CARVANA CO.
bd_a2d5f6d907d31acd · schema v1 · pii pii-v1
Full breach record for CARVANA CO. →4 incidents on fileCarvana Co. notified the NH Attorney General of a security incident where an unauthorized party used credentials obtained from another source to access user accounts. On July 5, 2024, Carvana discovered suspicious activity and reset passwords. Investigation revealed potential access to a credit status system for 1,799 individuals, including 3 New Hampshire residents. Data involved included usernames, passwords, dates of birth, and contact information. Carvana engaged forensic experts, notified law enforcement, and offered identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 5, 2024
Begins
Jul 5, 2024
Discovered
Sep 12, 2024
Filed
vs. sector median
+2 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_8c50c9e8458efb8b2024-09-12Candidate
- Maine State AGbd_8e12cdda170d6c5a2024-09-12Verified
- Indiana State AGbd_a14d3886e53edc202024-09-12Verified
- Massachusetts State AGbd_698cee77c1a257342024-09-13 · +1dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.