The Motility breach proved that a truck dealer’s DMS vendor is part of the dealer’s own attack surface. Ransomware hit the Reynolds-owned dealer software provider in August 2025, exposed data on 766,670 people, and ended in a $4.95 million class settlement.
Last updated: October 9, 2026
Picture the letter. It isn’t from a hacker. It’s from your software company, and it says your customers’ Social Security numbers may have walked out the door from a server you’ve never seen, in a building you’ve never visited.
That’s roughly the news dealers running Motility Software Solutions got in the fall of 2025, and their own customers got letters of their own. Nobody at those dealerships had to click anything. Their vendor got hit.
I’ve spent nearly 30 years around dealers, first on a sales floor, then selling software to them, and for the last 20 at Helion Technologies. The question dealers ask after a vendor breach is usually some version of “what were we supposed to do about that?” Fair question. There’s a real answer, and most of it is boring, which is good news. So this is a post about truck dealership cybersecurity from the vendor side. It covers what happened at Motility, why heavy truck stores should care more than the headlines suggest, and what I’d change this quarter. If you want the bigger picture of how we handle IT and cybersecurity for heavy truck dealerships, that lives on its own page.

What Happened in the Motility DMS Breach
The Motility DMS breach was a 2025 ransomware attack on Motility Software Solutions, a Florida dealer management system provider owned by Reynolds and Reynolds. Attackers encrypted part of its systems and took files holding names, Social Security numbers, driver’s license numbers, and other personal data on 766,670 people.
Motility isn’t a household name in car stores. In trucks it’s different. Founded in 1984 as Systems 2000 and bought by Reynolds in 2022, it sells DMS software to specialty dealers, and Comparitech’s reporting lists heavy trucks, buses, trailers, emergency vehicles, and marine among them. Here’s the timeline, stripped down.
| When | What happened |
|---|---|
| August 19, 2025 | Motility spots unusual activity on its servers, isolates the affected server, brings in outside specialists, and notifies law enforcement |
| September 12, 2025 | Reynolds and Reynolds discloses the incident and says its own corporate network wasn’t affected |
| Fall 2025 | Motility reports 766,670 affected people to the Maine Attorney General and offers 12 months of credit monitoring |
| Fall 2025 | A data-extortion group called PEAR claims the attack and says it took 4.3 TB of data |
| April 22, 2026 | A federal court in Ohio preliminarily approves a $4,949,500 class settlement covering about 760,797 people |
| August 14, 2026 | Final approval hearing scheduled, a week after the August 7 claim deadline |
Two things in that table deserve a second look. Motility restored from clean backups, which is the part that went right, and it’s the part most dealers never test. And the 766,670 people who got notification letters weren’t Motility’s customers. They were the dealers’ customers. The settlement details sit on the court-approved In re Motility Data Breach Litigation site if you want to read them yourself.
How the attackers got in hasn’t been made public. I’m not going to guess. Nobody outside that investigation knows, and the lessons below don’t depend on it.
Why a Vendor’s Breach Is Still Your Problem
Your DMS holds credit applications, driver’s licenses, Social Security numbers, and billing details for every retail buyer, owner-operator, and fleet account, and when that data sits on a vendor’s server in another state, it’s still your customers’ data. Regulators see it that way. So do the customers.
If your truck store arranges financing or leases, you’re a financial institution under the FTC Safeguards Rule, the same as the franchised car store across the highway. Three parts of 16 CFR 314.4 line up almost exactly with a vendor breach. Section 314.4(f) says you choose service providers that can protect customer information, put that requirement in the contract, and reassess them periodically. Section 314.4(h) wants a written incident response plan. And 314.4(j) requires notice to the FTC within 30 days when a notification event involves 500 or more consumers. Whether a vendor-side breach triggers your own notice is a question for your attorney, not for me, and it’s a lot easier to answer with a plan already written.

Nobody checks this stuff. Not until a letter shows up.
Why Heavy Truck Dealerships Are Easier Marks Than They Look
Plenty of truck dealers figure they’re too small and too boring to interest anybody. The numbers say otherwise. Franchised truck dealers sold 416,467 medium- and heavy-duty trucks in 2025, wrote more than 11 million repair orders, and booked over $48 billion in service and parts sales, according to ATD Data 2025. Every one of those repair orders lives in a DMS.
Then add what’s different about trucks. You sell business to business, so the DMS holds fleet accounts, payment terms, and contacts for companies that also get phished. Stores are spread out, often rural, often hours from the nearest technician. Plenty of groups run 10 or 20 rooftops on a small internal IT team. Peach State Truck Centers, a 12-location group we support, came to us with frequent outages at rural stores and a one-person IT department carrying all of it.
That’s not a target profile anybody brags about. It’s just an honest one.
Seven Lessons Truck Dealers Should Take From Motility
None of these require you to become a security company. Most of them are paperwork and phone calls.
Treat Your DMS Vendor Like the Biggest Risk on the Network
It probably is. Ask your DMS provider for its current security documentation, its independent audit reports if it has them, and its breach notification terms, then put a date on the calendar to ask again next year, because 314.4(f) expects that reassessment and an acquisition or ownership change is a good trigger for one.
Know Where Your Data Physically Lives
Hosted, on premises, or some of each? Many truck stores can’t say for sure, and it gets murkier in groups that bought stores running different systems over the past ten years and never got around to consolidating them. Write it down per rooftop. Include the old server in the closet that nobody turned off after the last migration, because it still has customer data on it.
Test the Restore
Motility came back from clean backups. That’s the lesson. The CISA #StopRansomware Guide says to keep offline, encrypted backups and regularly test them in a disaster recovery scenario. “The backup ran” isn’t the same thing. Restore something real, once a quarter, and time it.

