2024 Carvana — credential-stuffing access to credit-status tool; ~1.8k consumers (NH AG letter)
Data compromised
Dates of birth and contact details per AG notification metadata
Technical writeup
Carvana told New Hampshire regulators that July 2024 suspicious activity involved credential stuffing into a credit-status application using third-party-recycled passwords, with 1,799 individuals referenced in the cited filing set and DOB/contact fields potentially viewed.
Root cause
Credential reuse attack against customer-facing account surfaces