FEDERALItem 8.01 · voluntaryHackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICLowActive
GARRETT MOTION INC.
bd_c4fd29297f92fc17 · schema v1 · pii pii-v1
Full breach record for GARRETT MOTION INC. →Garrett Motion Inc. disclosed a cybersecurity incident stemming from a supply-chain compromise of its vendor, Progress Software Corporation's MOVEit file transfer software. On July 28, 2023, Garrett learned that an unauthorized party accessed certain data belonging to the Company, its employees, and customers prior to a vendor patch being applied. Garrett engaged third-party cybersecurity experts and notified law enforcement. The Company stated it believed the incident would have no material adverse effect on its business.
SEC clockMateriality determined Aug 2, 2023 → Filed Aug 2, 20230d ✓ SEC 4-day OK5 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1735707/000095014223002128/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Aug 2, 2023
- Raw hash
- 01e9deb9fe26e85d0797cc8b44bf4dac07c1220713dc07e93ea7e9c187ce844d
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- GARRETT MOTION INC.norm: garrett motion
- SEC CIK
- 0001735707
- Domain
- garrettmotion.com
Victim entity
- Name
- GARRETT MOTION INC.norm: garrett motion
- SEC CIK
- 0001735707
- Domain
- garrettmotion.com
Incident
- Discovered
- Jul 28, 2023
- Materiality determined
- Aug 2, 2023
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- notified law enforcement
- Initial access
- supply_chain
Compliance
- Time to disclose
- 5 days(5 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Aug 2, 2023→ Filed: Aug 2, 20230d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.