HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
AutoZone, Inc.
bd_0809502990bdba43 · schema v1 · pii pii-v1
Full breach record for AutoZone, Inc. →AutoZone, Inc. disclosed a data breach involving the exploitation of a vulnerability in the third-party MOVEit file transfer application. An unauthorized third party exfiltrated data from an AutoZone system. The incident was contained. Affected individuals may have had personal information, including potentially Social Security numbers and financial account details, compromised. AutoZone is offering credit monitoring services.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_2e82b08f0d975f28Vermont State AGfiled 2023-11-21(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576800
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 20, 2023
- Raw hash
- a85de6bf8413b508189ad18f6a6d0f1edbdfa05893751aaf9ad405b268d9f212
Reporting entity
- Name
- AutoZone, Inc.norm: autozone
- Domain
- autozone.com
Victim entity
- Name
- AutoZone, Inc.norm: autozone
- Domain
- autozone.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software (MOVEit)
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.