AutoZone, Inc.
bd_0809502990bdba43 · schema v1 · pii pii-v1
Full breach record for AutoZone, Inc. →AutoZone, Inc. disclosed a data breach involving the exploitation of a vulnerability in the third-party MOVEit file transfer application. An unauthorized third party exfiltrated data from an AutoZone system. The incident was contained. Affected individuals may have had personal information, including potentially Social Security numbers and financial account details, compromised. AutoZone is offering credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
May 28, 2023
Begins
Nov 20, 2023
Filed
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitedispossessorbd_8e8b2610b911309a2024-04-19 · +151dVerified by operator
- Leak Sitecl0pbd_194dee6c6b6f32a02023-07-07 · +136dVerified by operator
Regulatory filings (7) · sorted by filing gap
- Montana State AGbd_367ded5d15c02eb12023-11-20Verified
- Maine State AGbd_547d20145f6a4aa82023-11-20Verified
- Vermont State AGbd_2e82b08f0d975f282023-11-21 · +1dVerified
- Massachusetts State AGbd_6ec1d040bec779f62023-11-21 · +1dVerified
Show 3 more filings ↓Show fewer ↑up to 323d gap
- Oregon State AGbd_e2dcaa9f4f49c3c52023-11-21 · +1dVerified
- Washington State AGbd_a895d70c2f1e3c602023-11-22 · +2dVerified
- Illinois State AGbd_959f6ace42ee32a42023-01-01 · +323dCandidate
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Nov 22 (WA) — a 325-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.