HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Icahn Automotive Group LLC
bd_6bab6b4aa3f8df81 · schema v1 · pii pii-v1
Full breach record for Icahn Automotive Group LLC →Icahn Automotive Group LLC reported a data breach affecting California residents. An unauthorized actor gained access to an employee's email account between March 13, 2020, and April 4, 2020. The compromised account contained employee personal information, including names, SSNs, driver's license numbers, and financial account numbers. The company blocked access, engaged forensic investigators, and offered 12 months of identity monitoring via Kroll. No evidence was found that the data was used or disseminated.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190396
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 27, 2020
- Raw hash
- 10f2dc4f59584c661fa96b2f806a13de424b6dbd4dab16fc1b0cb5dbfc30a98c
Reporting entity
- Name
- Icahn Automotive Group LLCnorm: icahn automotive
Victim entity
- Name
- Icahn Automotive Group LLCnorm: icahn automotive
Incident
- Discovered
- Apr 6, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.