Asbury Automotive Group, Inc.
ent_019e4713be04ecbf75b21234bfa83ae5
Disclosures
7
SEC 10-K Item 1C · State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
41,571
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Asbury Automotive Group, Inc.
- Normalized
- asbury automotive— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300JH4DTA7U42GL91
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-20
Asbury Automotive Group, Inc. discloses in its 10-K Item 1C that it has robust cybersecurity risk management processes integrated into its enterprise risk program. The company employs a multi-layered defense including SOC-as-a-Service, SIEM, EDR, and cloud monitoring. It conducts regular employee training, phishing simulations, and annual penetration tests. No material cybersecurity incident has occurred or is reasonably likely to materially affect the company's financial condition as of the filing date.
- 🦞Maine State AGas victim2024-04-24
Asbury Automotive Group reported a breach occurring on 12/25/2023, discovered on 03/25/2024, affecting 2 Maine residents. The incident involved an external system breach (hacking) resulting in the acquisition of names and driver's license numbers. Asbury provided written notification and one year of credit monitoring services.
- 🦬Montana State AGas victim2024-04-24
Asbury Automotive Group reported a data breach to the Montana Attorney General. The breach was reported on 2024-04-24. The breach occurred on 12/25/2023. 7 Montana residents were affected.
- ⛰️New Hampshire State AGas victim2024-04-24
Asbury Automotive Group notified the New Hampshire Attorney General of a security incident detected on December 25, 2023, involving unauthorized access to file servers. The breach affected 6 New Hampshire residents, exposing names and government identifiers. Asbury engaged a cybersecurity firm, notified law enforcement, and sent notification letters on April 24, 2024, offering one year of identity monitoring services.
- 🍁Vermont State AGas victim2024-04-24
Asbury Automotive Group notified consumers of a December 25, 2023 security incident involving unauthorized access to file servers. The incident compromised names and unspecified data elements. Asbury engaged a cybersecurity firm, notified law enforcement, and enhanced security measures. Affected individuals received complimentary identity monitoring services.
- 🏎️Indiana State AGas victim2024-04-24
Asbury Automotive Group reported a data breach to the Indiana Attorney General. The breach occurred on 2023-12-25 and was reported on 2024-04-24. 1,973 Indiana residents were affected. 41,571 individuals affected in total.
- FEDERALSEC 10-K Item 1Cas victim2024-02-29
Asbury Automotive Group, Inc. discloses in its 10-K Item 1C that it has experienced targeted cybersecurity incidents in the past resulting in unauthorized access to information systems. No incident has materially affected the company as of the filing date. The company maintains a comprehensive cybersecurity risk management program including governance, training, and technical controls (SOCaas, SIEM, EDR) but acknowledges potential future risks.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of Asbury Automotive Group, Inc. — not by Asbury Automotive Group, Inc. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.