HackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
AUTOMOBILE CLUB OF SOUTHERN CALIFORNIA
bd_0a26f8a7e3b065f1 · schema v1 · pii pii-v1
Full breach record for AUTOMOBILE CLUB OF SOUTHERN CALIFORNIA →Automobile Club of Southern California (ACSC) notified members of a security incident involving third-party vendor DanubeNet, Inc. (Driving School Solutions). Unauthorized access to vendor systems occurred between July 10, 2025, and August 19, 2025. ACSC became aware of the incident on December 22, 2025. Affected data included names and driver's permit/license numbers. ACSC offered one year of credit monitoring and identity protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-619858
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 1, 2026
- Raw hash
- 2b12a11c04d461f94ad3cec85dd9fa40a775f888745f54374233a93d57086bf9
Reporting entity
- Name
- AUTOMOBILE CLUB OF SOUTHERN CALIFORNIAnorm: automobile club of southern california
Victim entity
- Name
- AUTOMOBILE CLUB OF SOUTHERN CALIFORNIAnorm: automobile club of southern california
Incident
- Discovered
- Dec 22, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via DanubeNet, Inc. aka Driving School Solutions
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 days(10 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.