Qvale Auto Group, Inc. notified employees of a data exposure that occurred in June 2016 during a third-party IT vendor's system upgrade. Employee access limitations were inadvertently removed, allowing certain employees to potentially view other employees' names, bank account information, and Social Security Numbers. The error was corrected upon discovery. Affected employees were offered 12 months of Experian ProtectMyID credit monitoring.