LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Lucidmotors Listed by Sovcali Ransomware Group

HIGH severityUnverified claimHow we verify

Lucidmotors Listed by Sovcali Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 8, 2026

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Lucidmotors Listed by Sovcali Ransomware Group

Reported August 8, 2026.

HIGH
Severity
August 8, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Lucidmotors has been listed by the Sovcali ransomware group, with the incident disclosed on 8 August 2026. An undisclosed number of individuals may have had personal data exposed; affected persons are advised to check the company’s notices and take protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

When a company that designs and builds electric vehicles appears on a ransomware group's listing, the immediate concern for customers, employees, and partners is straightforward: what information may now be outside the organisation's control, and what does that mean for the people connected to it. Public detail on this incident remains limited, but the claim itself is enough to warrant careful attention.

On August 08, 2026, Lucidmotors was listed by the Sovcali ransomware group. The group claims that a large engineering archive belonging to Lucid Motors and eShocan is available. The number of people affected is unknown, and the precise categories of personal data, if any, have not been independently confirmed. For anyone who has dealt with the company as a customer, employee, supplier, or collaborator, the practical question is whether their own information could be mixed into what the group says it holds.

Breaking down the breach

What is publicly reported is a leak-site listing rather than a fully verified forensic account. According to the reported summary associated with the listing, Sovcali claims that the complete engineering archive of Lucid Motors and eShocan is now available, described as 5.078 terabytes of material. That material is said to include CATIA and STEP models, FEA and NVH analyses, multi-gigabyte CFD simulations of a LiDAR washing system, topology optimization studies, static and modal results for the Gravity and Midsize enclosures, bills of materials (BOMs), and internal progress reports.

No independent confirmation of the intrusion method, the exact date of any intrusion, or the full scope of systems involved has been provided in the available facts. The number of individuals whose personal information might be implicated is listed as unknown. Data types beyond the engineering materials named in the group's claim are not disclosed. In short, the incident is known primarily through the group's assertion and the accompanying description of technical files; other operational details remain undisclosed.

The group behind it: Sovcali

Sovcali is presented in connection with this incident as a ransomware group that lists organisations on a leak site and claims to hold stolen data. Like other groups that follow this model, such actors typically encrypt systems or exfiltrate data and then pressure victims by threatening or carrying out public release. Listings on these sites are claims by the group; they are not the same as confirmed, independently audited disclosures.

Public reporting on ransomware operations in general shows that groups often publish sample files or volume figures to increase pressure, and that the contents they advertise can range from intellectual property to internal documents and, in some cases, personal data. Nothing in the available facts establishes that Sovcali has been independently verified as having successfully compromised Lucidmotors beyond the group's own listing. Readers should treat the description of the 5.078-terabyte archive and its contents as the group's claim unless and until further confirmation appears.

About Lucidmotors

Lucidmotors, commonly known as Lucid Motors, is an electric-vehicle manufacturer. Companies in this sector design, engineer, and produce passenger vehicles and related technology. They typically hold extensive engineering and design data, supplier and manufacturing information, employee records, and customer information tied to sales, service, and connected-vehicle features.

A breach involving an organisation of this kind is consequential for two reasons. First, vehicle engineering data can include proprietary designs, simulation results, and bills of materials that competitors or other parties might misuse. Second, automotive companies often maintain personal and commercial data about buyers, employees, and partners. Even when a listing emphasises engineering archives, the possibility that other categories of information were also taken cannot be ruled out when public detail is incomplete. The involvement of eShocan in the claimed archive, as stated in the group's summary, further suggests that engineering or supplier-side material may be part of what is being advertised.

The information in question

The facts state that data types named as exposed are not disclosed in a formal inventory sense. What is available is the group's claimed description: a large volume of engineering files, including CAD-related models (CATIA and STEP), structural and noise-vibration-harshness analyses, computational fluid dynamics simulations, topology studies, results related to Gravity and Midsize enclosures, BOMs, and internal progress reports, totaling a claimed 5.078 terabytes.

Organisations in the electric-vehicle sector commonly hold design intellectual property, manufacturing and supplier data, employee information, and customer records. None of those broader categories should be treated as confirmed contents of this incident. The exact mix of what, if anything, left Lucidmotors' control remains unconfirmed beyond the engineering materials the group asserts it possesses. Personal data exposure, if it occurred, has not been detailed in the available reporting.

The real-world impact

For the organisation, the claimed loss of engineering archives raises risks around intellectual property, competitive position, and the integrity of product-development processes. Design files, simulation results, and BOMs can be sensitive even when they do not contain names or contact details. Internal progress reports may reveal timelines, priorities, or unresolved technical issues.

For individuals, the picture is less clear because the number of people affected is unknown and personal data types are not confirmed. If employee, customer, or partner information was included in any wider set of taken files, typical risks would include unwanted contact, phishing that references real relationships with the company, or misuse of identity-related details. At present those outcomes are possibilities rather than established facts. The primary documented claim centres on engineering material; any personal impact depends on whether additional data was involved—an open question given the limited public detail.

If your data was in this breach

If you have a relationship with Lucidmotors as a customer, employee, or partner, treat the listing as a signal to tighten ordinary defences rather than as proof that your personal information is already public. Use unique passwords, enable multi-factor authentication on email and financial accounts, and be cautious of unexpected messages that reference the company or vehicle ownership. Monitor financial and account activity for unusual behaviour. Because Reported Details about personal data in this incident are lacking, avoid assuming the worst while still taking basic precautions.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step will not prove or disprove involvement in this specific incident, but it can show whether your address appears in other publicly tracked breaches and help you prioritise further protective measures.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyLucidmotors security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Lucidmotors’s full breach history →

More recent breaches

Louisville Bar Association Listed by Inc Ransom Ransomware GroupAugust 8, 2026Daily Trust Listed by Panzer Ransomware GroupAugust 8, 2026Barclay Damon Listed by Leakeddata Ransomware GroupAugust 8, 2026Sandberg Phoenix Listed by Leakeddata Ransomware GroupAugust 8, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Lucidmotors Listed by Sovcali Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by sovcali — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram