SYS::ONLINE
Wasteland.
Briefs2260
Issues25
SinceFeb 2026
LIVE
▣ Breach PREFERRED-PARKING- 2026-08-26

Preferred Parking: Unauthorized Actor Steals Customer Payment Card Data

"Preferred Parking Service, LLC, the Charlotte-based operator that manages parking lots, garages, permitting and violation processing across the Southeast, has confirmed that an unauthorized actor accessed its customer…"

Preferred Parking Service, LLC, the Charlotte-based operator that manages parking lots, garages, permitting and violation processing across the Southeast, has confirmed that an unauthorized actor accessed its customer database in June 2026 and took files containing names and payment card information. State filings put the nationwide total at 72,912 people, of whom 61,335 are North Carolina residents, a figure the office of N.C. Attorney General Jeff Jackson confirmed to the Charlotte Observer. Company owner and president Roger Stacks told the Observer that Preferred Parking "worked with outside experts to help us investigate, notified those whose information may have been involved and took additional measures to fortify our IT network."

A note on sourcing before anything else: every account of this incident currently in circulation is secondary. There is no published victim statement beyond the quotes given to the Observer, no CERT advisory, and no vendor report. Vermont, which received one of the notification filings, no longer publishes the underlying notification letters, as Class Action U points out. What follows is assembled from state regulator confirmations relayed through regional press, and the numbers should be read with that caveat attached.

What Happened

According to the notification letter quoted by the Charlotte Observer, an "unauthorized actor" gained access to Preferred Parking's database on June 7 and 8, 2026. The company's investigation into the intrusion concluded on July 30, the date on which, per Queen City News, Preferred Parking finished reviewing the affected files and determined exactly who was impacted. Notifications went out to affected North Carolina residents on August 14, the same day the company filed with regulators in South Carolina, Massachusetts and Vermont.

That timeline means roughly nine weeks elapsed between intrusion and victim notification, and about two weeks between the completion of the forensic review and the notices going out.

The state-by-state breakdown reported by the Observer and echoed by Hoodline: 61,335 in North Carolina, 5,176 in South Carolina, 142 in Massachusetts and 11 in Vermont. Hoodline reports that Preferred Parking also listed additional information for residents of Connecticut, Maryland, New York, Rhode Island, West Virginia and the District of Columbia, though no counts for those jurisdictions have surfaced.

Figures vary slightly by source and by publication date. The Charlotte Ledger, which broke the story on August 24 working only from the Vermont, South Carolina and Massachusetts filings, described the South Carolina count as "about 5,200" and said flatly that "the precise scope is unclear," correctly predicting that the North Carolina number would be far higher. The rankiteo blog aggregation repeats the Ledger's approximate 5,200 figure. Class Action U, writing on August 17, noted that "the exact date the incident occurred has not been publicly disclosed," which was accurate as of that date but has since been superseded by the June 7-8 window in the notification letter. The 5,176 and 72,912 figures come from state filings and should be treated as the authoritative ones; the "roughly 73,000" and "about 5,200" variants are rounding, not disagreement.

One source in the current collection does not belong to this incident at all. The Star's report on a June 29 cyberattack against the Flexi Parking platform in Malaysia, which prompted developer LITS to rebuild its entire system rather than clean compromised servers, is a separate event with no established connection to Preferred Parking. It is worth reading on its own merits, and we return to it below, but nothing in it should be attributed to the Charlotte incident.

What Was Taken

The exposed data set is narrow and financially specific. Per the North Carolina filing summarized by Queen City News and the Vermont filing described by Class Action U, the compromised information consists of names, credit and debit card numbers, and financial account codes.

Hoodline, citing the Vermont Attorney General filing by way of Class Action U, reports that the breach did not include Social Security numbers, passwords, dates of birth or medical records. Queen City News adds two further exclusions attributed to the company: the incident did not involve ransomware or business email compromise, and no employee data was affected.

That combination matters. A stolen card number is a revocable credential. Victims can cancel and reissue, and issuer fraud liability protections limit direct loss. A stolen Social Security number is not revocable and creates identity theft exposure that persists for years. On the evidence available, Preferred Parking's victims are in the first category, which is the better of two bad outcomes.

The unresolved question is what "credit and debit account information" and "financial account codes" actually encompass. Full PANs? Expiry dates? Card verification values? Filings of this kind rarely say, and none of the reporting resolves it. Whether the stolen data is directly usable for card-not-present fraud or merely useful for enrichment and social engineering depends entirely on that detail, and it has not been disclosed.

Why It Matters

Parking operators sit in an awkward spot in the payments ecosystem. They are not retailers, not banks, and not obviously high-value targets, yet a company like Preferred Parking, with more than 240 locations across 15 Southeast cities, over 40,000 daily customers and roughly 17,000 spaces in greater Charlotte alone, processes a continuous stream of card transactions and stores account data tied to monthly permit holders. As Class Action U frames it, permitting and violation-processing functions require the company to hold financial account information for the customers and permit holders it serves, which puts a mid-market operator in possession of a payment data set the size of a regional bank's card portfolio.

