LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Gossett Motor Cars Listed by lynx Ransomware Group

HIGH severityUnverified claimHow we verify

Gossett Motor Cars Listed by lynx Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 31, 2024
Gossett Motor Cars Listed by lynx Ransomware Group

Reported December 31, 2024.

HIGH
Severity
December 31, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Gossett Motor Cars was listed by the lynx ransomware group on December 31, 2024, after internal files were exfiltrated in a ransomware attack. Individuals connected to the company should check whether their information was exposed and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target mid-sized businesses across the United States, using data theft and public leak-site postings as leverage even when full operational details remain scarce. In this environment, a listing by the lynx ransomware group on December 31, 2024, has drawn attention to Gossett Motor Cars, a Tennessee-based automotive retailer. Public reporting indicates that internal files were claimed to have been exfiltrated, though the number of people affected and the precise contents of those files have not been confirmed.

The incident matters because automotive dealerships routinely handle sensitive personal and financial information belonging to customers and staff. When a ransomware group asserts it has taken internal files, the potential for later misuse or further exposure creates lasting uncertainty for anyone whose data may have been involved.

Inside the incident

According to available public information, Gossett Motor Cars was listed by the lynx ransomware group on December 31, 2024. The group claims that internal files were exfiltrated as part of a ransomware attack. No further technical details—such as the initial access method, the duration of any network intrusion, the volume of data taken, or whether systems were encrypted—have been disclosed in the reporting. The number of individuals potentially affected remains unknown. Public detail is limited to the fact of the listing itself and the assertion that internal files were removed from the company’s environment.

At the time of reporting, there has been no independent confirmation of the group’s claims beyond the appearance of the victim’s name on the leak site. Organizations in similar situations often face weeks or months of investigation before a fuller picture emerges, and that process is still ongoing or unreported here.

Inside lynx

Lynx is a ransomware operation that emerged in the public eye in 2024 and has since been observed conducting double-extortion campaigns. Like many contemporary groups, it typically gains access to a victim network, steals data, and then encrypts systems while threatening to publish the stolen material if a ransom is not paid. The group maintains a dark-web leak site where it posts the names of organizations it claims to have compromised, sometimes accompanied by sample files or countdown timers. Its tactics align with those of other mid-tier ransomware crews: opportunistic targeting of businesses that may lack mature security programs, use of common initial-access vectors such as phishing or exposed remote services, and reliance on public shaming to increase pressure.

Public reporting has linked lynx to multiple victims across manufacturing, professional services, and retail sectors. The group’s communications are generally concise and businesslike, focusing on the volume of data allegedly taken rather than elaborate political messaging. In the case of Gossett Motor Cars, the listing constitutes a claim by the group; no independent verification of the specific files or the success of any encryption has been published.

Who is Gossett Motor Cars?

Gossett Motor Cars is an automotive dealership group based in the Memphis, Tennessee area. Public statements from company leadership, including president Al Gossett, emphasize long-term customer and employee relationships and a family-oriented culture involving Al Gossett, his brother David, and son Brian. The business operates in the retail automotive sector, selling new and used vehicles and providing related services such as financing, service, and parts.

Dealerships of this type typically maintain extensive records: customer contact details, driver’s license information, credit applications, vehicle identification numbers, service histories, employee payroll data, and internal financial documents. A breach involving internal files therefore carries consequences beyond the immediate operational disruption, because the data held is both personal and commercially sensitive. The company’s stated commitment to treating customers and staff with respect underscores why any unauthorized access to those records is particularly consequential for the people who trust the organization with their information.

What data was at risk

The only data type named in public reporting is “internal files” said to have been exfiltrated in a ransomware attack. No inventory of specific file categories, record counts, or data elements has been released. Organizations in the automotive retail sector commonly store customer personally identifiable information, financial application data, employee records, and proprietary business documents. Whether any of those categories were among the files claimed by lynx remains unconfirmed. Public detail is limited, and the exact contents of the material the group asserts it possesses have not been independently verified.

Why it matters

For individuals whose information may have been among the internal files, the practical risks include identity theft, targeted phishing, and unauthorized use of financial or vehicle-related data. Even if the files prove to be largely operational rather than customer-facing, residual exposure of employee or partner information can still create long-term monitoring burdens. For Gossett Motor Cars itself, the incident raises questions of operational continuity, potential regulatory notification obligations, and reputational impact among customers who expect their personal details to remain protected.

Because the scale of the claimed exfiltration is unknown, the full scope of downstream harm cannot yet be measured. What is clear is that ransomware listings of this kind rarely resolve quickly; data that has left an organization’s control can resurface months later on criminal markets, extending the period of risk for anyone affected.

Were you affected?

If you have done business with Gossett Motor Cars or are a current or former employee, treat the possibility of exposure seriously until more information becomes available. Monitor financial accounts and credit reports for unexpected activity, be cautious of unsolicited communications that reference the dealership or vehicle purchases, and consider placing a fraud alert with the major credit bureaus. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Any official notifications from the company should be read carefully and acted upon promptly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyGossett Motor Cars security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Gossett Motor Cars’s full breach history →

More recent breaches

bayareaherbs.com Listed by lynx Ransomware GroupMay 10, 2026funkychunky.com Listed by lynx Ransomware GroupMay 10, 2026www.blackdogsalvage.com Listed by lynx Ransomware GroupJanuary 5, 2026americanhome Listed by lynx Ransomware GroupOctober 7, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Gossett Motor Cars Listed by lynx Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by lynx — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram