Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Breach - Stellantis Confirms Customer Data Breach in North America
Data Breach Attacks Critical Infrastructure Security Data Protection Latest News News & Analysis Security

Stellantis Confirms Customer Data Breach in North America

Kirsten DoyleBy Kirsten DoyleSeptember 23, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Stellantis Data Breach
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Stellantis, the parent of Citroën, FIAT, Jeep, Chrysler, and Peugeot, has confirmed a data breach affecting customers in North America. 

The company said on Sunday it detected unauthorized access through a third-party service provider that supports its customer service operations. Stellantis did not disclose how many people were affected. 

The compromised data included customer names, addresses, phone numbers, and email addresses. Stellantis stressed that no financial details or other sensitive personal information were exposed. 

“Upon discovery, we immediately activated our incident response protocols … and are directly informing affected customers,” the company told Reuters. Federal authorities have been notified. 

Stellantis urged customers to stay alert for phishing attempts, warning them not to click suspicious links or share personal information in response to unexpected or urgent requests. 

A Pattern in the Industry 

The incident isn’t the first in this industry.  Jaguar Land Rover was forced to halt UK factory operations earlier this month after a cyber incident.  

The breach is part of a broader trend. Large organizations are becoming prime targets as they rely more on third-party vendors and complex digital systems.  

Every partner with access to customer data can be a weak point. In recent months, we’ve seen attacks against leading brands including Marks & Spencer, The Co-op, Adidas, Christian Dior, and many more.  

Global companies face a rising tide of cyber and ransomware attacks. Sophisticated threat actors are disrupting operations and stealing sensitive data across industries, from healthcare and finance to retail and regulators. 

A Blind Spot 

Anders Askasen, Director of Product at Radiant Logic, says cyber incidents tied to third-party providers are unfortunately a blind spot that could cause CISOs to have sleepless nights. They also highlight the fact that identity security doesn’t stop at the perimeter.  

“Attackers can weaponize leaked and compromised identity data for phishing and social engineering attacks that open the door to larger breaches,” Askasen adds. “The automotive industry has a norm of a sprawling ecosystem of suppliers and contractors and not having the unified visibility and control creates systemic exposure.” 

He says global initiatives such as the EU’s NIS2 Directive put a sharp focus on third-party and supply chain risk, making continuous monitoring of identity security posture a compliance requirement. “Meeting this standard demands a data-centric approach that unifies identity intelligence across suppliers and contractors, giving enterprises the observability to detect, contain, and minimize risk. Organizations that apply the same rigor to third-party identities as they do internal ones will be far better prepared to withstand inevitable attacks.”  

The Common Thread 

Javvad Malik, Lead CISO Advisor at KnowBe4, comments: “The common thread in most of these recent attacks across various industries is the fact that supply chains are often compromised to gain access to systems.  

Criminals often target a smaller partner with weaker defences with social engineering being a common tactic. This includes convincing emails, messages, or calls, which can be powered by AI and deepfake technology to trick people into sharing access or approving actions they shouldn’t.  

“The approach to be taken is full human risk management which includes the use of technology and clear training, simple processes, and easy ways for people to ask for help so they can make safer choices in the moment,” he adds. 

“Incident response must cover more than the technical fix. It includes the need to communicate quickly and clearly with customers and stakeholders about what happened, what it means for them, and exactly what steps they should take.”  

A Proactive, Layered Approach 

Jamie Akhtar, CEO and Co-founder at CyberSmart add that this news follows similar recent data breaches and shows that these kinds of attacks aren’t going anywhere. “It seems that unauthorized access was gained through a third-party provider. Although Stellantis haven’t disclosed how many customers are involved, it has been confirmed that the compromised data includes customer names, addresses, phone numbers and emails.” 

Organizations can stay safe going forward by adopting a proactive, layered security approach that goes beyond compliance, Akhtar says. “This means implementing robust access controls, strong data encryption, and multi-factor authentication to protect sensitive information. Regular employee training helps reduce human error and phishing risks, while continuous monitoring, logging, and threat detection of their own systems and third-party systems enable faster response to suspicious activity.”  

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw
  • Kirsten Doyle
    CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet
  • Kirsten Doyle
    Threat Actors Deploy Tiflux RMM for Persistent Remote Access

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

7-Eleven Notifies Franchise Applicants After Breach Exposes Personal Data

May 19, 20262 Mins Read

Canvas cyberattack disrupts universities as ShinyHunters threatens massive data leak

May 12, 20267 Mins Read

Zara Owner Inditex Confirms Customer Data Breach Affecting Nearly 200,000 People

May 11, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}