Clustered 7 filings across 7 jurisdictions · filing window Dec 15, 2025 → Dec 16, 2025. View entity profile → Other incidents for this victim →
incident inc_c65f985c3b9c485e · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA IN ME MT NH TX VT
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Aug 1, 2025
When the intrusion reportedly occurred, per the linked filings
Oct 3, 2025
Reported by NEW HAMPSHIRE AG, MAINE AG, CALIFORNIA AG, VERMONT AG, TEXAS AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
LKQ Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-09 and was reported on 2025-12-15. 189 Indiana residents were affected. 9,070 individuals affected in total.
Affected (this filing): 9,070
On October 3, 2025, LKQ Corporation discovered that it was the victim of an external system breach that occurred on August 9, 2025. The breach affected 31 Maine residents. In response to the incident, the company offered 24 months of credit monitoring and identity theft restoration services through TransUnion.
Affected (this filing): 31
LKQ Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2025-12-15. The breach occurred from 08/01/2025 to 08/20/2025. 25 Montana residents were affected.
Affected (this filing): 25
LKQ Corporation notified the New Hampshire Attorney General of a security event involving its Oracle E-Business Suite. A third party exploited a previously unknown vulnerability (zero-day) in early August 2025. LKQ detected the activity in early October 2025, engaged forensic investigators, and took the system offline. The breach impacted 27 New Hampshire resident sole-proprietor suppliers, exposing their EINs and SSNs. LKQ began notifying affected individuals on December 15, 2025, offering two years of credit monitoring via TransUnion.
Affected (this filing): 27
LKQ Corporation notified Vermont AG of a cybersecurity event involving exploitation of previously unknown vulnerabilities in Oracle E-Business Suite. The incident was discovered in early October 2025. LKQ took systems offline and engaged forensic investigators. Impacted data included SSNs and EINs of sole proprietor suppliers. LKQ offered two years of credit monitoring.
LKQ Corporation notified the California AG of a cybersecurity event involving a previously unknown vulnerability in Oracle E-Business Suite. The breach occurred on August 9, 2025, and was discovered in early October 2025. The incident affected sole proprietor suppliers, exposing Employer Identification Numbers or Social Security Numbers. LKQ engaged forensic investigators, contained the issue by taking systems offline, and is offering two years of credit monitoring.
LKQ Corporation based in Antioch, Tennessee, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-10-03 and reported on 2025-12-16. 1,119 Texas residents were affected. 9,070 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Other. Consumers were notified via U.S. Mail.
Affected (this filing): 1,119