Data breach
Long-Lewis Automotive Group
- Records
- 327,318
- Breach date
- 4 August 2026Estimated
- Added
- 7 October 2026
What was exposed
11 types of data · 3 put you at serious risk
- Names327,318
- Vehicle VINs267,054
- Phone numbers242,515
- Email addresses153,006
- Street addresses152,823
- Dates of birth90,383
- Social security numbers9,511
- Medical diagnoses1,649
- Driving licence numbers194
- Licence plates98
- Passport numbers1
About this breach
Dark Project, a ransomware group operating a data-leak site, listed Long-Lewis Automotive Group as a victim in early August 2026, claiming it stole more than 500 GB of data from the Alabama-based dealership chain. The company has not publicly confirmed the incident, but the investigation team indexed roughly 327,000 rows of exposed records tied to the listing, including names, phone numbers, and vehicle identification numbers. Ransomware.live, which tracks ransomware leak sites, recorded the group's post and estimates the attack took place on August 4, 2026.
Limited public reporting: As of October 7, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
August 4, 2026: Dark Project posted Long-Lewis Automotive Group on its leak site, part of a same-day batch of three victim claims tracked by SecurityArsenal.
August 5, 2026: Independent threat-intelligence outlets, including dexpose and GalaxyWarden, reported the group's claim of more than 500 GB of stolen data, 15,000 records of customer and employee personal data, and more than 650,000 files. Neither claim has been independently verified.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Names, about 327,318 records
Phone numbers, about 242,515 records
Vehicle identification numbers (VINs), about 267,054 records
Email addresses, about 153,006 records
Street addresses, about 152,823 records
Dates of birth, about 90,383 records
Social Security numbers, about 9,511 records
Not every individual is affected by every type of data listed here.
The mix reflects the kind of records a dealership group holds on customers and employees: sales, financing, and service files that tie a person to a vehicle.
What Are the Potential Risks for Affected Individuals?
Social Security numbers and dates of birth combined with names and addresses are the core ingredients for identity theft. Criminals can use them to open credit accounts, file fraudulent tax returns, or apply for loans in someone else's name. Pittman, Dutton, Hellums, Bradley & Mann, a law firm investigating the incident, notes that exposure of customer and employee data could support fraudulent loans, financial fraud, and phishing scams.
Email addresses and phone numbers enable targeted phishing: a scammer who knows you bought a car from Long-Lewis can pose as the dealership or a lender to appear credible. VIN and license plate data can be used for vehicle-related fraud, such as title or warranty scams. Medical diagnosis information adds a sensitive category, because it cannot be changed the way a password can and can be used for extortion or insurance fraud.
What Should You Do If You Were Affected?
Place a free fraud alert or credit freeze with Equifax, Experian, and TransUnion. A freeze blocks most new credit in your name.
Review your credit reports at annualcreditreport.com and dispute anything you do not recognize.
Watch bank, credit card, and loan statements, as well as IRS and state tax notices, for unfamiliar activity.
Be skeptical of calls, texts, or emails that reference your vehicle, financing, or service history at Long-Lewis. Contact the company directly through its official website, not through links in messages.
Use unique passwords and enable two-factor authentication on financial and email accounts.
If a breach notice arrives from Long-Lewis, keep a copy and note any documented losses or time spent dealing with problems.
Because the company has not issued a public confirmation, affected individuals should watch for an official notice and for any state attorney general filings.
In the news
- Ransomware.live, Dark Project victim trackingransomware.live (opens in a new tab)
- dexpose, "Dark Project Strikes Long-Lewis Automotive Group"dexpose.io (opens in a new tab)
- GalaxyWarden, "Long-Lewis Automotive Group Listed by Dark Project Ransomware Group"galaxywarden.com (opens in a new tab)
- SecurityArsenal, Dark Project victim posting analysissecurityarsenal.com (opens in a new tab)
- Pittman, Dutton, Hellums, Bradley & Mann, "Long-Lewis Automotive Group Data Breach"
