HackingManufacturingRetail & ConsumerManufacturingStolen CredentialsCustomer Data InvolvedData ExfiltratedWire FraudPIIPCILowResolved
GENERAL MOTORS COMPANY
bd_8154a1b995a241a5 · schema v1 · pii pii-v1
Full breach record for GENERAL MOTORS COMPANY →Between May 18–20, 2024, unauthorized parties used previously compromised credentials from non-GM sites (credential stuffing) to access 65 GM MyAccounts on the GM accessories website, making fraudulent purchases. Exposed data included name, address, phone number, and last four digits of saved payment card. No GM-sourced credential breach was identified. GM forced password resets, implemented MFA, refunded fraudulent purchases, and notified law enforcement. Two Maine residents were affected.
Maine clockDiscovered May 24, 2024 → Filed with AG Jul 8, 202445d ⏱ ME AG >30d6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_1f566138bc47f4b0Indiana State AGfiled 2024-06-26(12d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/c4495163-2637-4aed-9d8e-cbc33731196e.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 8, 2024
- Raw hash
- 437033130abe410bcf8638927995bfac1a8aa94c2de970e6db8d5211f7e4d6b4
Reporting entity
- Name
- GENERAL MOTORS COMPANYnorm: general motors
- Domain
- gm.com
- Industry
- Other Commercial
Victim entity
- Name
- GENERAL MOTORS COMPANYnorm: general motors
- Domain
- gm.com
- Industry
- Other Commercial
- Industry
- ManufacturingllmRetail & Consumerllm
Incident
- Discovered
- May 24, 2024
- Materiality determined
- —
- Notification sent
- Jun 21, 2024
- Affected individuals
- 2
- Data types
- PIIPCI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1110 Brute Force
- Threat actor
- ExternalFinancial
- Regulator citations
- Notice filed with Maine Attorney General on June 21, 2024
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- ME AG >30d · 45d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 24, 2024→ Filed with AG: Jul 8, 202445d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.