HackingVulnerability ExploitZero-DayCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
LKQ CORPORATION
bd_f78e0c2f9e23cbd9 · schema v1 · pii pii-v1
Full breach record for LKQ CORPORATION →LKQ Corporation notified the California AG of a cybersecurity event involving a previously unknown vulnerability in Oracle E-Business Suite. The breach occurred on August 9, 2025, and was discovered in early October 2025. The incident affected sole proprietor suppliers, exposing Employer Identification Numbers or Social Security Numbers. LKQ engaged forensic investigators, contained the issue by taking systems offline, and is offering two years of credit monitoring.
California clockDiscovered Oct 3, 2025 → Notified Dec 15, 202573d ✗ CA 60-day late10 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_0d24498ef978ea45Indiana State AGfiled 2025-12-15Verified
- bd_222597b2166e9a95Maine State AGfiled 2025-12-15Candidate
- bd_3b11067f5766d01dMontana State AGfiled 2025-12-15Verified
- bd_6c3aa51f5e66e7edNew Hampshire State AGfiled 2025-12-15Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_e09da3b67b0dfe83Vermont State AGfiled 2025-12-15Verified
- bd_9f980168ee3c217dTexas State AGfiled 2025-12-16(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-615804
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 15, 2025
- Raw hash
- 4c9b4abf5e2ad9b976d9e30a075d5d348ddf3b9b7030bf20aef7912802ae97c5
Reporting entity
- Name
- LKQ CORPORATIONnorm: lkq
Victim entity
- Name
- LKQ CORPORATIONnorm: lkq
Incident
- Discovered
- Oct 3, 2025
- Materiality determined
- —
- Notification sent
- Dec 15, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(73 days from discovery to filing)
- Compliance flags
- CA 60-day late · 73d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 3, 2025→ Notified: Dec 15, 202573d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.