Heavy truck dealership service building at dusk with Class 8 semi tractors under security floodlights, illustrating truck dealership cybersecurity after the Motility DMS breach
Resources / Blog

Heavy Truck Dealership Cybersecurity: Lessons From the Motility DMS Breach

By Scot McConnorOctober 9, 2026 · 11 min read

The Motility breach proved that a truck dealer’s DMS vendor is part of the dealer’s own attack surface. Ransomware hit the Reynolds-owned dealer software provider in August 2025, exposed data on 766,670 people, and ended in a $4.95 million class settlement.

Last updated: October 9, 2026

Picture the letter. It isn’t from a hacker. It’s from your software company, and it says your customers’ Social Security numbers may have walked out the door from a server you’ve never seen, in a building you’ve never visited.

That’s roughly the news dealers running Motility Software Solutions got in the fall of 2025, and their own customers got letters of their own. Nobody at those dealerships had to click anything. Their vendor got hit.

I’ve spent nearly 30 years around dealers, first on a sales floor, then selling software to them, and for the last 20 at Helion Technologies. The question dealers ask after a vendor breach is usually some version of “what were we supposed to do about that?” Fair question. There’s a real answer, and most of it is boring, which is good news. So this is a post about truck dealership cybersecurity from the vendor side. It covers what happened at Motility, why heavy truck stores should care more than the headlines suggest, and what I’d change this quarter. If you want the bigger picture of how we handle IT and cybersecurity for heavy truck dealerships, that lives on its own page.

Heavy truck dealership service bay at early morning with Class 8 tractors and a service advisor carrying printed repair orders, the operation a DMS breach puts at risk

What Happened in the Motility DMS Breach

The Motility DMS breach was a 2025 ransomware attack on Motility Software Solutions, a Florida dealer management system provider owned by Reynolds and Reynolds. Attackers encrypted part of its systems and took files holding names, Social Security numbers, driver’s license numbers, and other personal data on 766,670 people.

Motility isn’t a household name in car stores. In trucks it’s different. Founded in 1984 as Systems 2000 and bought by Reynolds in 2022, it sells DMS software to specialty dealers, and Comparitech’s reporting lists heavy trucks, buses, trailers, emergency vehicles, and marine among them. Here’s the timeline, stripped down.

WhenWhat happened
August 19, 2025Motility spots unusual activity on its servers, isolates the affected server, brings in outside specialists, and notifies law enforcement
September 12, 2025Reynolds and Reynolds discloses the incident and says its own corporate network wasn’t affected
Fall 2025Motility reports 766,670 affected people to the Maine Attorney General and offers 12 months of credit monitoring
Fall 2025A data-extortion group called PEAR claims the attack and says it took 4.3 TB of data
April 22, 2026A federal court in Ohio preliminarily approves a $4,949,500 class settlement covering about 760,797 people
August 14, 2026Final approval hearing scheduled, a week after the August 7 claim deadline

Two things in that table deserve a second look. Motility restored from clean backups, which is the part that went right, and it’s the part most dealers never test. And the 766,670 people who got notification letters weren’t Motility’s customers. They were the dealers’ customers. The settlement details sit on the court-approved In re Motility Data Breach Litigation site if you want to read them yourself.

How the attackers got in hasn’t been made public. I’m not going to guess. Nobody outside that investigation knows, and the lessons below don’t depend on it.

Why a Vendor’s Breach Is Still Your Problem

Your DMS holds credit applications, driver’s licenses, Social Security numbers, and billing details for every retail buyer, owner-operator, and fleet account, and when that data sits on a vendor’s server in another state, it’s still your customers’ data. Regulators see it that way. So do the customers.

If your truck store arranges financing or leases, you’re a financial institution under the FTC Safeguards Rule, the same as the franchised car store across the highway. Three parts of 16 CFR 314.4 line up almost exactly with a vendor breach. Section 314.4(f) says you choose service providers that can protect customer information, put that requirement in the contract, and reassess them periodically. Section 314.4(h) wants a written incident response plan. And 314.4(j) requires notice to the FTC within 30 days when a notification event involves 500 or more consumers. Whether a vendor-side breach triggers your own notice is a question for your attorney, not for me, and it’s a lot easier to answer with a plan already written.

