🕸️ Ransomware Detected: Oztugotomotiv targeted by incransom
Oztugotomotiv is targeted by incransom.Victim Description: Öztuğ Otomotiv & Endüstri is a Turkish company established in 1990 in Bursa, specializing in the production of high-precision components for the automotive, industrial, defense, and aerospace sectors.
The company offers comprehensive services including design, mold manufacturing, and serial production of plastic, metal, and rubber parts, as well as industrial seals and vibration dampers.
Öztuğ Otomotiv utilizes modern equipment (high-tonnage presses, progressive dies) and adheres to international quality standards, including a zero-defect principle and compliance with OEM standards.
Financial performance (not publicly disclosed, but the company positions itself as a stable business):
As of 2025, the company reports over 35 years of successful operations, more than 300 employees, and three production facilities with a total enclosed area of 12,000 m².
Structure and facilities:
The company operates three production sites in Hasantığla, Nilüfer (Bursa), and Adapazarı.
As of 2025, the workforce comprises over 300 specialists. Production capabilities include plastic injection, metal forming, and rubber molding lines.
Laek: 100GB
WE HAS COLLECTED SUCH DATA AS:
- Confidential documents
- Clients Data
- NDA
- Financial data
- Operations
- Corporate data
- Business Agreements
- Development
- Financial databases, all transactions, all clients
And a lot of other VERY IMPORTANT information!Victim’s Country: TRDiscovered: 03 Jun 2026, 20:31 SGT
Known TTPs associated with INC Ransom
T1021.001 Remote Desktop ProtocolT1078 Valid AccountsT1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1566 Phishing
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: IBENA Textilwerke targeted by nova
IBENA Textilwerke is targeted by nova.Victim Description: IBENA HEIMTEX is a family-owned textile manufacturer based in Bocholt, Germany, established in 1826. The company specializes in high-quality home textiles, including cuddly blankets, bed linen, and technical textiles for various industries. Their products cater to both consumers and businesses, with offerings such as fireproof fabrics, digital printing textiles, and car interior fabrics for renowned automotive brands. IBENA is committed to sustainability and quality, ensuring their textiles meet numerous quality standards - Nova Provide tree and samples from stolen data, free 2 files decrypt to the company when its get in touch with support department.Victim’s Country: DEDiscovered: 02 Jun 2026, 18:25 SGT
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: Mayelia Automotive targeted by thegentlemen
Mayelia Automotive is targeted by thegentlemen.Victim Description: mayelia.com zoominfo.com/c/mayelia-automotive/480899337 is an Ivorian automotive company specializing in vehicle technical inspections.Founded in 2019, it operates under Mayelia Participations holding across multiple African sectors.Services include technical checks, stickers, and corporate solutions for drivers and businesses.The company emphasizes customer service, modern equipment, and road safety educationVictim’s Country: MXDiscovered: 29 May 2026, 02:54 SGT
Known TTPs associated with The Gentlemen
T1021.002 SMB/Windows Admin SharesT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1486 Data Encrypted for ImpactT1685 Disable or Modify Tools
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: jichasa.com targeted by m3rx
jichasa.com is targeted by m3rx.Victim Description: +1 (915) 881-8883. Jichasa Smart Logistics specializes in providing comprehensive solutions in foreign trade and logistics, with a focus on door-to-door services. Established in 1980, the company boasts over 30 years of experience and offers a wide range of services including customs consulting, inventory management, and supply chain management. Their intended clients span various industries such as automotive, aerospace, electronics, and agriculture, ensuring personalized attention through dedicated account executives. With a strong presence across Mexico and advanced technology for real-time operations, Jichasa aims to exceed client expectations in logistics and legal consulting. Stolen: 116gb 98k filesVictim’s Country: MXDiscovered: 27 May 2026, 23:25 SGT
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: PILLER AIMMCO targeted by incransom
PILLER AIMMCO is targeted by incransom.Victim Description: PILLER AIMMCO is a leading vertically integrated custom plastic injection molding and tool-making company based in Woodland and Washougal, Washington. The company serves as a "one-stop shop" by managing the entire manufacturing lifecycle under one roof—from initial part design and engineering to mold production, automated high-volume manufacturing, and secondary assembly.
