. Automotive dealerships and their associated CRM platforms hold structured customer contact data collected during sales inquiries, service appointments, and marketing opt-in processes. Once an attacker extracts this data, it is typically compressed, packaged, and distributed on underground forums or sold to other threat actors who specialize in monetizing personal contact information through targeted fraud campaigns.
Check If You Are Affected
HEROIC's free breach scanner checks your personal data against more than 400 billion exposed records, including regional breaches like this BMW Hong Kong incident. Run a free scan at heroic.com to find out if your information appeared in this or any related data breach.
Breach Breakdown
13,347 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds