← Carvana

2024 Carvana — credential-stuffing access to credit-status tool; ~1.8k consumers (NH AG letter)

2024 1.8K records affected Share on X

Data compromised

Dates of birth and contact details per AG notification metadata

Technical writeup

Carvana told New Hampshire regulators that July 2024 suspicious activity involved credential stuffing into a credit-status application using third-party-recycled passwords, with 1,799 individuals referenced in the cited filing set and DOB/contact fields potentially viewed.

Root cause

Credential reuse attack against customer-facing account surfaces

References