AutoNation, Inc.
bd_c158c2a75bf30f3e · schema v1 · pii pii-v1
Full breach record for AutoNation, Inc. →4 incidents on fileCrossCheck, Inc. reported a cybersecurity incident affecting AutoNation, Inc. customers. Between May 18-20, 2024, an unauthorized actor accessed CrossCheck's merchant portal, potentially exposing names, driver's license numbers, and financial account information of 299 Maryland residents. CrossCheck notified federal law enforcement, provided 12 months of credit monitoring via Experian, and implemented additional employee safeguards. Notification to the Maryland Attorney General was filed on March 4, 2025.
J jump to incidentP pin to compareR raw source
Incident timeline
May 18, 2024
Begins
May 20, 2024
Discovered
Mar 4, 2025
Filed
vs. sector median
+34 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Nebraska State AGbd_11c3ad79193326872025-03-04Verified
- Maine State AGbd_bcb09ac65f4f2fcb2025-03-04Verified
- Montana State AGbd_02c1dec26ae275ca2024-12-19 · +75dCandidate
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Dec 19 (MT), last Mar 4 (MD) — a 75-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.