Stellantis Data Breach Class Action: Spadafore Suit and Prior Hack

The Stellantis class action data breach lawsuit, Spadafore v. FCA US LLC, was filed in Michigan federal court in January 2026 over a Christmas Day 2025 ransomware attack that exposed Chrysler customers’ Social Security numbers and other personal information. The plaintiffs voluntarily dismissed the case on May 20, 2026, roughly four months after filing, and no settlement or claims process has been announced.1Law360. Carmaker Beats Suit Over Christmas Data Breach Claims

What Was Stolen in the Christmas 2025 Breach

On or around December 25, 2025, a ransomware group called Everest claimed it had breached Chrysler’s internal systems and taken about one terabyte of data.2Hackread. Everest Ransomware Group Chrysler Data Breach The stolen information reportedly included customer names, phone numbers, physical addresses, dates of birth, and Social Security numbers.3Top Class Actions. Stellantis Hit With Class Action Over Alleged Data Breach Affecting Chrysler Customers The haul also reached CRM records with customer interaction logs, vehicle details, and recall case notes.

Everest posted the breach on its dark web leak site on December 26, 2025. According to the complaint, Stellantis refused to pay the ransom, and the group published the stolen data online on January 4, 2026.4ClassAction.org. Spadafore et al. v. FCA US LLC, Complaint A database tracking site reported the leak contained roughly 1.75 million rows, including approximately 1.8 million unique email addresses and 262,900 unique phone numbers.5DataBreach.com. Chrysler 2025 Data Breach

What the Lawsuit Alleged

Loria and Thomas Spadafore, a married couple from Illinois, filed the proposed class action on January 21, 2026, in the U.S. District Court for the Eastern District of Michigan.3Top Class Actions. Stellantis Hit With Class Action Over Alleged Data Breach Affecting Chrysler Customers The complaint alleged Stellantis failed to implement basic cybersecurity protections and pointed to specific gaps:

  • Sensitive customer data allegedly stored without encryption
  • No multi-factor authentication in place
  • No strong password requirements for system access
  • Retention of personally identifiable information long after any business need
  • No secure backups of data

The plaintiffs argued these failures put Stellantis out of compliance with the NIST Cybersecurity Framework and the Center for Internet Security’s Critical Security Controls.4ClassAction.org. Spadafore et al. v. FCA US LLC, Complaint

The complaint brought five causes of action: negligence (including alleged noncompliance with Section 5 of the FTC Act), breach of fiduciary duty, breach of implied contract, unjust enrichment, and violations of the Illinois Consumer Fraud and Deceptive Business Practices Act. The Spadafores sought to represent a nationwide class of everyone in the United States whose personal information was exposed in the breach, along with a separate Illinois subclass, and asked for compensatory, statutory, and punitive damages, plus injunctive relief requiring stronger data security. The complaint stated the amount in controversy exceeded $5 million.4ClassAction.org. Spadafore et al. v. FCA US LLC, Complaint

Where the Case Stands

The case did not progress far. On May 20, 2026, the plaintiffs filed a notice of voluntary dismissal, effectively dropping the lawsuit.1Law360. Carmaker Beats Suit Over Christmas Data Breach Claims The publicly available record does not show any substantive ruling before dismissal, and no settlement or claims process has been announced. A voluntary dismissal does not necessarily mean the underlying claims lack merit; plaintiffs sometimes refile with stronger allegations, consolidate with other cases, or reach private resolutions.

For now, there is no active class action a Chrysler customer can join over the Christmas 2025 breach. Anyone whose information may have been exposed should watch for phishing attempts and identity theft signs, since Social Security numbers and dates of birth were reportedly among the data published online.

A Separate Earlier Breach

The Christmas Day attack was the second publicly known Stellantis breach in a matter of months, and the two are often confused. In September 2025, Stellantis disclosed that a different group, ShinyHunters, had accessed a third-party platform used for North American customer service and claimed to have taken over 18 million customer records from the company’s Salesforce instance, a figure Stellantis did not confirm.6BleepingComputer. Automotive Titan Stellantis Confirms Data Breach After Salesforce Hack Stellantis characterized that earlier incident as limited to “basic contact information” and said it did not involve financial details or sensitive personal data.7CBC News. Stellantis Data Breach North America The Spadafore lawsuit concerned only the December ransomware attack, not the September incident.