Charlotte/ Crime & Emergencies

Uptown Parking Giant's Breach Hits 73,000 Customers, Cards Exposed

AI Assisted Icon
Published on August 25, 2026
Uptown Parking Giant's Breach Hits 73,000 Customers, Cards ExposedSource: Unsplash/ Nick Nice

A hacker broke into the customer database of Preferred Parking, the Uptown Charlotte company that runs more than 65 parking lots and garages across the region, exposing credit and debit card information tied to roughly 72,912 people. Of those affected, 61,335 are North Carolina residents, with smaller pockets of victims spread across South Carolina, Massachusetts and Vermont.

According to the Charlotte Observer, an unauthorized actor gained access to Preferred Parking's database over June 7 and 8, and the company's investigation into the intrusion wrapped up on July 30. Preferred Parking, founded in 1961 and now managing more than 240 locations across the Southeast, including facilities in Uptown, South End and NoDa, serves over 40,000 daily customers and controls roughly 17,000 parking spaces in the greater Charlotte area alone, per the same report.

Regulatory filings submitted to the Vermont Attorney General's office on August 14 show the breach exposed credit card and debit card numbers along with financial account codes, but did not include Social Security numbers, passwords, dates of birth or medical records, according to Class Action U. That distinction matters for victims: stolen card numbers can be neutralized by canceling and replacing a card, while stolen Social Security numbers create longer-running identity theft risks that are far harder to undo.

How the Notifications Reached the Public

Preferred Parking notified at least three states about the incident by August 14, breaking down the impact as 5,176 people in South Carolina, 142 in Massachusetts and 11 in Vermont, the Observer's report notes. The company also listed additional information for residents of Connecticut, Maryland, New York, Rhode Island, West Virginia and the District of Columbia.

North Carolina itself does not maintain a public online registry of corporate breach notifications, unlike neighboring and regional states such as South Carolina, Vermont and Massachusetts, which do keep searchable filings, according to The Charlotte Ledger, which reported on the Preferred Parking breach earlier this month. That gap helps explain why Charlotte-area residents often first learn about local breaches through filings made in other states rather than through North Carolina's own regulators.

The office of North Carolina Attorney General Jeff Jackson confirmed the number of impacted people, the Observer reports. Jackson's office had already flagged the scale of the problem statewide in May, when it reported a record 2,349 data breaches submitted to the North Carolina Department of Justice over the prior year, affecting more than 9 million residents statewide.

What Preferred Parking Is Telling Customers

Preferred Parking has implemented additional measures to enhance the security of its IT network since the breach, per the Observer's reporting. The company is advising potentially affected customers to monitor their financial statements for unauthorized charges and to immediately dispute any suspicious activity with their banks. Preferred Parking did not respond to the Observer's request for comment as of August 24.

Under North Carolina's Identity Theft Protection Act, businesses operating in the state must notify affected residents of a security breach without unreasonable delay and must alert the North Carolina Attorney General's office immediately whenever a breach affects more than 1,000 people, according to Tec-Tel. That statutory duty sits alongside the separate notification requirements Preferred Parking has already triggered in Vermont, Massachusetts and South Carolina.

Part of a Wider Pattern for Charlotte Employers

Preferred Parking's breach lands amid a string of data security incidents involving major Charlotte-based and regional companies over roughly the past 15 months. Bojangles, Atrium Health, Belk and Food Lion have all reported breaches in that window, the Observer notes, and each has followed its own distinct path through the legal system.

Atrium Health began alerting Charlotte-area patients in May after a third-party breach tied to legacy Cerner systems, originally detected by Oracle Health in February 2025, exposed medical records created before August 2022, according to Becker's Hospital Review. Belk, the Charlotte-headquartered department store chain, faced class-action litigation after a May 2025 cyberattack by the ransomware group DragonForce exfiltrated 156 gigabytes of employee and customer data, Cybersecurity Dive reported, with lawsuits alleging the retailer failed to encrypt sensitive data and delayed notifying consumers for nearly a month.

Former employees suing Bojangles over an early-2024 data breach saw their federal lawsuit dismissed for lack of standing in September 2025, but most of their claims were revived when a North Carolina Business Court judge allowed the case to proceed in state court in June, as Hoodline reported in its piece on the Bojangles breach lawsuit's revival. That split outcome reflects a broader legal divide: federal courts have grown more likely to dismiss breach lawsuits without proof of realized identity theft, pushing more plaintiffs toward North Carolina's state business courts, which have shown more willingness to let negligence and delayed-notice claims move forward, per Inside Class Actions.

Food Lion's parent company, Ahold Delhaize USA, disclosed in June 2025 that a November 2024 ransomware attack exfiltrated personal and health records belonging to more than 2.24 million current and former associates across its U.S. supermarket brands, according to Claim Depot. Krispy Kreme, meanwhile, agreed to a $1.616 million class-action settlement in mid-2026 over a November 2024 cyberattack that compromised the personal information of nearly 162,000 people, WUSA9 reported, with the court-approved deal offering up to $3,500 in documented loss reimbursement or roughly $75 in flat cash payments.

Consumer privacy law firms have already begun reviewing potential class-action lawsuits on behalf of impacted Preferred Parking customers following the company's multi-state regulatory filings, according to Class Action U. Given the pattern seen in the Bojangles and Belk cases, any such litigation could ultimately test the same federal-versus-state legal divide that has shaped how North Carolina breach victims seek recourse.