Alabama's largest automotive retailer has been hit by a ransomware attack. If you purchased a vehicle from any Long-Lewis location, your personal and financial information may have been stolen.
On August 5, 2026, the ransomware group Dark Project publicly claimed responsibility for a cyberattack on Long-Lewis Automotive Group, posting the company as a victim on its dark web leak site. The attack is estimated to have occurred on August 4, 2026. According to the listing, cybercriminals stole more than 500 GB of confidential data from Long-Lewis systems, compromising more than 650,000 files in total.
This is a pre-notice incident. Long-Lewis Automotive Group has not yet sent notification letters to affected customers or employees. If you have purchased a vehicle from any Long-Lewis dealership in Alabama, you may be among those affected, and you may not know it yet.
Cory Watson Attorneys is reviewing claims from affected individuals and offering free, no-obligation consultations.
What Happened
Long-Lewis Automotive Group, headquartered at 2800 Woodward Avenue in Muscle Shoals, Alabama, is the largest automotive retailer in the state. With origins dating to the late 1880s and one of the nation's first Ford franchises awarded in 1915, the company operates multiple dealerships across Alabama, including Ford, Lincoln, Chevrolet, Honda, Volkswagen, Mitsubishi, and pre-owned vehicle locations in Muscle Shoals, Florence, Hoover, Prattville, Alabaster, Calera, Tuscumbia, Cullman, and Bessemer. The group retails about 1,000 vehicles per month and employs hundreds of people across its network.
On or around August 4, 2026, cybercriminals accessed Long-Lewis systems and exfiltrated a significant volume of data. The breach was publicly disclosed by the Dark Project ransomware group on August 5, 2026, through a listing on its dark web leak site. Third-party threat intelligence trackers, including Ransomware. live, discovered and indexed the claim.

Car dealership lot with rows of vehicles under an overcast sky
Dark Project is described by threat intelligence sources as an emerging ransomware group, and Ransomware. live notes the claim should be treated with caution until independently verified. Long-Lewis Automotive Group has not issued a public statement confirming or denying the breach as of the date of this article.
What Information Was Taken
According to the Dark Project leak site listing, the attack compromised:
- More than 500 GB of confidential data
- More than 15,000 records containing personal data of customers and employees
- Financial and banking documents
- Other valuable company information
- More than 650,000 total files
Auto dealerships collect and store some of the most comprehensive personal and financial data of any business. When you purchase a vehicle, a dealership typically collects your full name, address, date of birth, Social Security number, driver's license number, employment information, income details, and financial account information as part of the financing and titling process. That same data now appears to be in cybercriminals' hands.
Financial and banking documents of this volume can include transaction records, payment details, employee direct deposit information, and business account data. The combination of personal identity information and financial records creates significant risk of identity theft, fraudulent loan applications, tax fraud, and other financial crimes.
This Is a Pre-Notice Incident
Long-Lewis Automotive Group has not yet notified affected customers or employees. This matters because every day without notice is another day you cannot take steps to protect yourself.
Under the Federal Trade Commission's Safeguards Rule, auto dealerships are classified as financial institutions and are required to implement and maintain a written information security program to protect customer financial data. The rule was substantially strengthened in 2021, with compliance required by June 2023. A further amendment took effect in May 2024 requiring dealerships to notify the FTC within 30 days of discovering a breach affecting 500 or more consumers with unencrypted data.
Alabama's Data Breach Notification Act requires businesses to notify Alabama residents whose sensitive personal information has been compromised without unreasonable delay. Whether Long-Lewis's response to this incident will meet those obligations remains to be seen.
If you purchased a vehicle from any Long-Lewis location, do not wait for a letter to take action.
The Dark Project Ransomware Group
Dark Project is an active ransomware group tracked by multiple threat intelligence platforms. As of August, 2026, Ransomware. live tracks the group as having claimed victims across multiple countries, with the manufacturing, healthcare, and transportation sectors among the most frequently targeted.
Threat intelligence sources note the group is emerging and its claims should be treated with appropriate caution pending independent verification. That said, the volume of data described in the Long-Lewis listing (more than 500 GB across 650,000 files) is consistent with a significant, targeted intrusion rather than an opportunistic claim.
Dark Project's listing includes descriptions of customer and employee personal data alongside financial and banking documents, the type of detailed, organized data typically exfiltrated in a deliberate ransomware operation. If the stolen data is published or sold on criminal marketplaces, affected individuals could face fraud, identity theft, and financial harm for years.
Do You Qualify?
Cory Watson Attorneys is reviewing claims from Long-Lewis customers across Alabama.
If you purchased a vehicle from any Long-Lewis dealership in Alabama, you may have a legal claim. Contact us today for a free, no-obligation case evaluation.
Steps to Take Right Now
Do not wait for a notification letter. Long-Lewis has not yet informed affected customers. This is a pre-notice incident, and every day without action leaves your information more exposed.
Freeze your credit. Contact Equifax, Experian, and TransUnion to place a free credit freeze. This prevents new accounts and loans from being opened in your name without your authorization.
Pull your free credit reports. Visit annualcreditreport.com and review every account and inquiry for activity you do not recognize, including auto loans you did not take out.
Monitor your financial accounts closely. Review bank statements, credit card activity, and any loan accounts for unauthorized transactions or new accounts opened in your name.
Watch for phishing attempts. Criminals use stolen data to send convincing follow-up scams. Be skeptical of any unsolicited contact referencing Long-Lewis, vehicle financing, or your purchase history.
Report fraud. File a complaint with the FTC at identitytheft.gov and report any unauthorized activity to your bank or lender immediately.
Frequently Asked Questions
How do I know if I was affected? Long-Lewis Automotive Group has not yet notified affected customers. If you purchased a vehicle from any Long-Lewis dealership in Alabama, your personal and financial information may have been on the compromised systems. Do not wait for a letter. Speak with an attorney now.
What kind of information do auto dealerships store about me? When you purchase or finance a vehicle, dealerships typically collect your full name, address, date of birth, Social Security number, driver's license number, employment information, income, and financial account details. Each of those categories may have been compromised in this breach.
Can I file a lawsuit? If your information was compromised in the Long-Lewis data breach, you may have legal grounds for a claim. An attorney can evaluate your situation at no cost to you.
How long do I have to take action? Statutes of limitations vary by claim type. Do not delay. Contact an attorney as soon as possible to understand your options and protect your rights.
About Cory Watson Attorneys
Our data breach attorneys at Cory Watson Attorneys have been representing clients for more than 44 years, recovering over $4 billion for individuals whose rights were violated by institutional negligence. We handle data breach cases across Alabama and the Southeast, and our team is actively reviewing claims related to the Long-Lewis Automotive Group data breach.
Learn more about us and how we fight for clients.
Contact Cory Watson Attorneys today for a free case evaluation. There is no cost, no obligation, and no pressure.illion for clients. If you've received a notice or offer, contact us today for a free consultation or learn more about us.