TL;DR: 700Credit, a Michigan company that runs credit checks for nearly 18,000 auto dealerships, got hacked. Attackers exploited a third-party API from July to October 2025, copying names, addresses, dates of birth, and Social Security numbers for 5.8 million people. If you've financed a car in the last few years, your data was likely in their system. 700Credit didn't notify affected people until December 2025. Lawsuits are already piling up.

What Happened

In July 2025, hackers compromised one of 700Credit's third-party integration partners [1]. That gave them access to an API connected to 700Dealer.com, the web application dealerships use to pull credit reports on customers.

For the next three months, attackers copied consumer records. Bulk extraction. High volume. Nobody noticed until October 25, 2025 [2].

What was stolen:

  • Full names
  • Mailing addresses
  • Dates of birth
  • Social Security numbers

That's everything you need for identity theft. All in one database. Copied over months.

Timeline of Failure

  • July 2025: Third-party integration partner compromised
  • July - October 2025: Hackers copy consumer records undetected
  • October 25, 2025: 700Credit detects "suspicious activity"
  • October 27, 2025: Intrusion finally stopped
  • November 21, 2025: Dealerships notified
  • December 2, 2025: FTC notified
  • December 12, 2025: TechCrunch reports the breach publicly [3]
  • December 22, 2025: Letters to affected individuals begin
  • January 2, 2026: South Carolina reports 108,000+ state residents affected [4]

Three months of data theft. One month to tell dealerships. Another month to tell you.

Who Is 700Credit?

You've probably never heard of them. That's the point.

700Credit is a Michigan-based company that provides credit reports and identity verification to auto dealerships. When you walk into a dealership and apply for financing, they often pull your credit through 700Credit's system.

The scale:

  • Nearly 18,000 dealership clients
  • 5.8 million consumers affected by this breach
  • Data goes back to at least May 2025

You never signed up for 700Credit. You never agreed to their privacy policy. The dealership ran your credit, and 700Credit got your data. Now hackers have it too.

Why This Is Worse Than A Typical Breach

Credit check companies collect the exact data criminals need. This isn't an email address and password leak. This is your SSN, date of birth, full name, and address, together.

What criminals can do with this data:

  • Open new credit cards in your name
  • Take out loans
  • File fraudulent tax returns
  • Create synthetic identities mixing your real data with fake details
  • Apply for government benefits

Your SSN doesn't change. Your date of birth doesn't change. Once stolen, this data is compromised forever.

700Credit's Response

700Credit says its "internal network remained secure" and only the web application was compromised [2]. That's PR speak. The web application is where the customer data was. That's what got hit.

What they're offering:

  • 12 months of credit monitoring
  • Identity restoration services
  • A notice in the mail (if you're one of the 5.8 million)

Michigan Attorney General Dana Nessel warned residents: "If you get a letter from 700Credit, don't ignore it" [5]. She recommended credit freezes for anyone affected.

The Lawsuits Are Coming

Class action attorneys are already circling. Bloomberg Law reported lawsuits alleging negligence and increased risk of identity theft [6].

The claims: 700Credit failed to secure consumer data, failed to detect the breach for months, and failed to notify people fast enough.

Whether any of these lawsuits succeed won't change the fact that 5.8 million Social Security numbers are now in criminal hands.

What You Should Do Now

If you've financed a car recently: Assume your data may be in this breach. Don't wait for a letter.

Freeze your credit, all three bureaus:

A credit freeze prevents anyone from opening new accounts in your name. You can temporarily lift it when you need to apply for credit. This is free. Do it now.

Monitor for tax fraud:

  • File your taxes early to beat fraudsters
  • Set up an IRS Identity Protection PIN at irs.gov
  • Watch for IRS letters about returns you didn't file

Check your Social Security account:

  • Create an account at ssa.gov if you don't have one
  • Review your earnings record for suspicious activity
  • Someone using your SSN for employment shows up here

If you receive the 700Credit letter:

  • Sign up for their credit monitoring (it's the minimum they owe you)
  • Still freeze your credit separately, monitoring doesn't prevent fraud
  • Document everything for potential future legal action

The Bigger Picture

This breach happened because of how the data broker ecosystem works. You go to a car dealership. The dealership uses a third-party credit service. That service has third-party integration partners. One partner gets compromised. Your SSN gets stolen.

You never had a relationship with 700Credit. You never chose them. But they had your most sensitive information, and they couldn't protect it.

There's no way to opt out of this system if you want to finance a car. There's no way to know which back-end services the dealership uses. You're forced to trust companies you've never heard of with data that can ruin your financial life.

That's the surveillance economy. You're not the customer. You're the product. And when the product leaks, you pay the price.

References

  1. Bright Defense, 700Credit Breach: How Did Millions of SSNs Leak? (January 2026)
  2. SecurityWeek, 700Credit Data Breach Impacts 5.8 Million Individuals (December 2025)
  3. TechCrunch, Data breach at credit check giant 700Credit affects at least 5.6 million (December 2025)
  4. CyberNews, 700Credit breach raises alarms over 5.8 million Americans' sensitive auto financing data (January 2026)
  5. Fox News, 700Credit data breach exposes 5.8 million people's Social Security numbers (January 2026)
  6. Automotive News, 700Credit data breach affects 18,000 dealerships, 5.6 million customers (December 2025)