PILLER AIMMCO holds ISO 9001:2015 certifications across both its tooling and molding operations, enabling it to support rigorous industrial regulations:
1. Medical Devices & Biotech: Fluid management components, orthodontic instruments, and lab devices that meet FDA, biocompatibility, and sterilization metrics.
2. Aerospace & Defense: Specialized tooling, gauges, fixtures, and finished components requiring absolute traceability.
3. Consumer Electronics: Complex enclosures, wearable technology components, and carbon-fiber-filled metal replacements.
4. Industrial & Agriculture: Heavy-duty commodities, nursery containers, large housings, and automotive/heavy trucking aftermarket partsVictim’s Country: USDiscovered: 26 May 2026, 07:22 SGT
Known TTPs associated with INC Ransom
T1021.001 Remote Desktop ProtocolT1078 Valid AccountsT1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1566 Phishing
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: TRANSSYSTEM Group targeted by thegentlemen
TRANSSYSTEM Group is targeted by thegentlemen.Victim Description: transsystem.pl Polish engineering powerhouse with 30+ years of expertise in designing and manufacturing advanced technological transport systems and steel structures. Delivers turnkey intralogistics solutions for automotive, tire, and industrial sectors, with 200+ successful projects across 30+ countries worldwide. Trusted by global leaders including Tesla, Goodyear, Michelin, Continental, and KUKA for innovation, precision, and operational excellenceVictim’s Country: PLDiscovered: 24 May 2026, 17:01 SGT
Known TTPs associated with The Gentlemen
T1021.002 SMB/Windows Admin SharesT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1486 Data Encrypted for ImpactT1685 Disable or Modify Tools
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: Gitis targeted by akira
Gitis is targeted by akira.Victim Description: GITIS S.r.l. specializes in the production of high-quality rubber components, including O-rings
, rubber moulded components, and co-moulded components. Their products cater to various industr
ies such as automotive, general industry, food, pharmaceuticals, biomedical, oil and gas, and h
ydrogen technology.
We will upload 30gb of corporate data soon. Employee personal information, contracts and agreem
ents, financials, clients information, lots of projects, NDAs, etc.Victim’s Country: ITDiscovered: 22 May 2026, 23:50 SGT
Known TTPs associated with Akira
T1021.001 Remote Desktop ProtocolT1027.001 Binary PaddingT1036.005 Match Legitimate Resource Name or LocationT1059.001 PowerShellT1560.001 Archive via Utility
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: Vacu - Lug targeted by akira
Vacu - Lug is targeted by akira.Victim Description: Founded in 1950, Vaculug is a long-established commercial tyre retreading specialist based in G
rantham. Vacu-Lug distributes Westlake light truck tyres, including the WTX1 trailer axle tyre
for Max Load application, the WSR 1 steer axle tyre and the WDR 1 drive axle tyre to suit rims
of 17.5" and 19.5". In addition to supplying a range of Westlake light commercial vehicle tyres
, Vacu-Lug's has its own light truck tyre range.
We will upload 40gb of corporate data soon. Employee personal information (financial and other
docs), contracts and agreements, financials, NDA and other confidential docs.Victim’s Country: GBDiscovered: 18 May 2026, 21:21 SGT
Known TTPs associated with Akira
T1021.001 Remote Desktop ProtocolT1027.001 Binary PaddingT1036.005 Match Legitimate Resource Name or LocationT1059.001 PowerShellT1560.001 Archive via Utility
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: challenge-mfg.com targeted by chaos
challenge-mfg.com is targeted by chaos.Victim Description: Company management has exactly 72 hours to contact us. Otherwise, the organization’s data—which contains confidential information—will be published on our public platform, and the possibility of further negotiations will be ruled out.
