Data breach
The National Auto Loan Network
- Records
- 51,394
- Breach date
- 14 January 2026Estimated
- Added
- 14 March 2026
What was exposed
1 type of data
- Email addresses1
About this breach
The National Auto Loan Network, a Tustin, California firm that refinances auto loans, was targeted in a ransomware attack in January 2026. According to our investigation team, the incident is estimated to have occurred on or around January 14, 2026, and the indexed dataset contains 51,394 rows, including email addresses. External trackers linked the attack to the Nova ransomware group, which reportedly claimed on its leak site that it stole roughly 600 GB of company data. Our team has not verified a claiming actor for this listing, and the company itself has not confirmed the breach publicly.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
January 14, 2026: The ransomware tracking site Ransomware.live listed The National Auto Loan Network as a victim of the Nova group, with an estimated attack date of January 14, 2026.
January 16, 2026: The law firm Strauss Borrelli PLLC reported that a hacker group claimed to have stolen more than 600 GB of data from NALN, and that the company had not publicly commented on or confirmed a breach as of that date.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses. Our investigation team did not determine how many individual email addresses appear in the indexed data, so the exact count remains unknown.
Not every individual is affected by every type of data listed here.
Because the company has not published a confirmed list of compromised fields, it is not clear from verified sources whether names, loan details, or financial information were also taken. Claims about the content of the stolen files come only from the attacker's own posting and have not been independently verified.
What Are the Potential Risks for Affected Individuals?
Email addresses in the hands of criminals are most often used for phishing. Attackers can send messages that look like legitimate loan notices, payment reminders, or account alerts, then try to trick recipients into entering passwords, bank details, or Social Security numbers on fake websites.
Because the alleged attackers claim to hold a much larger set of company data, people who financed or refinanced vehicles through NALN should also watch for more personal messages that reference real loan activity. Criminals sometimes pair a stolen email address with other leaked details to make scams more convincing. Anyone who reused a password tied to a NALN account should treat that password as exposed.
What Is The National Auto Loan Network Doing in Response?
As of the most recent external reporting reviewed, NALN had not issued a public statement. Strauss Borrelli PLLC noted on January 16, 2026 that the company had not commented on or confirmed the incident. We did not find a verified breach notification from the company in the sources reviewed as of September 25, 2026. Affected customers can reach the company directly through its published customer service line, 888-391-3504, to ask about the incident.
What Should You Do If You Were Affected?
Be skeptical of any email about an auto loan, refinancing offer, or payment issue. Do not click links or open attachments in unexpected messages. If a message seems to come from NALN, contact the company using a phone number you find independently.
Change passwords on any account that shared a password with a NALN login, and turn on two-factor authentication where it is offered.
Monitor your bank and credit card statements for charges you do not recognize, and consider reviewing your credit reports for accounts you did not open.
In the news
- Ransomware.live victim listing for The National Auto Loan Networkransomware.live (opens in a new tab)
- Strauss Borrelli PLLC investigation notice, January 16, 2026straussborrelli.com (opens in a new tab)
- ClaimDepot summary of the Nova group's claimclaimdepot.com (opens in a new tab)
- BreachSense breach report for naln.combreachsense.com (opens in a new tab)
