We wish to inform customers of a data breach incident that occurred with our third-party supplier, Absolute Results. Absolute Results is a marketing agency used by the automotive retailing industry across North America, UK, Europe and Australia.
Our dealership was recently contacted by Absolute Results in relation to a cybersecurity incident. Absolute Results’ investigation found an unauthorised party accessed its on-premise server environment, spread malware, and accessed and copied certain files. Their investigation did not determine exactly which files were impacted, however as our dealership has used Absolute Results’ services, we wish to inform our sales and service customers that they may be impacted by this incident.
The types of personal information potentially impacted include, name, address, email address, phone number, vehicle description, VIN, sale date and last service date.
We do not consider there to be an immediate risk of harm, but cybercriminals are known to use personal information for phishing attacks or social engineering to trick you into giving them more of your information. To minimise these risks, we recommend that you change your email account password to a strong passphrase you have not used before and enable multi-factor authentication where possible. Do not open attachments or click on links in emails or social media messages if you are unsure if the sender is genuine. Take care on phone calls by not sharing your personal information until you are certain who you are speaking with.
For help on how to identify a scam and protect yourself go to www.scamwatch.gov.au or www.cyber.gov.au/acsc/individuals-and-families. If you believe that there has been any recent unknown activity or unexpected adverse impact on your credit history, you can contact any of the following organisations to obtain a credit history report:
illion Australia - https://www.creditcheck.illion.com.au/ 1300 734 806
Experian Australia - https://www.experian.com.au/order-credit-report
Equifax - https://www.equifax.com.au/personal/products 138 332
We take your privacy very seriously. Our business maintains a Data Breach Response Plan and Privacy Policy that is regularly reviewed. Our Privacy Policy is located at https://autosportsgroup.com.au/privacy/. We are reviewing our procedures on how we work with suppliers to minimise the likelihood of any similar occurrences in future. Similarly, Absolute Results has taken action to secure its environment and implement strict data deletion protocols. This incident was reported by us to the Office of the Australian Information Commissioner (OAIC).
Unfortunately, cybercrime is a regular occurrence impacting businesses and individuals globally. Whilst we are disappointed that this data breach has occurred, we believe that being open and transparent and working hand in hand with our customers and suppliers maintains trust as we work together to combat cybercrime.
If you have any questions or concerns, please don’t hesitate to contact us at privacy@autosportsgroup.com.au
Notification of data breach - Dealer Drive
Mercedes-Benz Toowong informs customers of a data breach incident that occurred in early 2018 regarding unauthorised access to personal information stored with our third-party software provider, Dealer Drive. Dealer Drive is a software program for recording the details of customers that take test drives and use service loan cars.
Our dealership was recently contacted by the Australian Federal Police (AFP) in regards to a current cyber-crime investigation which has identified a historical data breach relating to customer information held in our Dealer Drive account in early 2018. Our dealership was informed that a limited number of driver’s licence images were obtained during the AFP’s investigation. It is believed that unauthorised access was gained through a ‘phishing’ email in early 2018.
The types of personal information held in the Dealer Drive platform include driver’s licences, contact phone numbers, email addresses, test drive details and signatures.
If you test drove a vehicle at Mercedes-Benz Toowong or had the use of a courtesy vehicle in early 2018, your personal data may be impacted.
We strongly recommend that you take the following steps to help protect your identity and to mitigate the impacts of potential identity fraud:
1. Contact any or all of the following credit bureaus to obtain a current credit report to ascertain if there has been any recent unknown activity or unexpected adverse impact on your credit history:
illion Australia - https://www.creditcheck.illion.com.au/
Experian Australia - https://www.experian.com.au/order-credit-report
Equifax - https://www.equifax.com.au/personal/products
If you have identified any recent unknown activity or unexpected adverse impact on your credit history then contact the Department of Transport and Mains Roads on 13 23 80 or via other methods available on their website to request the cancellation and re-issue of your driver’s licence https://www.tmr.qld.gov.au/About-us/Contact-us
Mercedes-Benz Toowong takes your privacy very seriously. Our business maintains a Data Breach Response Plan and Privacy Policy that is regularly reviewed. Our Privacy Policy is located at https://autosportsgroup.com.au/privacy/. Our staff also receive training in relation to the Australian Privacy Principles, data breaches and cybersecurity.
Unfortunately, cybercrime is a regular occurrence impacting Australian businesses and individuals alike. Whilst we are disappointed that this data breach has occurred, we believe that being open and transparent and working hand in hand with our customers and suppliers maintains trust and provides a united front in the fight against cybercrime.
We are working with Dealer Drive in a collaborative manner to work through how the breach occurred and how we can minimise the likelihood of any similar occurrences in future. This incident will also be reported to Office of the Australian Information Commissioner (OAIC).
If you have any questions or concerns, please don’t hesitate to contact us at privacy@autosportsgroup.com.au