FEDERALItem 8.01 · voluntaryHackingSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIFINANCIALLowActive
SONIC AUTOMOTIVE, INC.
bd_2af1db1ca1aea898 · schema v1 · pii pii-v1
Full breach record for SONIC AUTOMOTIVE, INC. →Sonic Automotive, Inc. filed an 8-K on June 21, 2024, reporting a cybersecurity incident involving third-party provider CDK Global. On June 19, 2024, CDK notified customers of a cybersecurity incident that resulted in the suspension of systems used by Sonic, including its dealer management system (DMS) and customer relationship management (CRM) system. Sonic took precautionary containment steps and commenced an investigation. The full scope and impact, including whether customer data was accessed, are not yet known. The incident is ongoing.
SEC clockMateriality determined Jun 21, 2024 → Filed Jun 21, 20240d ✓ SEC 4-day OK2 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1043509/000104350924000059/sah-20240619.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 21, 2024
- Raw hash
- 7fbb838efd4b8915605def257311dca0970d390e8aabfd9a4345b566a326c489
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- SONIC AUTOMOTIVE, INC.norm: sonic automotive
- SEC CIK
- 0001043509
- Domain
- sonicautomotive.com
Victim entity
- Name
- SONIC AUTOMOTIVE, INC.norm: sonic automotive
- SEC CIK
- 0001043509
- Domain
- sonicautomotive.com
Incident
- Discovered
- Jun 19, 2024
- Materiality determined
- Jun 21, 2024
- Notification sent
- Jun 21, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via CDK Global
- Initial access
- supply_chain
Compliance
- Time to disclose
- 2 days(2 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jun 21, 2024→ Filed: Jun 21, 20240d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.