General Motors Company reported a data breach to the Indiana Attorney General. The breach occurred on 2024-05-18 and was reported on 2024-06-26. 2 Indiana residents were affected. 65 individuals affected in total.
Affected (this filing): 65
Clustered 2 filings across 2 jurisdictions · filing window Jun 26, 2024 → Jul 8, 2024. View entity profile → Other incidents for this victim →
incident inc_532cba038f6c4cdb · merge_method deterministic · confidence 95%
Discovered → first regulatory filing
Time between earliest and latest filing
Not recorded for this incident
Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
PII · PCI
IN ME
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
May 18, 2024
When the intrusion reportedly occurred, per the linked filings
May 24, 2024
Reported by MAINE AG filing
General Motors Company reported a data breach to the Indiana Attorney General. The breach occurred on 2024-05-18 and was reported on 2024-06-26. 2 Indiana residents were affected. 65 individuals affected in total.
Affected (this filing): 65
Between May 18–20, 2024, unauthorized parties used previously compromised credentials from non-GM sites (credential stuffing) to access 65 GM MyAccounts on the GM accessories website, making fraudulent purchases. Exposed data included name, address, phone number, and last four digits of saved payment card. No GM-sourced credential breach was identified. GM forced password resets, implemented MFA, refunded fraudulent purchases, and notified law enforcement. Two Maine residents were affected.
Affected (this filing): 2
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.