Motility Software Solutions, a provider of dealer management software (DMS) to over 7,000 dealerships across the United States, suffered a significant ransomware attack that resulted in the exposure of sensitive personal data belonging to approximately 766,000 individuals. The incident was detected on August 19, 2025, when Motility identified unusual activity within certain computer servers supporting its business operations. Subsequent investigation revealed that an unauthorized actor had deployed malware, encrypting a portion of Motility’s systems and exfiltrating files containing customer data prior to encryption. The compromised data included full names, addresses, email addresses, telephone numbers, dates of birth, Social Security numbers, and driver’s license numbers, with the specific data types varying by individual. Motility’s software is widely used in the automotive, powersports, marine, heavy-duty, and RV retail sectors, making the breach particularly impactful across multiple industries. The Pear ransomware gang claimed responsibility for the attack, and researchers noted that Motility’s parent company, Reynolds & Reynolds, was listed on the group’s leak site. Motility responded by conducting a thorough forensic investigation, restoring impacted systems from backups, and implementing additional security measures to prevent future incidents. The company also established dark web monitoring to detect if the stolen data appears on underground forums, although, as of the latest updates, there was no evidence that the information had been misused. Impacted individuals were notified and offered a year of free credit monitoring and identity protection services. The breach notification was also shared with the Office of the Maine Attorney General, as required by law. Motility urged affected customers to remain vigilant and take protective actions to mitigate the risk of identity theft or fraud. The attack on Motility occurred during a period of heightened cybercriminal activity targeting the insurance and automotive sectors, with other major firms also reporting incidents. The breach underscores the ongoing threat posed by ransomware groups to critical business software providers and the extensive downstream risks to their clients and customers. Motility’s swift response and transparency in disclosing the breach were noted, but the incident highlights the need for robust security controls and regular monitoring in organizations handling large volumes of sensitive personal data. The company’s efforts to update its security posture and provide support to affected individuals are ongoing as the investigation continues.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On October 2, 2025, coverage of the Allianz Life and Motility incidents said the combined toll of the two separate breaches exceeded 2 million people. Allianz Life alone was reported to affect about 1.49 million customers.
By October 2025, reporting said Motility's breach affected 766,670 individuals in the United States. The incident was publicly described as a data breach at the dealership software provider tied to the earlier ransomware attack.
Following the August 2025 intrusion, the Pear ransomware group claimed responsibility for the Motility attack. The group alleged it stole more than 4 TB of data from Motility parent company Reynolds & Reynolds.
In August 2025, dealership software provider Motility was hit by a ransomware attack that led to the theft of personal data. Exposed information reportedly included Social Security numbers and driver's license numbers.
In July 2025, attackers breached a third-party CRM system used by Allianz Life, exposing customer data including names, birthdates, addresses, and Social Security numbers. Reporting linked the intrusion to Scattered Spider's broader campaign targeting Salesforce CRM environments.
4 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcecyber.nj.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.