Challenge Manufacturing is a leading Tier 1 automotive sup…Victim’s Country: USDiscovered: 18 May 2026, 03:52 SGT
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: dosocho.es targeted by m3rx
dosocho.es is targeted by m3rx.Victim Description: +34 918 264 028. Recambios Generales del Automóvil Dosocho S.L. is a Madrid-based Spanish company specializing in the retail and e-commerce distribution of brand-new automotive spare parts and accessories. Operating through its dedicated platforms like dosochoauto.es, the company provides a comprehensive catalog of high-quality components tailored for various vehicle repairs and maintenance Stolen: 50gb 28k filesVictim’s Country: ESDiscovered: 17 May 2026, 22:54 SGT
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: NTN Bearing Corporation of America targeted by payoutsking
NTN Bearing Corporation of America is targeted by payoutsking.Victim Description: [AI generated] NTN Bearing Corporation of America is a US-based subsidiary of Japan's NTN Corporation, operating in the industrial manufacturing sector. The company produces and distributes precision bearings, driveshafts, and related mechanical components used in automotive, aerospace, and industrial machinery applications. Headquartered in Mount Prospect, Illinois, it serves customers across North America with engineering support and distribution services.Victim’s Country: USDiscovered: 13 May 2026, 08:24 SGT
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: Clark Fixture Technologies targeted by thegentlemen
Clark Fixture Technologies is targeted by thegentlemen.Victim Description: clarkfixtures.com zoominfo.com/c/clark-fixture-technologies-inc/31954083 Clark Fixture Technologies, Inc. is a privately held American manufacturer founded in 1978, headquartered at Bowling Green, Ohio, with an estimated annual revenue of $42.9 million and a staff of 51–200 employees. The company designs, manufactures, and inspects quality check fixtures and gages for bent tube, hose, wire, and weld products, serving industries including automotive, aerospace, space, medical, and agriculture. Clark Fixtures operates globally with facilities in the US, Mexico (Saltillo), and India (Bangalore), servicing clients across 11 countries, including a prestigious roster of aerospace and space clients who rely on its orbital weld tooling for propulsion and life support assemblies. It also offers CMM inspection services and advanced automated robotic cell fixture solutioVictim’s Country: USDiscovered: 06 May 2026, 21:34 SGT
Known TTPs associated with The Gentlemen
T1021.002 SMB/Windows Admin SharesT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1486 Data Encrypted for ImpactT1685 Disable or Modify Tools
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: youX / Drive IQ targeted by fulcrumsec
youX / Drive IQ is targeted by fulcrumsec.Victim Description: [AI generated] youX, formerly known as Drive IQ, is an Australian technology company specializing in connected vehicle data and mobility intelligence. The company collects and analyzes telematics and driving behavior data to deliver insights for insurers, fleet operators, and automotive businesses. Its platform enables usage-based insurance and risk assessment solutions. youX operates primarily in Australia and positions itself within the insurtech and automotive data analytics sectors.Victim’s Country: AUDiscovered: 02 May 2026, 01:10 SGT
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: endeavourautomotive.co.uk targeted by BrainCipher
endeavourautomotive.co.uk is targeted by BrainCipher.Victim Description: [AI generated] Endeavour Automotive is a UK-based car dealership group operating across England. The company sells new and used vehicles from multiple mainstream and premium brands, including Ford, Nissan, and others. It also provides vehicle servicing, parts, and aftersales support. Operating within the automotive retail industry, Endeavour Automotive runs several dealership locations primarily in the south and east of England.Victim’s Country: GBDiscovered: 01 May 2026, 17:55 SGT
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: UFP Technologies targeted by payoutsking
UFP Technologies is targeted by payoutsking.Victim Description: [AI generated] UFP Technologies is a US-based company specializing in the design and manufacturing of highly engineered custom packaging, components, and specialty products. Operating in the advanced materials and manufacturing industry, it serves sectors including medical, automotive, aerospace, and consumer goods. The company uses materials such as foam, plastics, and composites to create protective and functional solutions for its clients.Victim’s Country: USDiscovered: 30 Apr 2026, 08:55 SGT
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: Karl Chevrolet targeted by ransomhouse
Karl Chevrolet is targeted by ransomhouse.Victim Description: Karl Chevrolet, Inc. operates a Chevrolet car dealership. It offers new and used cars, commercial vehicles, SUVs, trucks, and vans. The company also provides automotive parts and accessories, such as brake pads, oil filters, and others; and services, which include vehicle maintenance, repair, inspection, and other services. It also allows customers to order parts online.Victim’s Country: USDiscovered: 30 Apr 2026, 06:00 SGT
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: Alkegen targeted by akira
Alkegen is targeted by akira.Victim Description: Alkegen creates high performance specialty materials used in adva
nced applications including electric vehicles, energy storage, fi
ltration, fire protection and high-temperature insulation, among
many others.
