GENERAL MOTORS COMPANY
ent_019e9a9eefe3334d62bf564bf97047de
Disclosures
6
SEC 10-K Item 1C · State AG · 4 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
4,920
as filed · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- GENERAL MOTORS COMPANY
- Normalized
- general motors— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 54930070NSV60J38I987
- SEC EDGAR CIK
- 0001467858
- Domain
- gm.com
Disclosure history (6)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-01-27
General Motors Company (GM) filed its 10-K Item 1C disclosing its cybersecurity risk management and strategy. The filing explicitly states that GM has not experienced any material cybersecurity incidents and that expenses from cybersecurity incidents were immaterial, including penalties and settlements. The company describes its governance structure, including a Cybersecurity Management Board and a CISO reporting to the Board's Risk and Cybersecurity Committee, but reports no specific breach events.
- 🦞Maine State AGas victim2024-07-08
Between May 18–20, 2024, unauthorized parties used previously compromised credentials from non-GM sites (credential stuffing) to access 65 GM MyAccounts on the GM accessories website, making fraudulent purchases. Exposed data included name, address, phone number, and last four digits of saved payment card. No GM-sourced credential breach was identified. GM forced password resets, implemented MFA, refunded fraudulent purchases, and notified law enforcement. Two Maine residents were affected.
- 🏎️Indiana State AGas victim2024-06-26
General Motors Company reported a data breach to the Indiana Attorney General. The breach occurred on 2024-05-18 and was reported on 2024-06-26. 2 Indiana residents were affected. 65 individuals affected in total.
- 🐻California State AGas victim2022-05-16
General Motors Company notified the California Attorney General of a data incident affecting 4,920 California residents. Between April 11 and April 29, 2022, unauthorized parties used credentials previously compromised on other sites to access GM online accounts. Affected data included names, emails, addresses, phone numbers, location data, and search history. GM suspended gift card redemptions, forced password resets, and reported the incident to law enforcement.
- 🦞Maine State AGas victim2022-05-11
General Motors Company reported a data breach on May 11, 2022, affecting 141 individuals, including 1 Maine resident. The incident involved unauthorized access to a non-financial online account, compromising names and account passwords. The breach occurred and was discovered on April 11, 2022. Electronic notifications were sent to affected consumers on May 11, 2022.
- 🦞Maine State AGas victim2022-05-10
General Motors Company reported that an unauthorized third party gained access to customer online accounts using their name and password.
Subsidiary disclosures (2)filed by group companies
◈ These filings were made by or about subsidiaries of GENERAL MOTORS COMPANY — not by GENERAL MOTORS COMPANY itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- FEDERALSEC 10-K Item 1Cvia General Motors Financial Company, Inc.2026-01-27
General Motors' Item 1C. Cybersecurity disclosure in its Annual Report describes its NIST CSF-aligned cybersecurity risk management program and governance structure (Risk and Cybersecurity Committee, Global CISO). The filing explicitly states the Company has not experienced any material cybersecurity incidents and that expenses incurred from cybersecurity incidents were immaterial. No specific breach is disclosed.
- 🏎️Indiana State AGvia DMAX Ltd2024-09-04
DMAX Ltd reported a data breach to the Indiana Attorney General. The breach occurred on 2024-07-16 and was reported on 2024-09-04. 8 Indiana residents were affected. 3,200 individuals affected in total.