EBlock notified nearly 2,000 people of breach of legacy ABS Auto Auctions systems
- Organization
- EBlock Corp.
- Exploit
- Hacking
- Industry
- Automotive Auctions
EBlock Corp., a Toronto-based dealer-to-dealer digital vehicle auction platform, disclosed that an unauthorized party had reached part of the legacy infrastructure it inherited from ABS Auto Auctions. The company said it detected the unauthorized access on August 14, 2023, and law firm write-ups of the notice describe the intrusion window as August 12 to 14, 2023.
EBlock began mailing notification letters on April 8, 2024, roughly eight months after discovery. Comparitech reported that close to 2,000 people were notified, while the law firm Strauss Borrelli put the figure at more than 1,500.
According to the notice, the exposed information included names, dates of birth, Social Security numbers, driver's license numbers, and bank account and routing numbers. EBlock said all impacted systems had been secured and restored, and it offered those notified free credit monitoring through Kroll along with advice to watch credit reports, tax filings and bank statements.
EBlock did not publicly attribute the intrusion. Comparitech noted that the Play ransomware group had claimed an attack on absautoauctions.com in August 2023, a domain that now redirects to EBlock, saying it had taken client and employee documents, contracts and financial information. Plaintiffs' firms opened investigations into potential class action claims after the notices went out.