Skip to main content
Back to overview
High

Industrial Acceptance Corporation (IAC) Suffers Data Breach

Industrial Acceptance Corporation (IAC), an automotive financing company, became aware of suspicious activity on its computer network on February 24, 2025.

Key points

  • Suspicious activity detected on February 24, 2025.
  • Cybercriminals infiltrated the network and exfiltrated files.
  • 79,216 individuals affected.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Feb 24, 2025
Updated
Jun 26, 2026
Confidence
High
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

IacData DisclosureIndustrial Acceptance CorporationIACCorporationINCSuspiciousCybercriminals

Quick context

Questions about this signal

What happened in this signal?

Industrial Acceptance Corporation (IAC), an automotive financing company, became aware of suspicious activity on its computer network on February 24, 2025. A subsequent forensic investigation determined that cybercriminals infiltrated the network and gained access to and removed files containing the sensitive personal information of 79,216 individuals. The exposed data included names, Social Security numbers, and driver's license numbers. The incident was later attributed to the INC ransomware group, with files exfiltrated around March 4, 2025. IAC began notifying affected individuals in May 2026 and offered complimentary credit monitoring services.

When was this signal reported?

Shadow Tier lists Feb 24, 2025 as the signal date.

Which organization is connected to this signal?

Iac is the organization connected to this public signal.

Explore Iac
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence