The 700Credit 2025 data breach occurred when third-party API access connected to the company's 700Dealer.com application was abused and consumer records were copied without authorization. 700Credit, which provides credit-report and identity-verification services to automotive dealers, detected suspicious activity on October 25, 2025. Its subsequent investigation confirmed that an unauthorized party had obtained certain records associated with its dealership clients.
A filing with the Maine Attorney General identifies 5,836,521 affected individuals. The exposed information varied by person but included names, physical addresses, dates of birth, and Social security numbers. This record uses the official total for pwnCount and totalRecords; it does not add dealership, transaction, or API-request counts to the number of people, and LeakData does not import any compromised personal data.
How Was the Incident Confirmed?
700Credit's notification letter to affected individuals explicitly states that certain records in the web application relating to its dealership clients were copied without authorization. The letter's filing with the Maine Attorney General officially confirms both that the event was a personal-data breach and that the notification scope reached 5,836,521 people. The Michigan Attorney General also published a consumer warning describing the incident and the affected data types.
BleepingComputer reviewed the official letter and statements from a company executive, reporting that the attack used an API reached through a compromised third-party integration partner. Its coverage independently corroborates the confirmed data fields, investigation timeline, and twelve months of identity-protection support. LeakData relies on findings shared by these sources and does not speculate about the attacker's identity or undisclosed technical details.
How Was the Third-Party API Used?
According to the company's account, an attacker entered the system of one of 700Credit's integration partners in July 2025 and discovered an API used to retrieve consumer information. The partner did not notify 700Credit of that compromise at the time. A control weakness that failed to validate a consumer reference identifier adequately against the original requester allowed the attacker to request consumer records without authorization.
After observing unusual activity on October 25, 700Credit began an investigation with external computer-forensics specialists and terminated the exposed API. A company executive publicly said the attacker obtained roughly twenty percent of consumer data collected from dealerships between May and October 2025. Because no exact first-access day was published, breachDate uses October 25, the verified date on which the company detected and began responding to the activity.
What Personal Information Was Affected?
The notification materials confirm four data classes: full names, physical addresses, dates of birth, and Social security numbers. The same fields were not necessarily present for every person, because the company said the contents varied by individual. Social security numbers create lasting exposure to identity theft and fraudulent credit applications, so this LeakData record is assigned high severity and critical sensitivity.
The cited sources do not place payment-card numbers, bank-account passwords, biometric templates, or driver's-license numbers within the confirmed scope. Those categories are therefore not added. Although 700Credit provides credit-reporting and identity-verification products, every type of information used across its product catalog cannot be assumed breached; the record remains limited to the four categories explicitly named in the notice.
How Were the Company Network and Dealers Affected?
700Credit said its internal network was not compromised and that the event was limited to the 700Dealer.com application layer. The initial access at an integration partner makes this a third-party connection risk that expanded through an application interface. The record does not, however, treat every system of the unnamed partner or each 700Credit dealership customer as a separate breach without supporting evidence.
The company began notifying affected dealership clients on November 21 and said written notices to individuals would begin on December 22. In coordination with the National Automobile Dealers Association, it submitted a consolidated notice to the Federal Trade Commission on its own behalf and for affected dealer clients. State attorneys general and the FBI were also notified about the incident.
What Should Affected People Do?
700Credit offered affected individuals twelve months of free credit monitoring and identity-restoration services through TransUnion. Notice recipients should enroll before the stated deadline, review their credit reports regularly, and report unfamiliar accounts or inquiries promptly. Messages that appear to come from the company but request a Social Security number or payment should be verified through an independently obtained contact channel.
Because a Social Security number is not readily replaceable, short-term monitoring alone may not address the continuing risk. U.S. consumers can place a free security freeze with all three major credit bureaus, use strong multifactor authentication on tax and government accounts, and watch for identity-theft indicators over the long term. A security freeze does not close existing accounts; it makes unauthorized new credit more difficult to open.
How Should This LeakData Record Be Read?
The pwnCount and totalRecords values are the 5,836,521 individuals reported to the Maine Attorney General. The rounded 5.8 million in news headlines and smaller interim totals in individual state filings are not added separately. The incident date is October 25, 2025, the verified day on which 700Credit detected suspicious activity; the third-party access beginning in July is described in the timeline without inventing an exact day.
importedRecordCount is zero: LeakData stores no names, addresses, birth dates, or Social security numbers from the incident. This entry contains only the event identity, verified total, data classes, response information, and source links. The scope can be reassessed if a regulator issues a correction or the company publishes a final forensic report; the current account does not exceed what official notices and independent reporting support.