ScrubaDub Auto Wash Centers Data Breach Exposes Passport Numbers and Driver’s License Information

Published: 6 September 2026
Retail data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

ScrubaDub Auto Wash Centers suffered a ransomware attack by the Akira group that exposed employee passport numbers, driver’s license numbers, and contact information for at least 22 employees, along with client contact details, company financials, and payment information. The company notified affected individuals in September 2026. Anyone affected should place a fraud alert or credit freeze immediately and monitor their credit reports closely.

CompanyScrubaDub Auto Wash Centers
IndustryRetail
Data Types ExposedPassport Numbers, Driver’s License Numbers, Employee Contact Information, Client Addresses and Contacts, Company Financial Records, Payment Details
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

What Happened in the ScrubaDub Auto Wash Centers Data Breach?

ScrubaDub Auto Wash Centers, a car wash chain operating more than 20 locations across Massachusetts, New Hampshire, Maine, and Rhode Island, has confirmed a ransomware attack on its computer systems. A group known as Akira has claimed responsibility for the intrusion. As a result, sensitive employee and client records may have been accessed by unauthorized parties.

According to available information, the breach discovery date has not been publicly disclosed. However, the company notified affected individuals in September 2026. The attackers reportedly gained access to internal systems and threatened to release stolen corporate files if their demands went unmet. This tactic, often called double extortion, pressures victims by combining data theft with the threat of public exposure.

Because ransomware groups like Akira typically infiltrate networks quietly before revealing themselves, the exact timeline of unauthorized access inside ScrubaDub’s systems remains unclear. In response, the company appears to have launched an internal investigation. Forensic specialists likely reviewed which systems were touched and which files were copied. This kind of review is standard practice after a confirmed ransomware event, since it helps determine the scope of exposure before notifications go out.

Who was affected?

The breach affects both employees and customers of ScrubaDub Auto Wash Centers. On the employee side, at least 22 individuals reportedly had passport numbers, driver’s license numbers, and contact information exposed. Meanwhile, client information, including addresses and contact details, also appears to have been accessed.

The total number of affected individuals has not been publicly disclosed. Because ScrubaDub operates across four New England states, the affected population likely spans a wide geographic area. In addition, the exposure of both workforce and customer data means this incident touches two very different groups with different risk profiles. Employees face identity document exposure, while customers may be more exposed through payment and contact details.

What Information Was Potentially Exposed?

The data categories connected to this breach are unusually sensitive for a retail-sector incident. Passport numbers and driver’s license numbers are government-issued identifiers that are difficult to replace and highly valuable to fraudsters. Combined with financial and contact data, the exposure creates multiple avenues for misuse.

  • Passport numbers (at least 22 employees)
  • Driver’s license numbers (at least 22 employees)
  • Employee contact information
  • Client addresses and contact details
  • Company financial records
  • Payment details

For the affected employees, the combination of passport and driver’s license numbers raises serious concerns. This is because these documents are commonly used to verify identity for loans, travel, and government services. As a result, criminals could attempt to open new accounts, apply for credit, or even impersonate victims when crossing borders.

For clients whose addresses, contacts, and payment details were exposed, the risk leans more toward phishing and financial fraud. Scammers often use stolen contact information to craft convincing messages that appear to come from a trusted business. Therefore, both employees and customers should watch for suspicious communications referencing ScrubaDub in the months ahead.

What is the company doing?

ScrubaDub Auto Wash Centers has acknowledged the ransomware attack and appears to be cooperating with the ongoing investigation. In response to the incident, the company reportedly began notifying affected employees and clients in September 2026. This notification process is a required first step under most state data breach laws.

Beyond notification, companies facing this type of extortion attempt typically work with cybersecurity firms to contain the threat and secure remaining systems. It is common for organizations in this situation to also review and strengthen network defenses to prevent repeat incidents. Additionally, businesses facing Akira-linked attacks often coordinate with law enforcement, since Akira has been tied to numerous ransomware cases nationwide.

What Should Affected Individuals Do?

Place a Fraud Alert or Credit Freeze

Because passport numbers, driver’s license numbers, and financial details were involved, affected individuals should strongly consider placing a fraud alert or credit freeze. A freeze restricts new creditors from accessing your credit file, which makes it much harder for identity thieves to open accounts in your name.

To set this up, contact each of the three major credit bureaus: Equifax, Experian, and TransUnion. Fraud alerts are free and last one year, while freezes remain in place until you lift them. Given the sensitivity of the exposed documents here, many affected individuals will find the extra protection worthwhile.

Monitor Your Credit Reports Closely

Regularly checking your credit reports is one of the simplest ways to catch fraud early. You are entitled to a free credit report from each bureau every year through AnnualCreditReport.com. Reviewing these reports lets you spot unfamiliar accounts or inquiries before they cause lasting damage.

In addition to annual reports, consider signing up for ongoing credit monitoring if it becomes available through ScrubaDub. Monitoring services can alert you quickly to new account openings or hard credit inquiries. This early warning can make a significant difference in limiting the damage from stolen identity documents.

Watch for Phishing Attempts

Since contact information was exposed for both employees and clients, phishing attempts are a realistic concern. Scammers often use real names and details to make fraudulent emails or texts look legitimate. Because of this, treat unexpected messages referencing ScrubaDub with caution, especially those asking for personal or payment information.

Never click links or provide information in response to unsolicited messages. Instead, verify any claimed communication by contacting ScrubaDub directly using official contact channels. This simple habit can prevent a secondary scam from compounding the original breach.

Protect Your Passport and Driver’s License Identity

If your passport number was exposed, contact the U.S. Department of State to ask about your options, since passport numbers cannot simply be changed like a password. Similarly, if your driver’s license number was compromised, contact your state’s motor vehicle agency to discuss reissuing your license or flagging your record for potential misuse.

These government-issued numbers are frequently used for identity verification elsewhere. Therefore, taking proactive steps with these agencies can reduce the chance that a stolen document number is used to impersonate you in other contexts, such as opening financial accounts or crossing international borders.

Consider Consulting a Data Breach Attorney

Given the sensitivity of passport numbers, driver’s license numbers, and financial data involved in this breach, affected individuals may want to speak with a data breach attorney. An attorney can help evaluate whether you qualify for compensation through a class action or individual claim.

Many attorneys who handle these cases offer free initial consultations. As a result, there is little downside to exploring your legal options, especially if you experience any signs of identity theft or fraud connected to this incident.



Related Data Breaches

Browse all recent data breaches →