Skip to content

Intoxalock cyberattack and nationwide service outage

Summary

Intoxalock logo

A March 14 cyberattack led Intoxalock to pause systems supporting installations, calibrations, account access and service centers across its nationwide network. Some drivers could not start their vehicles, and two named shops reported blocked work; Intoxalock said core services resumed March 22. State agencies addressed compliance consequences, but no agency outage was documented, and ransomware, attribution and data theft remain unconfirmed.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Transaction processing disruption

    Business, financial, customer, administrative, or operational transactions could not be completed normally.

  • Scheduling disruption

    Appointment, booking, reservation, dispatch, staffing, or other scheduling functions were unavailable or impaired.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Third-party service disruption

    The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Intoxalock experienced a confirmed cyberattack that materially disrupted its nationwide service network beginning March 14, 2026. Intoxalock’s official status chronology said it was investigating a cybersecurity event affecting its ability to service customers and had paused systems as a precaution. A company spokesperson later confirmed the cyberattack to TechCrunch.

The attack affected Intoxalock’s service infrastructure rather than disabling every installed ignition-interlock device. Intoxalock said devices remained operational, but systems needed for installation, calibration, removal, account access and service-center support were unavailable or restricted. Drivers whose vehicles required calibration or related service could face delayed starts or lockouts even though the device itself continued performing its alcohol-testing function.

Operational significance

Intoxalock operates through a service-center network spanning 46 states. The system pause blocked new installations and disrupted calibrations, removals, account access and service-center transactions. Drivers reported vehicles that would not start, towing needs, lost work and concern about court or licensing compliance. Intoxalock offered reimbursement for qualifying towing costs and developed a 10-day device-extension workaround where state authorities permitted it. Eligibility varied by state and during the response.

Independent reporting directly documents blocked work at two downstream service businesses. WCVB reported that Juniors Automotive Sales and Service Inc. in Middleborough, Massachusetts, had vehicles sitting at the shop because technicians could not complete Intoxalock recalibrations. WMUR reported that blocked Intoxalock service-center computers prevented Guillermo Auto Repair LLC in Manchester, New Hampshire, from doing affected work and hurt the business financially.

Evidence for Baldwin Electronics is narrower. Cybernews reported that the Odessa, Texas, service center publicly asked Intoxalock what it should tell customers about towing and lockout expenses. That supports a downstream relationship and an Odessa connection, but it does not establish that Baldwin’s own systems were unavailable or that its work stopped. The incident’s Odessa impacted-location confidence is therefore medium. None of the three businesses is known to have been a direct cyber victim.

Government-program effects

State agencies had to address compliance consequences because Intoxalock devices are used in court- and licensing-mandated programs. This does not mean agency networks or public services were disrupted. Massachusetts’ Registry of Motor Vehicles authorized a 10-day extension window for eligible customers after an initial delay. The Oklahoma Board of Tests for Alcohol and Drug Influence said it did not operate or control the vendor’s devices or systems, instructed participants to document contact and service attempts, and said compliance would be evaluated case by case under applicable law. No reviewed agency notice reported that an agency system was compromised or unavailable.

Disclosure posture

Intoxalock first used concrete cyber-specific wording March 15, the day after the company says the event began. Because the affected organization publicly characterized the event before any identified external actor claim, the disclosure sequence supports OC. The documented nationwide interruption to customer and service-center functions supports OD.

The company’s updates described precautionary isolation, customer accommodations and staged recovery. They did not identify an attack vector, responsible actor or malware family. TechCrunch reported that Intoxalock would not say whether ransomware or a data breach occurred or whether it received ransom communications.

Current status

Intoxalock said at 5:30 p.m. EDT March 22 that installations, calibrations and service-center support had resumed and service centers were fully operational. A later Tennessee transition deadline addressed compliance after restoration; it does not establish continuing system unavailability. The incident is therefore classified as resolved, with March 22 retained as the last documented operational-impact date. Recovery does not establish when malicious activity ended, so the attack’s technical end date remains unknown.

