HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLOCATIONBEHAVIORMediumContained
GENERAL MOTORS COMPANY
bd_256b6e3ce41b7f70 · schema v1 · pii pii-v1
Full breach record for GENERAL MOTORS COMPANY →General Motors Company notified the California Attorney General of a data incident affecting 4,920 California residents. Between April 11 and April 29, 2022, unauthorized parties used credentials previously compromised on other sites to access GM online accounts. Affected data included names, emails, addresses, phone numbers, location data, and search history. GM suspended gift card redemptions, forced password resets, and reported the incident to law enforcement.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_ca2e78a3ee421e54Maine State AGfiled 2022-05-11(5d gap)Verified
- bd_d5ca7a50f8cdb0bfMaine State AGfiled 2022-05-10(6d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-553442
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 16, 2022
- Raw hash
- e9f161cd0316244fee504ca2e089d37415ea948bba5ab454a440bee8cda212f4
Reporting entity
- Name
- GENERAL MOTORS COMPANYnorm: general motors
- Domain
- gm.com
Victim entity
- Name
- GENERAL MOTORS COMPANYnorm: general motors
- Domain
- gm.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- May 16, 2022
- Affected individuals
- 4,920
- Data types
- IDENTITY_BASICCREDENTIALSLOCATIONBEHAVIOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the activity to law enforcement
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.