FEDERALItem 8.01 · voluntaryHackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTPIICriticalActive
Advance Auto Parts, Inc.
bd_5d35e57adff28295 · schema v1 · pii pii-v1
Full breach record for Advance Auto Parts, Inc. →Advance Auto Parts, Inc. disclosed a cybersecurity incident on May 23, 2024, involving unauthorized access to a third-party cloud database. A criminal threat actor attempted to sell data on June 4, 2024. The breach impacted personal information, including SSNs and government IDs, of current and former employees and job applicants. The company incurred approximately $3 million in response costs and offered credit monitoring services.
SEC clockMateriality determined Jun 14, 2024 → Filed Jun 14, 20240d ✓ SEC 4-day OK22 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1158449/000115844924000162/aap-20240523.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 14, 2024
- Raw hash
- f87d9a7394735617858085028b396ae75ddb55fbd9804831caa681aa33d92b7b
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Advance Auto Parts, Inc.norm: advance auto parts
- SEC CIK
- 0001158449
Victim entity
- Name
- Advance Auto Parts, Inc.norm: advance auto parts
- SEC CIK
- 0001158449
Incident
- Discovered
- May 23, 2024
- Materiality determined
- Jun 14, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jun 14, 2024→ Filed: Jun 14, 20240d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.