New group Sovcali claims Lucid Motors breach
An emerging extortion group called Sovcali claims to have stolen 5TB of Lucid Motors and eShocan engineering data, including CAD, FEA, and CFD files.
Ransomware.live has catalogued a new, previously unseen extortion group calling itself Sovcali, which surfaced on August 9, 2026, claiming an intrusion against electric-vehicle maker Lucid Motors and partner firm eShocan Engineering with an estimated attack date of August 4, 2026. The group claims possession of a 5.078TB engineering archive containing CATIA and STEP CAD models, FEA and NVH analyses, CFD simulations of a LiDAR washing system, topology optimization studies, structural/modal results for the Gravity and Midsize vehicle enclosures, bills of materials, and internal progress reports.
The listing also enumerates a substantial exposed footprint: one compromised employee account, 226 compromised user records, 19 sets of third-party employee credentials, and 30 external attack-surface findings, alongside extensive SaaS/DNS metadata (Salesforce, SAP SuccessFactors, Box, DocuSign, Mimecast, Stripe, Wiz, LucidLink, and others) tied to the victim domain — none of which constitute malicious infrastructure, but which indicate broad reconnaissance of the target's identity and cloud ecosystem.
As Sovcali is a newly discovered group with no independently verified track record, the claim should be treated with caution pending corroboration. No malware family, exploited vulnerability, or specific intrusion technique is disclosed in the listing, and no confirmed data leak beyond a screenshot has been independently validated at this time.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/THVjaWRtb3RvcnNAU292Y2FsaQ==
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free