LKQ CORPORATION
bd_e09da3b67b0dfe83 · schema v1 · pii pii-v1
Full breach record for LKQ CORPORATION →3 incidents on fileLKQ Corporation notified Vermont AG of a cybersecurity event involving exploitation of previously unknown vulnerabilities in Oracle E-Business Suite. The incident was discovered in early October 2025. LKQ took systems offline and engaged forensic investigators. Impacted data included SSNs and EINs of sole proprietor suppliers. LKQ offered two years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 1, 2025
Begins
Oct 3, 2025
Discovered
Dec 15, 2025
Filed
vs. sector median
on median
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_ca963b548e29a5612025-10-27 · +49dVerified by operator
Regulatory filings (9) · sorted by filing gap
- Indiana State AGbd_0d24498ef978ea452025-12-15Verified
- Maine State AGbd_222597b2166e9a952025-12-15Verified
- Montana State AGbd_3b11067f5766d01d2025-12-15Verified
- New Hampshire State AGbd_6c3aa51f5e66e7ed2025-12-15Verified
Show 5 more filings ↓Show fewer ↑up to 14d gap
- Nebraska State AGbd_a883eb69b4b810b72025-12-15Verified
- California State AGbd_f78e0c2f9e23cbd92025-12-15Verified
- Massachusetts State AGbd_6b3dcc0a0ce73b642025-12-16 · +1dVerified
- Texas State AGbd_9f980168ee3c217d2025-12-16 · +1dVerified
- Illinois State AGbd_290f5cb85d1397ca2025-12-01 · +14dCandidate
Filing propagation · 10 filings · 10 states
View merged incident ↗Pattern: first filing Dec 1 (IL), last Dec 16 (TX) — a 15-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.