SovCali Threatens 100GB Lucid Motors Data Leak After Vendor Breach

SovCali ransomware is threatening to release another 100 GB of alleged Lucid Motors engineering data after the automaker confirmed a vendor cybersecurity incident.
SovCali ransomware data leak site showing Lucid Motors entries, including a 35 GB engineering data leak and a threat to release another 100 GB.
SovCali's Tor data leak site shows multiple Lucid Motors entries, including an alleged 35 GB engineering data release and a threat to publish another 100 GB. Screenshot: BreachNews

SovCali ransomware has escalated its extortion campaign against Lucid Motors, threatening to publish another 100 GB of allegedly stolen engineering data within 2 days after the electric vehicle maker confirmed a cybersecurity incident involving one of its vendors.

The latest threat follows SovCali’s claim that it obtained approximately 5 TB of engineering data associated with Lucid vehicle development. The ransomware group has already claimed to have released approximately 35 GB of technical material as proof of the alleged theft.

Lucid has not publicly attributed the incident to SovCali or confirmed the group’s claimed 5 TB data theft. The company has, however, confirmed that a vendor experienced a cybersecurity incident and said it is working with investigators and law enforcement to protect its intellectual property.

SovCali threatens another 100GB release

In a new message posted Aug. 28, SovCali claimed Lucid had been given sufficient time to respond but had failed to take what the ransomware group considered appropriate action.

SovCali said it intends to issue another update within 2 days and publish an additional 100 GB of data. The group did not specify exactly what the threatened release would contain.

The announcement marks another escalation in an extortion campaign that appears primarily focused on proprietary engineering material rather than customer information.

SovCali previously claimed it wanted to negotiate directly with Lucid and threatened to make the allegedly stolen information available to competitors if an agreement was not reached.

Lucid confirms cybersecurity incident at vendor

Lucid publicly acknowledged the incident on Aug. 21, confirming that one of its vendors had suffered a cybersecurity incident and that the automaker was working with the vendor to contain and investigate the matter.

In an official statement, Lucid said its review determined that the affected vendor did not have access to customer data or information that could be used to interfere with the operation of its vehicles or core business.

Lucid also said its retail and production activities were unaffected by the incident.

The automaker said it is working with investigators and law enforcement to identify those responsible, protect its intellectual property and pursue available civil and criminal remedies.

Lucid did not identify the affected vendor or attribute the incident to SovCali in its statement.

SovCali claims 5TB engineering archive

SovCali claims to have exfiltrated approximately 5.08 TB of engineering data associated with Lucid’s Gravity and midsize vehicle programs. The ransomware group says the archive contains more than 56,000 files spanning approximately 2023 through 2025.

According to SovCali, the allegedly stolen archive includes:

  • 3D CAD models and assemblies
  • Finite element analysis and simulation files
  • Structural and vibration analysis results
  • Computational fluid dynamics simulations
  • Engineering presentations and reports
  • Manufacturing and design trackers
  • Bill of materials information
  • Design and validation documentation

The group claims the engineering material covers vehicle components including advanced driver-assistance system mounting hardware, protective covers, LiDAR cleaning systems, display housings, headlamp components and structural and noise, vibration and harshness analyses.

SovCali attributes the archive to engineering work involving Lucid and eShocan, an engineering services company involved in automotive product development and engineering simulation.

Lucid’s statement confirms that a vendor suffered a cybersecurity incident but does not publicly identify eShocan as that vendor. BreachNews therefore cannot independently confirm that eShocan is the vendor referenced by Lucid.

35GB allegedly released as proof

On Aug. 23, SovCali claimed to have published approximately 35 GB of technical material as evidence that it possessed Lucid-related engineering data.

The group described the release as containing finite element analysis and computer-aided engineering material, including model files, simulation results and accompanying presentation and spreadsheet reports.

According to SovCali, the released material includes engineering work involving stiffness studies, strain-energy evaluations, displacement assessments and noise, vibration and harshness analysis of vehicle components.

BreachNews is not linking to or distributing the allegedly stolen engineering files.

The staged publication appears designed to increase pressure on Lucid rather than immediately expose the entire archive SovCali claims to possess. The group has progressively threatened larger disclosures while continuing to push for negotiations.

Intellectual property at center of extortion campaign

The potential impact differs from a conventional customer data breach. Lucid has specifically confirmed that the affected vendor did not have access to customer information or data capable of interfering with its vehicles or core business.

Instead, the material described by SovCali centers on proprietary automotive engineering and development work.

If the group’s description of the archive is accurate, detailed CAD models, simulation results, design documentation and engineering analyses could expose information about how Lucid vehicle components were designed, tested, optimized and prepared for manufacturing.

SovCali has attempted to use the potential competitive value of that intellectual property as leverage, previously threatening to offer the information to competitors if negotiations failed.

The group’s latest threat raises the prospect of significantly more material becoming public. SovCali says another 100 GB will be released within 2 days, although BreachNews has not independently verified the claimed volume of stolen data or established what the next release would contain.

Lucid had not issued a further public statement addressing SovCali’s Aug. 28 threat at time of publication.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site