Confidence and uncertainty

Confidence is high that a cyberattack caused the service disruption because Intoxalock used cyber-specific wording and its spokesperson confirmed the attack. Confidence is also high that the outage affected drivers and service businesses across multiple states, though public evidence does not establish that all customers or all service centers were affected at once. Connecticut Public reported an Intoxalock estimate of about 6,000 Connecticut customers, with 7% to 10% needing calibration during the disruption.

Ransomware and threat-actor attribution remain unresolved. No stable ransomware or extortion victim claim was identified. A proposed class action reported by KCCI alleges that attackers stole data and that customers suffered vehicle, towing, employment and financial effects. Those assertions remain allegations and do not independently establish data acquisition or the full scope of impact. No public forensic report or breach notice reviewed for this assessment confirms what information, if any, was accessed or taken.

Analytic gaps

The public record does not establish the initial access vector, compromised account or host, exploited vulnerability, attacker dwell time, persistence, lateral movement, command-and-control infrastructure, encryption activity or exact systems isolated. It also does not identify a ransomware family, responsible actor, ransom demand, negotiation, payment or public data release.

The record does not establish whether data was accessed, acquired, altered, encrypted or deleted; which records or people may have been affected; or whether notification obligations were triggered. The full number of drivers, service centers and transactions affected nationwide is also unknown.

Organizations involved

Impacted locations

Sources

Iowa-based Intoxalock cyberattack disrupts calibration service

A cybersecurity event beginning March 14 caused systemwide calibration downtime and service delays for ignition-interlock customers nationwide.

Intoxalock Status Center

Intoxalock’s status chronology says a cybersecurity event beginning March 14 affected its ability to service customers. It documents the precautionary system pause, state-dependent temporary extensions and the March 22 restoration of installations, calibrations and service-center support.

Intoxalock service disruption

The Oklahoma board said it had received reports of nationwide service disruption affecting certain Intoxalock devices and related systems. It said it did not operate or control the vendor systems, instructed participants to document contact and service attempts, and said compliance would be evaluated case by case under applicable law.

Cyberattack on Intoxalock affects New Hampshire drivers, businesses

WMUR quoted Guillermo Auto Repair owner Juan Jimenez saying Intoxalock blocked service-center computers during the response, preventing affected work and hurting the Manchester shop’s revenue.

Cybersecurity issue affects Intoxalock breathalyzers

WCVB quoted Juniors Automotive owner George Damato saying vehicles had been parked at his Middleborough shop all week because technicians could not complete Intoxalock recalibrations. Massachusetts authorized a 10-day extension window for eligible customers.

Cyberattack on vehicle breathalyzer company leaves drivers stranded across the US

TechCrunch reported that an Intoxalock spokesperson confirmed a cyberattack and a precautionary pause of company systems. The company did not answer whether ransomware or a data breach occurred or whether it received ransom communications.

CT drivers caught up in cyberattack on breathalyzer company

Connecticut Public reported an Intoxalock estimate of about 6,000 Connecticut customers, with 7% to 10% needing calibration during the disruption. It reported that company systems resumed March 22.

Intoxalock resumes service following cyberattack

Intoxalock said installations, calibrations and service-center support resumed March 22 after the cyber event.

Intoxalock restores service after hack left drivers unable to start cars across 46 states

Cybernews reported broad customer and service effects and preserved Baldwin Electronics’ public request for guidance about customers facing towing and lockout costs. The request supports a downstream connection but does not establish an outage at Baldwin. Cybernews also reported Intoxalock’s March 22 restoration of service-center systems.

Class-action lawsuit filed against Iowa maker of ignition interlock devices

KCCI reported that a proposed class action alleges attackers stole data and that customers experienced vehicle, towing, employment and financial effects. The assertions are allegations and do not independently establish data acquisition or the full scope of impact.

Terms of use

Intoxalock’s terms identify Consumer Safety Technology LLC as the service operator within the Mindr family and list a current legal address in Urbandale, Iowa.

Baldwin Electronics official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

Guillermo Auto Repair LLC official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

See something that needs correction?

Signed-in members can report an error, update, or missing source.