700Credit·Financial services·
Consumer personal information was exposed through the breach.
700Credit disclosed unauthorized copying of consumer records through a compromised third-party API linked to its web application. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- Incident occurred
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Reported cause: API failed to validate consumer reference IDs against the original requester
- Consequence
- Reported: Consumer personal information was exposed through the breach.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- 700Credit
- Industry
- Financial services
- Disclosed
- Event date
- Third party
- 700Credit integration partner
- Affected asset
- 700Credit web application and API
- Country
- US
- Data involved
- Personal data
- Reported impact
- Data exposure
- Attached evidence
- 3 independent domains · 3 sources
2)Evidence-backed incident path
- 01
Reported cause
API failed to validate consumer reference IDs against the original requester
ConfidenceSecondaryExact excerpt
E1“a failure to validate consumer reference IDs against the original requester”
bleepingcomputer.com · Dec 15 - 02
Third party
700Credit integration partner
ConfidenceSecondaryExact excerpt
E2“one of 700Credit's integration partners in July”
bleepingcomputer.com · Dec 15 - 03
Reached
700Credit web application and API
ConfidenceSecondaryExact excerpt
E3“involved a compromised third-party API linked to the 700Credit web application”
securityweek.com · Dec 15 - 04
Observed
Consumer personal information was exposed through the breach.
ConfidenceProbableExact excerpt
E4“their personal information has been exposed in a data breach incident”
bleepingcomputer.com · Dec 15
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- That a Defence review would have prevented this incident
4)Relevance to your product
Third-party access can inherit more reach than the product team intended.
This pattern applies when…
- Products whose APIs accept record identifiers from clients or partners.
Diagnostic questions
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
This incident does not establish your product's risk.
5)Sector context — Financial services
- 2 incident threads
- 0 incident threads
- 1 incident threads
- 4 incident threads
- 7 incident threads
- 10 incident threads
- 4 incident threads
- 10 incident threads
- 7 incident threads
- 7 incident threads
- 5 incident threads
- 8 incident threads
- Same incident family
- 12 Supply chain / third party
- Confirmed share
- 23% 15 confirmed · 50 reported
- Display family
- Supply chain Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Financial services in Radar →6)Defence control mapping
What Defence can test
Third-party integration review
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
7)Public evidence ledger
3 attached sources across 3 independent domains. No attached source is marked as an organization or regulator primary source.
- E1, E2, E4bleepingcomputer.com700Credit data breach impacts 5.8 million vehicle dealership customersSpecialist reporting · Dec 15 · CitedSpecialist reportingCited
Exact excerpt
“the company filed with the Federal Trade Commission (FTC) a breach notification”
- E3securityweek.com700Credit Data Breach Impacts 5.8 Million IndividualsEstablished press · Dec 15 · CitedEstablished pressCited
Exact excerpt
“names, addresses, dates of birth, and Social Security numbers”
Does this integration boundary exist in your product?
A bounded review can test the authorized web/API path without assuming this incident predicts your risk.