HackingSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
BMW FINANCIAL SERVICES NA, LLC
bd_f9d9c1bab8b44bad · schema v1 · pii pii-v1
Full breach record for BMW FINANCIAL SERVICES NA, LLC →BMW Financial Services NA, LLC notified the California AG of a data breach involving its third-party service provider, AIS InfoSource LP. Unauthorized access occurred between Feb 16-21, 2025, and was discovered on Feb 17, 2025. The incident involved the exfiltration of customer data including names, SSNs, and financial account information. BMW FS systems were not directly impacted. AIS engaged forensic specialists, secured the network, and is offering credit monitoring to affected individuals.
California clockDiscovered Feb 17, 2025 → Notified Jun 13, 2025116d ✗ CA 60-day late19 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_8e640f2e80dd8255Maine State AGfiled 2025-07-03Candidate
- bd_a00483d8d52831c0Indiana State AGfiled 2025-07-02(1d gap)Verified
- bd_6a83915b1ec3ffa3Texas State AGfiled 2025-07-08(5d gap)Verified
- bd_819d74f937591393New Hampshire State AGfiled 2025-07-14(11d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-604910
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 3, 2025
- Raw hash
- 7b1966ceba2cd750368cfe6a9eacd443fcf48a06d08f4ef8b0a202d594c4db36
Reporting entity
- Name
- AIS Incnorm: ais
- Domain
- ais-inc.com
Victim entity
- Name
- BMW FINANCIAL SERVICES NA, LLCnorm: bmw financial services na
Incident
- Discovered
- Feb 17, 2025
- Materiality determined
- —
- Notification sent
- Jun 13, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via AIS InfoSource LP
Compliance
- Time to disclose
- 19 weeks(136 days from discovery to filing)
- Compliance flags
- CA 60-day late · 116d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 17, 2025→ Notified: Jun 13, 2025116d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.