A threat actor claims to have breached RevolutionParts, an e-commerce platform for automotive dealerships, manufacturers, and parts sellers. The actor listed a database allegedly belonging to RevolutionParts for sale on a cybercrime forum in November 2025. The actor claims the breach impacts 5.1 million unique customers.
The compromised database allegedly contains extensive Personally Identifiable Information (PII), including full names, email addresses, phone numbers, physical addresses (street, city, state, zip code), IP addresses, and device information (device OS, model, brand). The company has not publicly confirmed these claims, and the full extent of the breach remains unclear.
More details may emerge as investigations continue, and official notices may be delayed.