Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

766,000 Impacted by Data Breach at Dealership Software Provider Motility

The hackers stole names, contact details, Social Security numbers, and driver’s license numbers in an August 19 ransomware attack.

Dealership software company Motility Software Solutions is notifying over 766,000 people that their personal information was compromised in a ransomware attack.

A provider of software for recreational vehicle and power sport dealers, Motility discovered the incident on August 19, after hackers accessed servers that support the company’s business operations.

The attackers, the company says, deployed file-encrypting ransomware on its systems, but also stole files containing customers’ personal information.

The affected data, it says, includes names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, and driver’s license numbers.

“At this time, we have no evidence of actual misuse of the information; nevertheless, we are issuing this notice so that you can take appropriate steps to safeguard your information,” Motility writes in the notification letter sent to the affected individuals.

The data breach was initially disclosed by Motility’s parent company Reynolds and Reynolds on September 12, and this week the dealership software provider notified the Maine Attorney General’s Office that 766,670 people were affected.

Advertisement. Scroll to continue reading.

The company is providing the impacted individuals with 12 months of free identity theft, credit monitoring, and fraud consultation services.

Motility says it has fully restored its systems from clean backups and implemented additional security tools and measures, but did not say which ransomware group was responsible for the incident.

Last week, however, the Pear ransomware gang listed Reynolds and Reynolds on its Tor-based leak site, claiming the theft of 4.3 terabytes of data.

Given that Reynolds and Reynolds previously said that its systems and network were not affected by the Motility incident, it is likely that the data Pear allegedly stole came from the subsidiary. The cybercrime group has made the data available for download, which suggests that no ransom was paid.

SecurityWeek has emailed Reynolds and Reynolds for clarification on Pear’s claims and will update this article if the company responds.

Related: 1.5 Million Impacted by Allianz Life Data Breach

Related: VerifTools Fake ID Operation Dismantled by Law Enforcement

Related: Mainline Health, Select Medical Each Disclose Data Breaches Impacting 100,000 People

Related: Canadian Airline WestJet Says Hackers Stole Customer Data

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Tim Byrd has been appointed Chief Information Security Officer at First Citizens Bank.

IRONSCALES has named Steve McKenzie as Chief Operating Officer.

Silvio Pappalardo has joined AuthMind as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.