HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
AUTOMOBILE CLUB OF SOUTHERN CALIFORNIA
bd_5a1121510021516c · schema v1 · pii pii-v1
Full breach record for AUTOMOBILE CLUB OF SOUTHERN CALIFORNIA →Automobile Club of Southern California (ACSC) notified the New Hampshire Attorney General of a security incident involving its vendor, DanubeNet, Inc. (DSS). Unauthorized access to DSS systems occurred between July 10, 2025, and August 19, 2025. ACSC determined on January 16, 2026, that member data was involved, specifically identifying records for three New Hampshire residents containing names and driver's permit/license numbers. ACSC mailed notifications on March 9, 2026, and offered one year of identity protection services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0fd715fce2ab9f8dIndiana State AGfiled 2026-03-09Candidate
- bd_74b21c973de3198bCalifornia State AGfiled 2026-05-08(60d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/automobile-club-southern-california-20260309.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 9, 2026
- Raw hash
- 61e7fd60b0e04aaf3f5e392d8d2f6aaeca768ac331ee348c11a2fc3319fb74d3
Reporting entity
- Name
- AUTOMOBILE CLUB OF SOUTHERN CALIFORNIAnorm: automobile club of southern california
Victim entity
- Name
- AUTOMOBILE CLUB OF SOUTHERN CALIFORNIAnorm: automobile club of southern california
Incident
- Discovered
- Jan 16, 2026
- Materiality determined
- —
- Notification sent
- Mar 9, 2026
- Affected individuals
- 3
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Third party
- via DanubeNet, Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.