July 26, 2026

I probably use my iPhone’s real, actual phone feature a lot more than the average person, being a journalist and all. I talk on the phone with people every day, and when an unfamiliar number flashes up on my phone screen, I usually pick up, assuming it has something to do with work.

Everyone outside of my industry I speak with seems to avoid talking on the phone altogether. I can understand why. Half the phone calls I get are just straight-up spam, with either an automated voice or someone trying to sell me something on the other end. If I didn’t have to use my phone for a living, I’d definitely just ignore any number that wasn’t saved in my contacts.

If you own an Alfa Romeo, Chrysler, Dodge, Jeep, Maserati, or Ram, you should probably do the same. Stellantis on Sunday announced that a third-party service provider that supports the company experienced a data breach, with hackers gaining unauthorized access to customer data, specifically contact information. According to a new report from BleepingComputer, up to 18 million records could have been stolen.

Stellantis’s brief statement from Sunday doesn’t really say much, other than letting the public know something happened and that it responded:

We recently detected unauthorized access to a third-party service provider’s platform that supports our North American customer service operations.

Upon discovery, we immediately activated our incident response protocols, initiated a comprehensive investigation, and took prompt action to contain and mitigate the situation. We are also notifying the appropriate authorities and directly informing affected customers.

2026 Ram 1500 Warlock 5.7 Liter Hemi® V 8 Etorque
Even if the caller ID says “Dodge,” don’t pick up. Source: Stellantis

The company goes on to say that only “contact information” was involved in the data breach, but doesn’t specify what sort of contact info or how many pieces of data were taken. These data points could be anything from names to phone numbers to email addresses. Importantly, Stellantis says no financial or “sensitive” personal information was accessed.

Then there’s this report from BleepingComputer, which claims to have actually talked to the hacker group behind the breach. From the piece:

Although Stellantis didn’t share more information regarding this attack, BleepingComputer has learned that it is part of a recent wave of Salesforce data breaches linked with the ShinyHunters extortion group, which has affected numerous high-profile companies.

Earlier today, ShinyHunters claimed responsibility for the Stellantis data breach and told BleepingComputer that they had stolen over 18 million Salesforce records, including names and contact details, from the company’s Salesforce instance.

A Stellantis spokesperson declined to comment when I reached out about the above claims.

The BleepingComputer report goes on to say that this string of data breaches, which has also affected brands like Google, Cisco, Farmers Insurance, and Workday, has been done through voice phishing attacks. Anyone who’s taken one of those silly corporate training courses has probably heard of this before. These attacks, sometimes known as “vishing,” use good old-fashioned audio calls to trick people into giving up information. Here’s how Bank of America describes it:

It usually comes as a phone call that sounds urgent or alarming. An unsolicited caller tells you your bank account has been compromised and that they need your PIN so they can verify your identity or unlock the account. Or they say they’re from a government agency, such as the IRS or the Social Security Administration. Sometimes they insist you owe money. Or they might announce you’re a lucky winner — but you’ll need to pay for shipping and handling to claim your prize.

[…]

One of the reasons these deceptions can be so convincing is that criminals can use personal information they’ve harvested from other sources to make a vishing attempt sound like an honest exchange. They also spoof phone numbers that belong to established organizations, which makes them appear legitimate on your caller ID. And they may lower your defenses with excellent imitations of call center professionals.

Pretty scary stuff. Stellantis is acutely aware of how someone’s contact info can be weaponized against them, so it’s told owners to be extra cautious:

We encourage customers to remain vigilant against potential phishing attempts and avoid clicking on suspicious links or sharing personal information in response to unexpected emails, texts, or calls. Customers with questions or who wish to verify communications, should contact Stellantis directly through official channels.

My recommendation? If someone calls you claiming to be a Chrysler Capital employee looking for this month’s loan payment, just hang up and call the place yourself to double-check things. That might sound rude, but better to be safe than sorry.

Top graphic images: Dodge; DepositPhotos.com

Support our mission of championing car culture by becoming an Official Autopian Member.

The post Do You Own A Dodge, Jeep, Or Ram? Be Careful About Who You Talk To On The Phone appeared first on The Autopian.

Read More

Leave a Reply

Your email address will not be published. Required fields are marked *