Kill Shared Logins Before Somebody Else Uses Them
Parts counter login. Service drive login. The one taped under the keyboard. Safeguards requires multi-factor authentication for anyone accessing customer information under 314.4(c)(5), and CISA pushes phishing-resistant MFA for email, VPNs, and anything touching critical systems. Shared credentials make all of that impossible to enforce.
Have Somebody Watching at 2 a.m.
Motility caught unusual activity and isolated a server. Would your stores? Ransomware crews like nights and holiday weekends, when the only person in the building is a tech finishing a brake job. There’s a rule for this too. Section 314.4(c)(8) wants user activity monitored and logged, and in practice that means a person, not a dashboard nobody opens. Our managed cybersecurity for dealerships runs on a staffed SOC with live US-based analysts around the clock. MDR, EDR, SOC? Our earlier piece on MDR and EDR for dealerships untangles the acronyms.
Put Vendor Phone Numbers in the Incident Response Plan
Open your written plan. Find the DMS vendor’s security contact, not the general support line. Then look for your cyber insurance carrier’s breach hotline and the attorney you’d actually call, because on the first day of an incident nobody has time to dig through old email for a policy number or a phone extension. If any of those are missing, or point to someone who left, fix it this week.
Throw Out Data You Don’t Need
You can’t lose what you don’t keep. Section 314.4(c)(6) says to dispose of customer information no later than two years after you last used it to serve that customer, unless there’s a legitimate business or legal reason to hold it. Ask how far back yours goes. In a lot of stores the answer is the day the DMS went in, so there are credit apps from trucks sold back when your service manager was still an apprentice, backed up every night and shared with whichever vendor wanted an integration that year. Purge them.
What to Ask Your DMS Vendor This Quarter
Karmak, Procede Excede, Motility, whoever. The questions don’t change with the logo. If you’re shopping, our Karmak vs Procede comparison covers what each one asks of your network, but these apply to anybody already holding your data.
- When was your last independent security assessment, and can we see a summary?
- How fast will you tell us if our customers’ data is involved in an incident, and is that in our contract?
- Where is our data hosted, and who else can reach it?
- Do you require MFA for your own support staff when they connect to our system?
- What happens to our data if we leave, and how is it destroyed?
- Which third parties connect through you to us? Ask for the list.

Good vendors answer these without drama. If what comes back is a sales pitch, a promise to circle back after renewal, or a security brochure with no dates on it, that tells you something too, and it belongs in the vendor file.
Who Should Own This at a Truck Dealership
Not the DMS vendor. That’s not a knock on anybody. Their job is the software. Your firewall, your backups, your logins, and your Safeguards file are outside that scope, and they should be.
Dealers take a lot of technology advice from the people selling them something, and every one of those people is answering a narrower question than the one you have. I’d rather see one partner looking at the whole picture, because a vendor breach touches the network, the security program, the compliance paperwork, and the people all at once. When something’s not working, I ask myself one question. What am I not doing?
Helion has supported automotive and heavy truck dealerships since 1997. We cover 2,000-plus dealerships and 35,000 end users, with an average of 82 seconds to reach a support agent and a 98% client retention rate. Our FTC Safeguards compliance program keeps the vendor file and the incident plan current, and if you’ve lived through a big vendor outage before, our take on why CDK wasn’t a one-time wake-up call reads a lot differently after Motility. Does your manufacturer send its own security rules? Our guide to OEM cybersecurity requirements for dealers covers what automakers ask for.
What Truck Dealers Are Asking Us About Motility
We’re not a Motility shop. Why should we care?
Did truck stores actually get hit?
The vendor got breached. Is notifying people on us?
$4.95 million sounds like a lot. Is it?
What’s one thing I can do Monday morning?
Start With One Honest Look
Motility did some things right after the fact. It isolated the server, brought in help, restored from clean backups, and notified people. Your stores should be able to say the same, about their own systems and about every vendor they trust with customer data.
If you’d like help with that look, start with our complimentary IT and cybersecurity assessment. We’ll tell you what’s covered and what isn’t. Plainly.

