700Credit $17.5 Million Settlement Puts a September Deadline on Claims After 5.8 Million Car Buyers Were Exposed

The claim window on the 700Credit breach is measured in days, not quarters. Class members who want cash from the $17.5 million deal have until September 22, 2026, to file. The deadline to opt out or object is September 8. A federal judge in Michigan has the final-approval hearing on the calendar for October 7 at 2 p.m. The people inside that class handed a dealership a license and a Social Security number so they could finance a car, an RV, a boat, or an ATV. They did not hand those numbers to a stranger on a forum. The stranger got them anyway.
Oregon’s attorney general counted 5,836,521 affected consumers across roughly 18,000 U.S. dealerships. The platform was 700Dealer.com. The date 700Credit says it detected the incident is October 25, 2025. Names, dates of birth, Social Security numbers, and other identifiers sat behind an application programming interface that did not check whether a requested file belonged to the dealer who was asking. That is not ransomware folklore. That is a missing ID check. (700Credit settlement site)
A partner key and a velocity attack
Attackers first hit a small third-party shop that handled finance work for independent dealers and talked to 700Credit every day. They read that vendor’s logs, stole API credentials and a decryption key, and impersonated a real client. The partner did not warn 700Credit.
Ken Hill, 700Credit’s managing director, later said the sentence the industry did not want on tape: “We weren’t validating the consumer reference IDs to the original requestor.” Anyone holding stolen partner keys could throw guessed IDs at the API and pull files that belonged to some other lot. On October 25 the crew ran a velocity attack for about 90 minutes before 700Credit killed the integration. Hill said they scraped about 20 percent of the consumer records collected between May and October. (American Banker)
No one had to plant malware on the internal network. The damage was the application layer plus a partner that already held a legitimate decryption key. Social Security numbers left a credit shop without a smashed server.
ROOTBOY, a ransom argument, and a Michigan docket
Hill described “heated conversations” about paying the attackers. He would not confirm a payment and said the company was proceeding as if the data had been contained. On November 16, 2025, a handle calling itself ROOTBOY advertised about 8.4 million 700Credit records. Trusting the word of the person who attacked you is not a containment strategy. It is a hope.
The first class complaint landed November 24, 2025. On February 10, 2026, a judge in the Eastern District of Michigan consolidated the suits as In re 700 Credit Data Security Incident Litigation. Preliminary approval of a $17.5 million settlement followed in June. 700Credit admits no wrongdoing. The deal offers two cash tracks and credit monitoring. Details and the claim form live at 700creditdatabreachsettlement.com.
What the $17.5 million actually buys
Class members who got an email or postcard in July or August 2026 can choose reimbursement of documented ordinary losses up to $2,500, or an alternative cash payment of $50. Both figures can shrink if the claim pile is large. Eligible expenses described in settlement explainers include bank fees, postage, local travel tied to cleaning up the mess, and money already spent on credit reports, monitoring, or identity-theft products before the claim deadline. (Claim Depot, Top Class Actions)
Two years of credit monitoring is the automatic track. Activation codes went out with the notices. They do not work until the judge approves the settlement. Doing nothing still binds a class member to the release. Doing nothing also leaves the monitoring code on the table and the cash on the floor.
Seventeen million dollars divided by 5.8 million Social Security numbers is not a lottery ticket. It is a claims process. People who can document fraud get the higher cap, subject to pro rata cuts. People who cannot document a dollar of loss get the $50 option, also subject to cuts. That math is why the September 22 date is the only date that matters for anyone who intends to be paid.
Dealers got a paperwork courtesy. Buyers did not
Auto dealers are financial institutions under the FTC Safeguards Rule. A breach at a shared vendor would have forced thousands of duplicate filings. The National Automobile Dealers Association worked with 700Credit and the FTC on a consolidated notice so each lot would not file the same incident. Dealers still had to follow state consumer-notice laws. 700Credit mailed letters and offered Cyberscout monitoring in the first wave.
The federal courtesy did not end the pressure. The FTC sent warning letters to 97 dealerships in March 2026. Michigan Attorney General Dana Nessel, with about 160,000 residents in the blast radius, told people not to ignore the letter. South Carolina counted 108,829 residents. At least ten attorneys general received notice. A one-time pass on duplicate federal forms is not a finding that the lots ran a clean vendor program.
Anyone who applied for financing through a 700Credit dealer between May and October 2025 should treat the identifiers as exposed. Freeze credit at Equifax, Experian, and TransUnion. File the claim if the notice arrived. Assume a dark-web listing is not a rumor when the handle already advertised the file.
Vendor risk is the product
Car lots did not build 700Dealer.com. Buyers did not choose 700Credit. The finance office chose a pipeline, and the pipeline trusted a smaller partner, and the smaller partner kept logs and a key that turned into a skeleton key. That chain is the story The AEGIS Alliance keeps hitting on this beat. The Mixpanel incident that spilled Pornhub Premium account data is a different brand and the same geometry: the name on the homepage is only as strong as the analytics shop nobody has heard of. The Tricolor auto-lender collapse is the other half of the lot — the credit file and the loan tape living in the same neighborhood. The IRS-impostor remote-access wave is what happens after a Social Security number is already in circulation.
Hill’s quote about reference IDs is the part that should outlive the settlement PDF. Authentication that stops at “does this partner know the password” is not authentication of the customer. It is authentication of a stolen badge.
Dates that will not move
September 8, 2026: last day to opt out or object, postmarked. September 22, 2026: last day to submit a claim, online or postmarked. October 7, 2026, 2 p.m.: final approval hearing. No benefits pay out unless the court signs the deal. 700Credit still denies wrongdoing. ROOTBOY’s listing is not a court exhibit that has to be true in every row. It is a reminder that once a credit file is copied, the copy does not come back.
The AEGIS Alliance is not a claims mill. This rewrite exists because a six-million-person auto-finance breach is now a claims form with a short fuse, and because the hole that made it possible was a validation step that never ran. If a notice is in a junk folder from July or August, that is the ticket. If it is not, a credit freeze still is. The October hearing will decide whether $17.5 million is enough peace for the company. It will not put the reference IDs back inside the API.









