Item 1.05 Material Cybersecurity Incident disclosure filed by Advance Auto Parts, Inc. regarding unauthorized access to third-party cloud data environment containing customer and employee records.
Advance Auto Parts
advanceautoparts.comAutomotive retailer Advance Auto Parts filed Form 8-K Item 1.05 after cybercriminals compromised its cloud database tenant, stealing 380 million customer profiles.
OPEN WEIGHTS TELEMETRY • DETERMINISTIC CONFIDENCE
Confidence & Source Corroboration
100%
CONFIDENCE
1. Primary Authority
CONFIRMED BY REGULATOR
Base weight: 65%
2. Evidence Specificity
+23%
Statutory Filing Verified
3. Corroboration Curve
+17%
3 independent domains
4. Timeline & Staleness
+3%
3 milestones logged
Corroborated Source Domains:
corp.advanceautoparts.com cloud.google.com sec.gov
STATUTORY REGULATORY DISCLOSURES
Official Regulatory Filings & Legal Compliance Records
1 Verified Statutory Filing
Regulatory Ground Truth Standard: The disclosures below represent formal statutory filings and enforcement records submitted to government regulatory authorities (SEC, State Attorneys General, HHS OCR, CISA). In accordance with repository principles, this data is captured exactly as filed by the reporting entity and is never modified, overridden, or synthesized by AI models.
Statutory Filing Details & Summary (Preserved As Filed):
View Official Regulatory Filing Document
https://www.sec.gov/Archives/edgar/data/1158449/000115844924000163/aap-20240605.htm
Technical Forensic Briefing
Incident Overview
Automotive retailer Advance Auto Parts filed Form 8-K Item 1.05 after cybercriminals compromised its cloud database tenant, stealing 380 million customer profiles.
Compromised Assets & Data Scope
- Primary Data Classes: Customer Profiles, Social Security Numbers (SSNs), Driver License Numbers, Purchasing & Loyalty Data.
- Disclosed Affected Population: Approximately 380,000,000 individuals or records.
Statutory Disclosures & Compliance
- Statutory filing submitted to SEC (Form 8-K (Item 1.05)) under accession 0001158449-24-000163.
Milestone Timeline (3 events logged)
2024-05-23 16:30 UTC
CONFIRMED BY TARGET
Unauthorized actor accesses company's cloud data environment via stolen contractor credentials.
2024-06-04 18:00 UTC
INDEPENDENT VERIFICATION
Threat actor offers 380 million customer records for sale on dark web breach forums for $1.5 million.
2024-06-05 17:30 UTC
CONFIRMED BY REGULATOR
Advance Auto Parts files Form 8-K Item 1.05 confirming exfiltration of customer and employee data files.
Have updated information or a new verifiable source?
This incident record is a flat Markdown file tracked in Git. Propose an update or add a milestone via Pull Request.