Lynx Ransomware Disrupts Gossett Motor Cars Operations

Incident Date: Jan 17, 2025

Attack Overview
VICTIM
Gossett Motor Cars
INDUSTRY
Retail
LOCATION
USA
ATTACKER
Lynx
FIRST REPORTED
January 17, 2025

Ransomware Attack on Gossett Motor Cars by Lynx Group

On January 22, 2025, Gossett Motor Cars, a prominent automotive dealership group based in Memphis, Tennessee, allegedly fell victim to a ransomware attack orchestrated by the notorious Lynx group. This incident has reportedly caused significant operational disruptions to the dealership, which is renowned for its extensive portfolio of automotive brands and commitment to customer satisfaction.

About Gossett Motor Cars

Founded in 1985, Gossett Motor Cars has grown to become the largest privately owned automotive group in the Mid-South Region. The company operates a network of dealerships representing brands such as Volkswagen, Porsche, Audi, and more. With an estimated annual revenue of $103.5 million and a workforce of approximately 285 employees, Gossett Motor Cars stands out for its comprehensive vehicle sales and service offerings. The company's dedication to quality and customer service has earned it an A+ rating from the Better Business Bureau.

Details of the Attack

The ransomware attack by Lynx has underscored the vulnerabilities faced by businesses in the retail sector. While specific details about the extent of data compromised or ransom demands remain undisclosed, the attack highlights the persistent threat posed by ransomware groups. The dealership's reliance on digital infrastructure for operations and customer interactions may have made it an attractive target for cybercriminals.

Profile of Lynx Ransomware Group

Lynx is a relatively new ransomware group that emerged in July 2024, quickly gaining notoriety for its aggressive tactics and double extortion methods. The group primarily targets small and medium-sized businesses across North America and Europe. Lynx employs a ransomware-as-a-service model, allowing other cybercriminals to utilize its ransomware for a fee. The group's technical sophistication, including the use of AES-128 encryption and process termination capabilities, distinguishes it in the cyber threat landscape.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.