Truck dealer principal reading a vendor data breach notification letter at his desk, with semi tractors on the lot outside the office window

Nobody checks this stuff. Not until a letter shows up.

Why Heavy Truck Dealerships Are Easier Marks Than They Look

Plenty of truck dealers figure they’re too small and too boring to interest anybody. The numbers say otherwise. Franchised truck dealers sold 416,467 medium- and heavy-duty trucks in 2025, wrote more than 11 million repair orders, and booked over $48 billion in service and parts sales, according to ATD Data 2025. Every one of those repair orders lives in a DMS.

Then add what’s different about trucks. You sell business to business, so the DMS holds fleet accounts, payment terms, and contacts for companies that also get phished. Stores are spread out, often rural, often hours from the nearest technician. Plenty of groups run 10 or 20 rooftops on a small internal IT team. Peach State Truck Centers, a 12-location group we support, came to us with frequent outages at rural stores and a one-person IT department carrying all of it.

That’s not a target profile anybody brags about. It’s just an honest one.

Seven Lessons Truck Dealers Should Take From Motility

None of these require you to become a security company. Most of them are paperwork and phone calls.

Treat Your DMS Vendor Like the Biggest Risk on the Network

It probably is. Ask your DMS provider for its current security documentation, its independent audit reports if it has them, and its breach notification terms, then put a date on the calendar to ask again next year, because 314.4(f) expects that reassessment and an acquisition or ownership change is a good trigger for one.

Know Where Your Data Physically Lives

Hosted, on premises, or some of each? Many truck stores can’t say for sure, and it gets murkier in groups that bought stores running different systems over the past ten years and never got around to consolidating them. Write it down per rooftop. Include the old server in the closet that nobody turned off after the last migration, because it still has customer data on it.

Test the Restore

Motility came back from clean backups. That’s the lesson. The CISA #StopRansomware Guide says to keep offline, encrypted backups and regularly test them in a disaster recovery scenario. “The backup ran” isn’t the same thing. Restore something real, once a quarter, and time it.

IT technician checking a network rack and backup appliance in a truck dealership server closet, part of testing that backups actually restore

Kill Shared Logins Before Somebody Else Uses Them

Parts counter login. Service drive login. The one taped under the keyboard. Safeguards requires multi-factor authentication for anyone accessing customer information under 314.4(c)(5), and CISA pushes phishing-resistant MFA for email, VPNs, and anything touching critical systems. Shared credentials make all of that impossible to enforce.

Have Somebody Watching at 2 a.m.

Motility caught unusual activity and isolated a server. Would your stores? Ransomware crews like nights and holiday weekends, when the only person in the building is a tech finishing a brake job. There’s a rule for this too. Section 314.4(c)(8) wants user activity monitored and logged, and in practice that means a person, not a dashboard nobody opens. Our managed cybersecurity for dealerships runs on a staffed SOC with live US-based analysts around the clock. MDR, EDR, SOC? Our earlier piece on MDR and EDR for dealerships untangles the acronyms.

Put Vendor Phone Numbers in the Incident Response Plan

Open your written plan. Find the DMS vendor’s security contact, not the general support line. Then look for your cyber insurance carrier’s breach hotline and the attorney you’d actually call, because on the first day of an incident nobody has time to dig through old email for a policy number or a phone extension. If any of those are missing, or point to someone who left, fix it this week.

Throw Out Data You Don’t Need

You can’t lose what you don’t keep. Section 314.4(c)(6) says to dispose of customer information no later than two years after you last used it to serve that customer, unless there’s a legitimate business or legal reason to hold it. Ask how far back yours goes. In a lot of stores the answer is the day the DMS went in, so there are credit apps from trucks sold back when your service manager was still an apprentice, backed up every night and shared with whichever vendor wanted an integration that year. Purge them.

