FEDERALItem 1.05 · mandatoryThird-Party / Supply ChainRetail & ConsumerRetailSupply Chain (3P Vendor)Downstream VictimsLowActive
SONIC AUTOMOTIVE, INC.
bd_36e25d22f9c4d664 · schema v1 · pii pii-v1
Full breach record for SONIC AUTOMOTIVE, INC. →Sonic Automotive disclosed under Item 1.05 that disruptions to its CDK Global-provided dealer management system, CRM and other sales/inventory/accounting systems began June 19, 2024 from a cybersecurity incident at CDK. Basic DMS functionality has been restored; CRM and other systems remain offline. The Company concluded the incident is reasonably likely to have a material impact on Q2 2024 results due to slower vehicle sales. Full scope and restoration timing remain unclear.
SEC clockMateriality determined Jul 5, 2024 → Filed Jul 5, 20240d ✓ SEC 4-day OK16 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1043509/000104350924000060/sah-20240705.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 5, 2024
- Raw hash
- 064814894cbbebf56e053758eaec140bc36b2c39c6048fbad867435214d9e46b
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- SONIC AUTOMOTIVE, INC.norm: sonic automotive
- SEC CIK
- 0001043509
- Domain
- sonicautomotive.com
Victim entity
- Name
- SONIC AUTOMOTIVE, INC.norm: sonic automotive
- SEC CIK
- 0001043509
- Domain
- sonicautomotive.com
- Industry
- Automotive Retail
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Jun 19, 2024
- Materiality determined
- Jul 5, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- —
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Filed Form 8-K under Item 1.05 with the SEC (initial filing June 21, 2024; supplemental July 5, 2024)
- Third party
- via CDK Global
- Initial access
- supply_chain
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jul 5, 2024→ Filed: Jul 5, 20240d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.