AutoZone notified 184,995 people of a MOVEit-related data breach
- Organization
- AutoZone
- Exploit
- Hacking
- Industry
- Automotive Parts Retail
AutoZone, the Memphis-based automotive parts retailer, began notifying people in November 2023 that their information had been taken during the Clop extortion group's mass exploitation of Progress Software's MOVEit Transfer product. The retailer told regulators the intrusion dated to May 28, 2023, and that it determined on or about August 15, 2023 that the flaw, tracked as CVE-2023-34362, had been used to exfiltrate files from its environment.
A filing with the Office of the Maine Attorney General put the number of people notified at 184,995. The information involved included full names and Social Security numbers.
Clop had already listed AutoZone on its leak site and published roughly 1.1 GB of material on July 7, 2023. According to BleepingComputer's review of the leaked archive, it held employee names and email addresses, tax and payroll documents, Oracle database files, parts supply records, and store, production and sales data. No customer records appeared in the published files, despite some early accounts describing customer data as part of the theft.
AutoZone said it disabled MOVEit, rebuilt the affected systems and applied the vendor's patch. It offered those notified free identity theft protection and credit monitoring and advised them to watch their accounts and credit reports for the following 24 months. The company said it had seen no evidence that the exposed information had been misused.