HackingVulnerability ExploitCapture Stored DataData ExfiltratedTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
AutoZone, Inc.
bd_2e82b08f0d975f28 · schema v1 · pii pii-v1
Full breach record for AutoZone, Inc. →AutoZone, Inc. notified Vermont consumers of a data breach involving the MOVEit file transfer application. An unauthorized third party exploited a vulnerability in MOVEit on or about August 15, 2023, to exfiltrate personal information. AutoZone contained the incident, disabled the application, rebuilt the system, and patched the vulnerability. Affected individuals were offered credit monitoring services.
Vermont clock✗ VT AG >45 bday14 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 137 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_0809502990bdba43California State AGfiled 2023-11-20(1d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-11-21-autozone-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2023
- Raw hash
- 4ad8a7c1987c43c3aed448554d0c487c7ee99abd17f8442f2ad1957cb401a583
Reporting entity
- Name
- AutoZone, Inc.norm: autozone
- Domain
- autozone.com
Victim entity
- Name
- AutoZone, Inc.norm: autozone
- Domain
- autozone.com
Incident
- Discovered
- Aug 15, 2023
- Materiality determined
- —
- Notification sent
- Nov 21, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 weeks(98 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.