LKQ CORPORATION
ent_019e1f2a500eb6f52b7b746b32051d2e
LKQ Corp is a supplier of replacement discount auto parts, including remanufactured engines, transmissions, components, and paint products for consumer automobiles, trucks, and recreational vehicles.
AI-summarized from indexed web sources · Chicago, Illinois · 2026-08-04 · source
Disclosures
13
State AG · Leak Site · SEC 8-K · 12 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
9,070
nationwide · State AG TX
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- LKQ CORPORATION
- Normalized
- lkq— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- DS830JTTZQN6GK0I2E41
- SEC EDGAR CIK
- 0001065696
- Domain
- lkqcorp.com
Disclosure history (13)newest first
- Massachusetts State AGas victim2025-12-16
LKQ Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-12-16. 189 Massachusetts residents were affected.
- Texas State AGas victim2025-12-16
LKQ Corporation based in Antioch, Tennessee, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-10-03 and reported on 2025-12-16. 1,119 Texas residents were affected. 9,070 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Other. Consumers were notified via U.S. Mail.
- Indiana State AGas victim2025-12-15
LKQ Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-09 and was reported on 2025-12-15. 189 Indiana residents were affected. 9,070 individuals affected in total.
- Maine State AGas victim2025-12-15
LKQ Corporation reported an external system breach (hacking) affecting 9,070 individuals, including 31 Maine residents. The breach involved the exploitation of vulnerabilities in Oracle E-Business Suite, leading to unauthorized access and exfiltration of personal information (SSN/EIN) from sole proprietor suppliers. The incident was discovered on October 3, 2025, and notifications were sent on December 15, 2025. LKQ engaged forensic investigators, took systems offline, and offered 24 months of credit monitoring.
- Montana State AGas victim2025-12-15
LKQ Corporation notified Montana residents of a cybersecurity event involving the exploitation of a previously unknown vulnerability in Oracle E-Business Suite. The incident was discovered in early October 2025. Impacted data included SSNs or EINs of sole proprietor suppliers. LKQ engaged forensic investigators, contained the breach, and offered two years of credit monitoring.
- New Hampshire State AGas victim2025-12-15
LKQ Corporation notified the New Hampshire Attorney General of a security event involving its Oracle E-Business Suite. A third party exploited a previously unknown vulnerability (zero-day) in early August 2025. LKQ detected the activity in early October 2025, engaged forensic investigators, and took the system offline. The breach impacted 27 New Hampshire resident sole-proprietor suppliers, exposing their EINs and SSNs. LKQ began notifying affected individuals on December 15, 2025, offering two years of credit monitoring via TransUnion.
- Nebraska State AGas victim2025-12-15
LKQ Corporation notified Nebraska AG of a cybersecurity event involving exploitation of Oracle E-Business Suite vulnerabilities. LKQ discovered the incident in early October 2025, investigated with forensic assistance, and took the system offline. Notices were sent on December 15, 2025, to sole proprietor suppliers whose EINs or SSNs were impacted. LKQ offered two years of credit monitoring via TransUnion/Cyberscout.
- Vermont State AGas victim2025-12-15
LKQ Corporation notified Vermont AG of a cybersecurity event involving exploitation of previously unknown vulnerabilities in Oracle E-Business Suite. The incident was discovered in early October 2025. LKQ took systems offline and engaged forensic investigators. Impacted data included SSNs and EINs of sole proprietor suppliers. LKQ offered two years of credit monitoring.
- California State AGas victim2025-12-15
LKQ Corporation notified the California AG of a cybersecurity event involving a previously unknown vulnerability in Oracle E-Business Suite. The breach occurred on August 9, 2025, and was discovered in early October 2025. The incident affected sole proprietor suppliers, exposing Employer Identification Numbers or Social Security Numbers. LKQ engaged forensic investigators, contained the issue by taking systems offline, and is offering two years of credit monitoring.
- Illinois State AGas victim2025-12-01
LKQ CORPORATION filed a data-breach notice with the Illinois Attorney General in December 2025 (case 25-12-658). The register records the breach as discovered on October 3, 2025. Personal information types reported: ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- GLOBALLeak Siteas victim2025-10-27
LKQ Corporation is a leading provider of alternative and specialty parts to repair and accessorize automobiles and other vehicles. The company offers a broad range of replacement parts, components, and systems needed to repair cars and trucks, with an emphasis on recycled and remanufactured parts. LKQ Corporation operates across North America, Europe, and Taiwan.
- FEDERALSEC 8-Kas victim2024-12-13
LKQ Corporation (CIK 0001065696) filed an 8-K on December 13, 2024, reporting a cybersecurity incident affecting a single business unit in Canada. The Company detected unauthorized access to IT systems on November 13, 2024, which disrupted operations. LKQ engaged forensic investigators, notified law enforcement, and contained the threat. The Company states the incident is not material to its financial condition, though operations were impacted for a few weeks. No specific data types or individual counts were disclosed.
- New Hampshire State AGas victim2019-06-10
LKQ Corporation notified the NH AG of unauthorized access to an employee email account between Oct 31, 2018 and Jan 9, 2019. The incident affected 2 NH residents, exposing names, addresses, and bank account details. LKQ secured accounts, engaged forensic investigators, and provided 12 months of credit monitoring.
Subsidiary disclosures (4)filed by group companies
◈ These filings were made by or about subsidiaries of LKQ CORPORATION — not by LKQ CORPORATION itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Maryland State AGvia Uni-Select2025-03-18
Uni-Select notified Maryland AG of a November 2024 security incident affecting one Maryland resident. Unusual activity led to systems going offline. Affected data included name, workplace accident info, and health insurance details. Notification sent Feb 20, 2025, with Equifax credit monitoring offered. Threat actor described as financially motivated and sophisticated.
- Massachusetts State AGvia Warn Industries Inc2019-03-22
Warn Industries, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-03-22. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGvia Warn Industries Inc2019-03-22
Warn Industries, Inc. notified Montana residents of a data breach where an unknown actor accessed employee email accounts. The actor established a forwarding rule on Feb 28, 2018, which operated until detection on Dec 13, 2018. Customer PII and credentials were potentially exposed. Warn engaged forensic experts, secured accounts, and offered 2 years of credit monitoring.
- Oregon State AGvia Warn Industries Inc2019-03-22
Warn Industries, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2019-03-22. The breach occurred during 2/28/2018 - 1/7/2019. The breach was discovered on 1/7/2019. 860 individuals were affected. Notice was sent on 3/22/2019.