Data breach
Chrysler
- Records
- 1,752,162
- Breach date
- 25 December 2025Estimated
- Added
- 6 January 2026
What was exposed
3 types of data · 4 more reported
- Email addresses1
- Names1
- Phone numbers1
- Social security numbersReported, not counted
- Home addressesReported, not counted
- VehiclesReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In late December 2025, the Everest ransomware group claimed it had breached systems belonging to Chrysler, the Stellantis-owned automaker, and stolen more than one terabyte of internal data. Security outlets including SC World and BlackFog reported that the group posted the claim on its dark web leak site after ransom negotiations reportedly failed. Our investigation team has indexed more than 1.75 million rows of data connected to the listing, including email addresses, phone numbers, and names. Chrysler's parent company, Stellantis, has not issued a public confirmation of the breach; as of September 25, 2026, no detailed company notice had been located in sources reviewed.
December 26, 2025: The Everest ransomware group listed Chrysler on its dark web leak site, claiming it had stolen roughly one terabyte of data, according to SC World and other security reporting.
January 4, 2026: Everest published the stolen data online after the company reportedly refused to pay a ransom, according to reporting on a subsequent lawsuit by CyberInsider.
January 2026: A federal class action, Spadafore v. FCA US LLC, was filed in Michigan over the breach, alleging the exposure of customer Social Security numbers and other personal information.
May 20, 2026: The plaintiffs voluntarily dismissed the class action, roughly four months after filing, according to CourtDocket.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, phone numbers, and names.
Not every individual is affected by every type of data listed here.
The reported haul went beyond those basics. Screenshots published by the attackers showed customer interaction logs with physical addresses, vehicle details, recall case notes, and call outcomes, along with internal spreadsheets, CRM exports, and agent work logs, according to SC World. The material reportedly spanned 2021 through 2025 and covered customers, internal agents, and dealers. The class action filed in January 2026 alleged that the exposed data also included dates of birth and Social Security numbers, though those allegations come from the complaint rather than a company notice.
What Are the Potential Risks for Affected Individuals?
The combination of names, email addresses, phone numbers, and home addresses gives criminals the raw material for targeted phishing and phone scams. A message that references a real vehicle purchase or a real recall case is far more convincing than a generic one.
If Social Security numbers were indeed exposed, as the lawsuit alleges, the risk extends to identity theft: fraudulent loan or credit card applications, tax refund fraud, and account takeovers that depend on answering basic identity questions. Because the attackers published the data rather than only selling it privately, anyone can potentially access it, and it may circulate for years. Affected individuals should also expect that this information could resurface in future scams that impersonate Chrysler, a dealer, or a recall program.
What Should You Do If You Were Affected?
Watch your email, texts, and phone for messages or calls that reference Chrysler, a vehicle, or a recall. Do not click links or share personal details in response; contact the company through its official website if you need to verify something.
Place a free fraud alert or a credit freeze with the three major credit bureaus if you have reason to believe your Social Security number was exposed.
Review your credit reports at annualcreditreport.com and dispute anything you do not recognize.
Change passwords you have reused elsewhere, especially for email and financial accounts, and turn on multi-factor authentication where it is offered.
In the news
- SC World: Chrysler allegedly compromised by Everest ransomware gangscworld.com (opens in a new tab)
- BlackFog: The State of Ransomware, December 2025blackfog.com (opens in a new tab)
- CyberInsider: Stellantis sued over Chrysler data breach claimed by Everest ransomwarecyberinsider.com (opens in a new tab)
- CourtDocket: Stellantis Data Breach Class Actioncourtdocket.org (opens in a new tab)