What to Ask Your DMS Vendor This Quarter

Karmak, Procede Excede, Motility, whoever. The questions don’t change with the logo. If you’re shopping, our Karmak vs Procede comparison covers what each one asks of your network, but these apply to anybody already holding your data.

  • When was your last independent security assessment, and can we see a summary?
  • How fast will you tell us if our customers’ data is involved in an incident, and is that in our contract?
  • Where is our data hosted, and who else can reach it?
  • Do you require MFA for your own support staff when they connect to our system?
  • What happens to our data if we leave, and how is it destroyed?
  • Which third parties connect through you to us? Ask for the list.
Truck dealership general manager and IT advisor reviewing a DMS vendor contract's security and breach notification terms at a conference table

Good vendors answer these without drama. If what comes back is a sales pitch, a promise to circle back after renewal, or a security brochure with no dates on it, that tells you something too, and it belongs in the vendor file.

Who Should Own This at a Truck Dealership

Not the DMS vendor. That’s not a knock on anybody. Their job is the software. Your firewall, your backups, your logins, and your Safeguards file are outside that scope, and they should be.

Dealers take a lot of technology advice from the people selling them something, and every one of those people is answering a narrower question than the one you have. I’d rather see one partner looking at the whole picture, because a vendor breach touches the network, the security program, the compliance paperwork, and the people all at once. When something’s not working, I ask myself one question. What am I not doing?

Helion has supported automotive and heavy truck dealerships since 1997. We cover 2,000-plus dealerships and 35,000 end users, with an average of 82 seconds to reach a support agent and a 98% client retention rate. Our FTC Safeguards compliance program keeps the vendor file and the incident plan current, and if you’ve lived through a big vendor outage before, our take on why CDK wasn’t a one-time wake-up call reads a lot differently after Motility. Does your manufacturer send its own security rules? Our guide to OEM cybersecurity requirements for dealers covers what automakers ask for.

What Truck Dealers Are Asking Us About Motility

We’re not a Motility shop. Why should we care?
Because your vendor holds the same kind of file Motility did. Credit apps, license scans, Social Security numbers, all on somebody else’s hardware, and the Safeguards Rule still holds you responsible for picking that somebody and keeping an eye on them. Put your own vendor’s name on the checklist above.
Did truck stores actually get hit?
Probably some, though nobody’s published a number. Motility’s customers include heavy truck, bus, trailer, emergency vehicle, and marine dealers, and the 766,670 figure reported to Maine wasn’t split out by dealer type. I wouldn’t assume you dodged it just because nobody called.
The vendor got breached. Is notifying people on us?
Could be, and that’s your attorney’s call, not your IT guy’s. Safeguards gives covered dealers 30 days to tell the FTC when 500 or more consumers are involved (that’s 314.4(j)), and state breach laws run their own clocks on top. Decide now who makes the call.
$4.95 million sounds like a lot. Is it?
About $6.50 a person. Roughly 760,797 class members, before the lawyers get paid. What a breach really costs a dealer is downtime, and the fleet customer who doesn’t call back.
What’s one thing I can do Monday morning?
Pick up the phone. Ask your DMS rep, in writing, for their security documentation and how fast they’ll tell you about an incident. The answer matters. So does how long it takes to show up.

Start With One Honest Look

Motility did some things right after the fact. It isolated the server, brought in help, restored from clean backups, and notified people. Your stores should be able to say the same, about their own systems and about every vendor they trust with customer data.

If you’d like help with that look, start with our complimentary IT and cybersecurity assessment. We’ll tell you what’s covered and what isn’t. Plainly.

About the author

Scot McConnor

VP of Technology Advisory, Helion Technologies

Scot McConnor is VP of Technology Advisory at Helion Technologies. He started on the dealership sales floor in the late '90s, spent five years selling CRM solutions to dealers, and has spent the past 20 years helping dealerships treat IT as a competitive advantage instead of a cost center.

Scot McConnor on LinkedIn

Confidence in your current setup and actual protection aren't always the same thing. The only way to know which one you have is to look.

Get Your Complimentary IT & Cybersecurity Assessment →