McCarthy Tire Service Data Breach Exposes Employee and Customer Personal Information

Published: 17 September 2026
Automotive Technology data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: Not Publicly Disclosed

McCarthy Tire Service, a major East Coast commercial tire dealer, suffered a ransomware attack claimed by the Storm threat group, potentially exposing employee and customer personal data, including Social Security numbers and financial information. The exact number of people affected has not been publicly disclosed. Anyone who worked for or did business with the company should monitor their credit reports and consider a credit freeze immediately.

CompanyMcCarthy Tire Service
IndustryAutomotive Technology
Data Types ExposedFull Names, Social Security Numbers, Employment Records, Financial Account Information, Contact Information, Business and Vendor Records
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the McCarthy Tire Service Data Breach?

McCarthy Tire Service, a family-owned commercial tire and automotive service company based in Wilkes-Barre, Pennsylvania, has confirmed a ransomware attack on its computer systems. A threat actor group known as Storm has claimed responsibility for the intrusion. This means sensitive company and personal data may have been accessed without authorization.

According to available reporting, the breach discovery date has not been publicly disclosed. However, the Storm group’s involvement points to a targeted ransomware campaign rather than a random opportunistic attack. Ransomware groups like Storm typically infiltrate networks, extract data, and then deploy encryption tools while threatening to leak stolen files unless a ransom is paid.

As a result of the discovery, McCarthy Tire Service reportedly launched an internal investigation into the scope of the intrusion. Because forensic reviews take time, the exact timeline of unauthorized access has not yet been made public. In addition, the company has not confirmed how the attackers first gained entry into its systems.

Investigators typically work to determine which files were accessed, copied, or exfiltrated during incidents like this one. Until that forensic work concludes, the full extent of the exposure may remain uncertain. Meanwhile, affected individuals are left waiting for further updates from the company.

Who was affected?

The population affected by the McCarthy Tire Service data breach has not been publicly disclosed. Because the company operates more than 70 service locations across eight states on the East Coast, the breach could potentially touch a wide range of people. This includes current and former employees, as well as customers who have used its commercial tire and automotive services.

McCarthy Tire Service employs between 1,000 and 5,000 workers, according to available company data. This suggests that a significant number of employee records could be involved. In addition, because the company serves industries such as transportation, construction, agriculture, and forestry, business partners and vendors may also be impacted.

At this time, the exact number of affected individuals has not been publicly disclosed. As more information becomes available, that number may be updated by the company or through regulatory filings. Until then, anyone who has interacted with McCarthy Tire Service as an employee, customer, or vendor should stay alert.

What Information Was Potentially Exposed?

While the complete list of compromised data has not been made public, ransomware attacks like this one commonly involve theft of sensitive personal and business records. Because McCarthy Tire Service manages payroll, human resources functions, and customer accounts, several categories of information could be at risk.

  • Full names
  • Social Security numbers
  • Employment records
  • Financial account information
  • Contact information such as addresses and phone numbers
  • Business and vendor records

If Social Security numbers or financial account details were indeed part of the stolen data, affected individuals could face a heightened risk of identity theft. Criminals often use this type of information to open new credit lines, file fraudulent tax returns, or apply for loans in someone else’s name. This can cause lasting financial and emotional stress for victims.

In addition, exposed contact information could lead to an increase in targeted phishing attempts. Scammers frequently use breach data to craft convincing emails or text messages that appear to come from a trusted source. Because of this, affected individuals should treat any unexpected communication with caution, especially messages asking for personal details or payment.

What is the company doing?

In response to the attack, McCarthy Tire Service has reportedly begun working with cybersecurity professionals to assess the damage and secure its network. This typically includes isolating affected systems, removing malicious tools, and strengthening defenses to prevent further unauthorized access.

Furthermore, companies facing ransomware incidents like this one generally conduct a full forensic review before notifying affected individuals. This process helps determine exactly whose information was involved and what categories of data were taken. As that review continues, McCarthy Tire Service may issue formal notification letters to those impacted, along with guidance on protective steps.

Businesses that experience data breaches involving personal information often also offer credit monitoring or identity protection services to affected individuals. While it has not been confirmed whether McCarthy Tire Service will provide such services, this is a common practice following ransomware incidents of this scale.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone who believes they may be affected by the McCarthy Tire Service data breach should start by checking their credit reports regularly. This step helps you catch unauthorized accounts or unusual activity early. You can request free reports from the three major credit bureaus at AnnualCreditReport.com.

Because identity thieves often wait months before using stolen information, it’s important to keep checking your reports over time, not just once. If you notice unfamiliar accounts or inquiries, report them immediately to the credit bureau and consider filing a police report as well.

Consider a Fraud Alert or Credit Freeze

If Social Security numbers or financial account information were part of this breach, placing a fraud alert or credit freeze on your credit file is a smart precaution. A fraud alert requires lenders to verify your identity before opening new credit in your name. This can slow down or stop a thief from opening fraudulent accounts.

A credit freeze offers even stronger protection by restricting access to your credit file entirely. Although it requires a few extra steps when you need to apply for credit yourself, this option significantly reduces the risk of new-account fraud. You can request a freeze directly through each of the three credit bureaus at no cost.

Stay Alert for Phishing Attempts

Because contact information may have been exposed, affected individuals should watch for suspicious emails, texts, or phone calls. Scammers often pose as legitimate companies to trick victims into revealing more personal information. Never click on links or download attachments from unexpected messages.

Instead, verify any communication by contacting the company directly through a known, official phone number or website. This simple habit can prevent a lot of damage. If something feels off, trust that instinct and take extra time to confirm before responding.

Review Financial and Employment Accounts

Affected employees and customers should also review their bank statements, payroll records, and benefits accounts for any unusual activity. Because payroll systems often contain sensitive financial details, unauthorized changes to direct deposit information or tax withholdings could be a red flag.

If you notice anything unusual, report it to your HR department or financial institution right away. Additionally, consider setting up account alerts so you’re notified immediately of any changes or new activity. Early detection can make a significant difference in limiting potential damage.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

See the latest data breaches we're tracking →