Data breach
Motility Software Solutions
- Records
- 2,796,970
- Breach date
- 2 September 2025Estimated
- Added
- 17 October 2025
What was exposed
5 types of data · 3 more reported · 1 puts you at serious risk
- Email addresses1
- Names1
- Home addresses1
- Phone numbers1
- Social security numbers1
- Driving licence numbersReported, not counted
- PasswordsReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Motility Software Solutions, a dealer management software provider for RV and powersports dealerships owned by The Reynolds and Reynolds Company, disclosed a ransomware incident that exposed the personal information of roughly 766,670 consumers. According to our investigation team, the listing contains about 2.8 million records, and we estimate the attack occurred around September 2, 2025. State filings and the company put the number of affected individuals near 766,000, though the full volume of data involved remains unclear because no ransomware group has publicly claimed responsibility and the company has not said whether a ransom was demanded or paid.
Breach Timeline
August 11, 2025: A filing with the Maine Attorney General's office lists this as the date the breach occurred.
August 19, 2025: Motility detected unusual activity on its servers and took the affected systems offline.
September 12, 2025: Reynolds and Reynolds publicly disclosed the incident in a press release.
September 15, 2025: The Pear ransomware gang listed Reynolds and Reynolds on its leak site, claiming the theft of 4.3 terabytes of data, according to BreachSense.
September 29, 2025: Motility began mailing written notification letters to affected individuals, per its notice to state attorneys general.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers, email addresses, phone numbers, names, and home addresses.
According to Motility's consumer notification letter filed with state attorneys general, the affected files varied by individual but could also include dates of birth, driver's license numbers, and, for some people, customer portal credentials. The company said an unauthorized actor deployed malware that encrypted part of its systems and, before encryption, may have removed files containing customers' personal data.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of Social Security numbers, dates of birth, and driver's license numbers is particularly valuable to identity thieves because these identifiers are difficult to change and are commonly used to verify identity. With this data, criminals can attempt to open lines of credit, file fraudulent tax returns, impersonate victims with financial institutions, or craft convincing phishing messages using real names and contact details. Motility said it has no evidence of actual misuse so far, but the data was made available for download by the Pear gang, which suggests it could circulate on underground marketplaces. Stolen email addresses and portal credentials also raise the risk of account takeovers and targeted scams.
What Is Motility Software Solutions Doing in Response?
Motility isolated the affected server, engaged cybersecurity experts, and notified law enforcement. The company said it conducted a forensic investigation, restored systems from clean backups, added security tools and third-party monitoring, and established dark web monitoring. It is offering affected individuals one year of complimentary identity theft protection and credit monitoring through Norton LifeLock, with enrollment open until December 19, 2025, and it set up a dedicated call center. Reynolds and Reynolds said its own systems and network were separate and not affected. A PRNewswire notice shows the law firm Schubert Jonckheer & Kolbe is investigating the incident on behalf of potential claimants.
What Should You Do If You Were Affected?
Enroll in the free credit monitoring and identity protection services offered in the notification letter. Review your credit reports at annualcreditreport.com and watch for accounts or inquiries you do not recognize. Consider placing a fraud alert or a security freeze with the three major credit bureaus, Equifax, Experian, and TransUnion. Be cautious with unsolicited emails, calls, or texts that reference the breach, since scammers often pose as companies after an incident. If you believe your information has been misused, contact the Federal Trade Commission at reportfraud.ftc.gov and your state attorney general, and file a police report if needed.
