Dell confirmed unauthorized access to a portal containing limited customer purchase information in May 2024. A threat actor using the name Menelik claimed to have scraped about 49 million records, but Dell did not confirm that figure or disclose how many people were affected. Dell said the first incident did not involve payment information, email addresses, or phone numbers.
What happened in the Dell incident?
On May 9, 2024, Dell said it was investigating unauthorized access to a portal containing limited customer purchase information. The company said it began containment and investigation measures, notified law enforcement, and engaged an external forensic firm. Dell described an incident in which information was accessed; outside reporting commonly called it a data breach. Dell’s customer notice
The disclosure followed a hacker-forum listing reported on April 29, 2024. The person behind it, using the name Menelik, claimed to have scraped customer and purchase-related records associated with Dell systems bought between 2017 and 2024. Reporting linked that claim to Dell’s notice because the described data categories overlapped. The overlap does not mean Dell confirmed every detail in the listing. TechCrunch’s account of the incident
What information did Dell say was involved?
Dell’s notice described the first incident as involving limited purchase-related information. It listed:
#1 Best Overall
- Customer names and physical addresses
- Dell hardware information, including service tags
- Item descriptions, order dates, and related warranty information
Dell said the affected database did not contain financial or payment information, email addresses, telephone numbers, or what it called “highly sensitive” customer information. That statement concerns the first disclosed dataset, not the separate later portal claim discussed below. Dell’s customer notice
What is confirmed—and what remains a claim?
| Question | What the available reporting establishes |
|---|---|
| Did Dell confirm unauthorized access? | Yes. Dell said information was accessed from a portal containing limited purchase-related customer data. Dell’s notice |
| Were 49 million customers affected? | Not confirmed. Menelik claimed about 49 million records; Dell did not disclose the number of affected customers. TechCrunch |
| Was some of the offered data genuine? | TechCrunch reported checking sample records and confirming matches to real Dell customers who agreed to verification. This supports the authenticity of some records, not the full dataset. TechCrunch |
| Was the entire 49-million-record dataset verified? | No. The cited reporting does not establish that every record was genuine, unique, complete, or current. |
| Were payment details or passwords exposed? | Dell said financial and payment information was not in the first affected database. Its listed fields did not include passwords. The cited reporting does not establish password exposure. |
| Was the technical method publicly explained? | No detailed exploit chain or specific vulnerability is established in the cited reporting. |
Why “records” does not mean “customers”
A record is a database entry; one person or organization can have multiple orders, devices, or warranty entries. “49 million records” therefore cannot automatically be translated into 49 million unique people, affected accounts, or current customers. Dell did not publish a count that resolves those distinctions.
What sample verification can—and cannot—show
TechCrunch reported that some sample information supplied by the threat actor matched real customers, including a service tag associated with a customer’s purchase. That lends credibility to the claim that the actor had genuine Dell-related data. It does not prove that all claimed records came from one intrusion, that the actor personally collected them all, or that the dataset was publicly distributed. TechCrunch’s reporting
Was there a second Dell portal incident?
A May 16, 2024 report described a separate claim by Menelik involving another Dell portal and a dataset said to include names, phone numbers, and email addresses. TechCrunch reported reviewing a sample, and said Ireland’s Data Protection Commission confirmed it had received a breach notification from Dell and was assessing the matter. This is separate reporting and should not be folded into the first incident’s confirmed list of exposed fields. TechCrunch on the later claim and Irish regulator
Recommended Free Tools
How was the information allegedly obtained?
Menelik claimed to have found flaws in Dell portals and scraped customer data. The cited public reporting does not establish a specific vulnerability, affected endpoint, or detailed attack sequence. It is reasonable to describe the access as alleged portal abuse or unauthorized automated access, but not to assert a particular technique such as SQL injection or an authentication bypass.
What does this mean for Dell customers?
A name and home address linked to a product, service tag, purchase date, or warranty can help a scammer make a message or call sound credible. Plausible risks include fake warranty-renewal or repair offers, tech-support impersonation, and phishing that refers to an actual Dell product. Linking an address to specific hardware may also create physical-security concerns in some circumstances.
The first disclosed fields do not, by themselves, show that bank accounts, payment cards, passwords, or government identity numbers were exposed. The incident is a reason to scrutinize targeted requests, not evidence that financial fraud or identity theft is inevitable. Dell advised customers to remain alert to tech-support phone scams and report suspicious activity related to Dell accounts or purchases to [email protected]. Dell’s notice
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should you do if you received a Dell notice?
- Verify the message independently. Dell community moderators confirmed that the breach-notification email was legitimate, but scammers can imitate breach notices. Don’t use links or phone numbers in a suspicious copy; go to Dell’s official website yourself to check your account or contact options. Dell community notice and moderator response
- Watch for personalized approaches. Be skeptical of unsolicited calls, texts, or emails referring to your service tag, order, warranty expiration, repair, refund, or replacement. A real product detail is not proof that the person contacting you represents Dell.
- Don’t grant access or disclose secrets. Do not give an unsolicited caller remote access to your computer, and do not provide passwords, one-time codes, payment-card details, or banking information.
- Change reused passwords as a precaution. Dell’s list of affected fields did not include passwords. If you reused your Dell password elsewhere, change it on those accounts, use unique passwords, enable multifactor authentication where available, and review sign-in alerts and account-recovery settings.
- Respond to evidence of financial fraud, not the headline alone. Dell said payment information was not in the first affected database. Contact your bank or card issuer if you see suspicious transactions or have other evidence that financial details were compromised.
Do you need a credit freeze?
A credit freeze can help restrict new credit opened in your name, but Dell’s disclosed fields did not include Social Security numbers or financial information. A freeze is not a required response for every Dell customer based on the disclosed data alone; consider your wider exposure history and personal risk.
Best Value
Do you need to replace your computer?
The cited reporting describes customer and purchase information in a portal. It does not indicate that Dell computers, operating systems, or device firmware were compromised, so the incident alone is not evidence that you need to replace or reset your hardware.
Quick Recap
What remains unknown?
- The exact number of unique people affected by the first incident.
- Whether all of the 49 million records claimed by Menelik were genuine, current, or unique.
- The complete technical path used to access either portal.
- Whether the claimed dataset was publicly distributed.
- The final outcome of the Irish regulator’s assessment; the cited May 2024 report says it was assessing Dell’s notification.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




