Motility Software Solutions, one of the leading providers of Dealer Management Systems (DMS) in the United States, has confirmed that it has been the victim of a serious ransomware cyberattack. The incident resulted in the exposure of sensitive personal data of 766,000 customers, confirming once again how attractive targets are for companies that manage critical databases.

A provider with an extensive footprint
Motility, formerly known as Systems 2000 (Sys2K), offers software used by approximately 7,000 dealerships (automotive, motorsports, marine, heavy-duty vehicle and RV retail) nationwide. Its portfolio covers a wide range of business functions:
- Customer Relationship Management (CRM)
- Inventory management
- Sales and accounting
- Financial services
- After-sales and customer service
- Fleet rental and management
- Access to dashboards via web and mobile applications
See also: Allianz Life: Data breach affects 1.5 million people
The fact that its services touch almost every aspect of a dealership's operations makes the attack even more critical, as it potentially affects thousands of businesses that rely on Motility's software every day.
The cyberattack of August 19th
The company announced that on August 19, 2025, it detected “unusual activity” on some of the servers supporting its business operations. It was soon confirmed to be a ransomware attack, where attackers deployed malware that encrypted a significant portion of the systems and restricted access to internal data.
It appears that before the encryption, the perpetrators had already extracted files with personal data.

Motility Software Solutions: The data exposed
The notice filed with the Maine Attorney General's Office details the types of data that may have been exposed. By person, the list may include:
- Full name
- Residential address
- Email address
- Phone number
- Date of birth
- Social Security Number (SSN)
- Driving license number
This is information that on its own is particularly valuable to hackers, while combined they form a complete profile for identity theft and financial fraud.
See also: FunkLocker Ransomware Leverages AI and Windows Tools
The first response measures
Motility said it conducted a thorough investigation with the help of experts, restored affected systems from backups and implemented new cybersecurity measures.
At the same time, the company launched monitoring system dark webto detect any sale or publication of stolen data on illegal forums.
Free protection services for victims
While there is no indication yet that the data has been used maliciously, Motility urges affected individuals to be on heightened alert.
To this end, it is providing one year of free identity monitoring through LifeLock, giving recipients of the alerts until December 19, 2025, to register with a unique activation code.
What do experts recommend?
The following measures are recommended for affected individuals:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Monitoring credit reports
- Enable fraud alerts
- Consideration of a possible credit freeze
- Increased attention to suspicious communications via email or phone
With social security numbers and driver's licenses on the list of exposed data, the risks are particularly high, as these are details that cannot be easily changed, unlike a password.
See also: Chinese 'Phantom Taurus' targets organizations with Net-Star

The silence of ransomware groups
So far, no known ransomware group has claimed responsibility for the attack, leaving open the question of whether this is a new group or whether Motility Software Solutions may be negotiating behind the scenes with the perpetrators.
The lack of a public "signature" does not reduce the risk; on the contrary, it highlights how difficult it is to attribute such attacks with certainty.
The message for the industry
The attack on Motility Software Solutions highlights the scope of the threat to the DMS industry. Car dealerships and related businesses that rely on third-party software providers are indirectly becoming targets for cybercriminals.
A breach at a single provider can have ripple effects for thousands of businesses, causing both financial losses and a blow to customer trust.
The Motility incident is yet another stark reminder that ransomware cyberattacks are becoming a systemic risk for entire industries. Protecting data and investing in robust cybersecurity measures is no longer an option, but a necessity.
Source: www.bleepingcomputer.com