The regional context is its own signal. The Observer notes that Preferred Parking joins a run of Charlotte-area companies disclosing breaches in the past fifteen months, including Bojangles, Krispy Kreme, Belk, Food Lion and Atrium Health. That clustering is more plausibly a reflection of the density of consumer-facing businesses in the metro and the steady baseline rate of database intrusion than evidence of a campaign targeting Charlotte specifically, but defenders in the region should assume they are inside a well-mapped target set.

There is also a disclosure-visibility problem worth naming. Both the Ledger and Hoodline observe that North Carolina does not maintain a public online breach registry, meaning the largest victim population in this incident was invisible to the press until the AG's office confirmed the count on request. The Ledger's early coverage could see 5,329 victims across three states; the real number was more than thirteen times that. Analysts building breach datasets from state portals are systematically undercounting incidents whose center of gravity sits in non-publishing states.

The Attack Technique

Little has been disclosed, and what has been disclosed is mostly negative space. The company characterized the event to North Carolina regulators, per Queen City News, as "hackers or unauthorized access to electronically stored information," and stated that the affected data was protected by access controls, passwords and unique user permissions. That last claim is a curious one to make about data an intruder successfully exfiltrated; it establishes that controls existed, not that they held.

Explicitly ruled out by the company: ransomware and business email compromise. No threat actor has been named, no extortion demand has been reported, and no data has been observed for sale. The two-day access window on June 7 and 8 is consistent with a focused smash-and-grab against a database rather than an extended dwell-time intrusion, but the notification letter does not describe the initial access vector, and nobody should infer one from a date range alone.

For contrast, and only as contrast, The Star's account of the unrelated Flexi Parking incident in Malaysia offers the kind of technical detail this disclosure lacks. LITS chief executive Lai Thiam Sin told StarMetro that the June 29 breach occurred while the company was migrating ageing virtual servers to newer cloud infrastructure, and that "some folder permissions were inadvertently left open" during the window. He likened it to moving house and leaving the gate open. The attacker reached a legacy server. LITS chose to rebuild rather than remediate, standing up new virtual servers, migrating code, reconstructing the network, moving to a new VPN and rotating passwords and keys, with the compromised servers isolated, decommissioned and imaged for forensics while CyberSecurity Malaysia conducted a post-mortem. Two parking-sector incidents in the same month, on opposite sides of the world, with no evidence linking them. The Malaysian operator's transparency is the outlier here, not the attack.

What Organizations Should Do

Inventory stored cardholder data and justify every field. The single most effective control against this class of incident is not holding the data. Tokenize stored payment instruments so that a database dump yields references rather than PANs, and confirm that recurring-billing and permit-renewal flows genuinely require retained card data rather than a vault token.

Instrument the database tier for bulk-read anomalies. Access controls and unique user permissions, the protections Preferred Parking cited, are preventive. They tell you nothing once an actor is authenticated. Alert on query volume, row-count thresholds and off-hours access patterns against tables holding financial data, so that a two-day exfiltration window is detected in hours rather than reconstructed in July.

Audit legacy and in-migration infrastructure specifically. The Malaysian case is a clean illustration of a general pattern: transitional states are where permissions get loosened and forgotten. Any cloud migration, server decommissioning or infrastructure refresh should carry a mandatory permissions review at both the start and the close of the change window.

Shorten the gap between detection and notification. Nine weeks from intrusion to notice is not unusual, but every week of it is a week of unmonitored fraud exposure for cardholders. Pre-build the notification workflow, including state-by-state filing templates and a data-mapping capability that can answer "whose records were in this table" in days rather than seven weeks.

Treat card-only breaches as a reason to accelerate, not relax. The absence of SSNs lowers the identity theft ceiling, but it does not lower the immediate fraud risk. Preferred Parking is advising affected customers to monitor financial statements and immediately dispute suspicious charges with their banks. Organizations in a similar position should go further and coordinate proactively with issuing banks so that reissuance can begin before the first fraudulent transaction posts.

Assume regional clustering means you are already enumerated. If peers in your metro or sector have disclosed in the past year, treat your external attack surface as mapped. Run credential-stuffing detection against customer portals, verify that internet-facing application stacks are patched, and validate that your third-party parking, payments and permitting vendors are not carrying your card data on their own weaker footing.

Sources: Uptown Parking Giant's Breach Hits 73,000 Customers, Cards Exposed | Charlotte parking company notifies customers of card breach | Preferred Parking data breach exposes customer credit card information | Preferred Parking Service Data Breach Lawsuit | Preferred Parking: What it’s like to live in a historic landmark | Cyberattack triggers parking platform rebuild The Star | Charlotte-based parking company data breach impacts more than 61,00... | More than 72K people affected by parking company data breach – WSOC TV