DisclosureLens
FEDERALItem 1.05 · mandatoryThird-Party / Supply ChainRetail & ConsumerRetailSupply Chain (3P Vendor)LowActive

Sonic Automotive, Inc.

bd_36e25d22f9c4d664 · schema v1 · pii pii-v1

Severity

Low

Discovered

—

Filed

Jul 5, 2024

To disclose

—

Affected

Not disclosed

Confidence

67%
Full breach record for Sonic Automotive, Inc. →3 incidents on file

Sonic Automotive, Inc. reported disruptions to its dealer management and CRM systems since June 19, 2024, caused by a cybersecurity incident at its third-party provider, CDK Global. The filing is a supplemental Item 1.05 disclosure updating a June 21, 2024 report. Basic DMS functionality has been restored, but other systems remain offline. The Company determined the incident is reasonably likely to have a material impact on Q2 2024 results due to slower vehicle sales. No specific data types affected or individual counts were disclosed.

Incident timeline

Jun 19, 2024

Begins

Jul 5, 2024

Filed

Part of CDK GLOBAL II LLC supply-chain incident (2024) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.