Intoxalock
Incident posture
Linked entities
- Victim
- Intoxalock
- Threat actors
- 0 actors
- Sources
- 3 sources
Timeline
Summary
Intoxalock, a provider of ignition interlock devices for court‑ordered alcohol monitoring, suffered a cyberattack that disrupted its servers and prevented its breathalyzer units from communicating for calibration, leaving many users unable to start their vehicles. The outage led to stranded drivers, towing expenses, lost wages and reports of spam communications after personal data were allegedly accessed. Affected users filed federal lawsuits claiming the company failed to implement reasonable security measures such as encryption, multifactor authentication and timely patching, and sought class‑action status for damages related to property loss, income loss and breach of contract. In response, the company requested a stay of litigation while it conducts an incident response investigation to determine the scope of the breach and the number of impacted customers, noting that settlement talks cannot proceed until those details are known.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On March 14, 2026, cybercriminals attacked Intoxalock’s systems, disabling critical network infrastructure and causing the company to experience downtime. Intoxalock announced on its website that its systems were currently experiencing downtime after the cyberattack. A spokesperson confirmed the cyberattack and said the company had temporarily paused some systems as a precautionary measure. Intoxalock’s breathalyzer devices require periodic calibrations that need a connection to the company’s servers, and the outage prevented those calibrations from being performed. As a result, drivers across the United States reported being unable to start their vehicles, with lockouts reported from New York to Minnesota and in states such as Maine. One auto shop in Middleboro noted that cars remained parked in its lot all week due to the issue. Derrick Curry of Worth, Illinois, alleged that while driving his vehicle home, the car suddenly shut off on a city street, forcing him to have it towed at a cost exceeding seven hundred dollars. The next day his Intoxalock device remained nonfunctional, causing him to miss a day of work and subsequently lose his job. He later paid three hundred dollars to have the vehicle towed to the original installer so the device could be removed. Curry also said he began receiving an alarming number of spam emails and spam calls and learned that someone had applied for a loan using his credentials.
Intoxalock responded by offering ten‑day extensions on required calibrations and providing towing services in some cases. The company did not disclose the type of cyberattack, whether it involved ransomware, if a data breach occurred, or whether it had received any communications from the attackers. In March 2026, Derrick Curry and four other individuals filed federal lawsuits against Consumer Safety Technology, which does business as Intoxalock, in the U.S. District Court for the Southern District of Iowa. A similar lawsuit was later filed by Robert Million of Crystal, Minnesota. The plaintiffs allege that Intoxalock failed to properly secure its information technology network and to implement reasonable cybersecurity measures such as data encryption, multifactor authentication, and updated software patches. They claim these alleged shortcomings allowed unauthorized third parties to hack the system, disable ignition interlock devices, and steal information maintained by the company. The lawsuits state that the outage left countless users unable to use their vehicles for over a week and caused losses of property, vehicle use, and wages. Each suit seeks class‑action status so that one case can represent all affected users, with plaintiffs’ attorneys estimating the impacted class to be in the tens of thousands. The initial five lawsuits were consolidated into a single case and, on the Thursday preceding July 31, 2026, a federal judge issued a stay of the proceedings. The stay was granted at Intoxalock’s request to allow the company to complete an extensive incident response investigation aimed at determining the full scope of the data breach and the number of customers affected.
Intoxalock describes itself as the leading ignition interlock device company in Iowa, with 177 installation locations across the state. The company’s technology is used in forty‑six states and it says it provides services to approximately one hundred fifty thousand drivers each year. Intoxalock has stated that it is open to engaging the plaintiffs and their counsel in early class‑action settlement discussions. However, the company maintains that any settlement talks are hampered by the ongoing investigation, because without knowing the impacted class size or the specific data elements compromised, the parties cannot participate in informed negotiations. As of the latest available information, Intoxalock has not provided an estimated timeline for restoring full service or disclosed further details about the attack’s nature or outcome.
Sources
Sources available to members: 3 sources.