Unverified forum listing — May 2026: A threat actor listed roughly 130,000 Mercedes-Benz customer and vehicle records for sale on an underground marketplace. Cybernews verified sample fields including UK phone numbers, postcodes, car models, and registration numbers. Mercedes-Benz UK told Cybernews the dataset is linked to a previously investigated external UK dealership incident, has been altered, and does not indicate a current Mercedes-Benz systems breach.
What the listing claims
The seller advertised Excel/CSV data with:
- Customer names, UK addresses, postcodes, mobile numbers, emails
- Vehicle numbers, Mercedes model identifiers, registration numbers and dates
- MOT due dates, last service dates, order/quote status
Cybernews confirmed ten sample records with plausible UK formatting. If authentic, the data likely originated from a UK dealership or service channel rather than Mercedes-Benz Group central systems—but Mercedes has not confirmed the listing's accuracy.
Mercedes-Benz UK response
Mercedes-Benz UK stated it is aware of the forum claims, that the data relates to a previously known external dealership incident thoroughly investigated at the time, that the advertised dataset has been altered and is unreliable, and that protecting customer data remains a priority. There is no official confirmation of a new 130,000-person breach at indexing time.
Risks for UK Mercedes owners
Vehicle ownership data enables targeted phishing (fake MOT/recall notices), VIN-cloning fraud, and—in extreme cases—physical theft targeting high-value models when registration data maps to addresses.
What to do
- Do not buy or download alleged leak archives.
- Verify MOT, service, and financing messages through official Mercedes-Benz or authorized dealer channels only.
- Report suspicious contact citing your registration or model details to Action Fraud (UK) and Mercedes customer support.
Canonical record: Mercedes-Benz UK forum listing 2026 on BreachHistory.
Source: Cybernews