We will upload 57gb of corporate data soon. Employee personal doc
uments (passports, DLs, contacts, addresses, medical information
and so on), client personal information, lots of confidential fil
es, projects, contracts and agreements, detailed financials, NDAs
, etc.Victim’s Country: USDiscovered: 23 Apr 2026, 23:57 SGT
Known TTPs associated with Akira
T1021.001 Remote Desktop ProtocolT1027.001 Binary PaddingT1036.005 Match Legitimate Resource Name or LocationT1059.001 PowerShellT1560.001 Archive via Utility
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: Jiangsu Zenergy Battery Technologies Group Co., Ltd. targeted by ransomhouse
Jiangsu Zenergy Battery Technologies Group Co., Ltd. is targeted by ransomhouse.Victim Description: Zenergy (Jiangsu Zenergy Battery Technologies Group Co., Ltd.) is a Chinese lithium-ion battery manufacturer founded in 2019, specializing in traction batteries for electric vehicles (EVs), energy storage systems (ESS), and aviation batteries. The company delivers end-to-end solutions ranging from individual cells to fully integrated battery packs and battery management systems (BMS). In 2024, Zenergy turned profitable for the first time, and in April 2025, it successfully completed its listing on the Hong Kong Stock Exchange.Victim’s Country: CNDiscovered: 22 Apr 2026, 02:10 SGT
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: Disk Precision targeted by thegentlemen
Disk Precision is targeted by thegentlemen.Victim Description: diskprecision.com zoominfo.com/c/disk-precision-group/11452653 Disk Precision Group (DP Group) is a Singapore-headquartered precision engineering company founded in 1986, specializing in CNC Turning and Milling of high-precision metal components. With manufacturing sites across Southeast Asia (Singapore, Malaysia, Thailand), they serve global OEM clients in Oil & Gas, Automotive, Consumer Electronics, and Aerospace sectorsVictim’s Country: SGDiscovered: 20 Apr 2026, 01:03 SGT
Known TTPs associated with The Gentlemen
T1021.002 SMB/Windows Admin SharesT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1486 Data Encrypted for ImpactT1685 Disable or Modify Tools
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: Fletcher Chrysler Products targeted by akira
Fletcher Chrysler Products is targeted by akira.Victim Description: Fletcher Chrysler Dodge Jeep Ram is a dealership located in Frank
lin, IN, offering a wide selection of new and used Chrysler, Dodg
e, Jeep, and Ram vehicles. They serve clients in Franklin, Indian
apolis, Shelbyville, and surrounding areas, providing assistance
in vehicle purchasing, financing options, and automotive services
.
We will upload 28gb of corporate data soon. Personal data of empl
oyees (passports, DLs, SSNs and others), financials, contracts an
d agreements, client files, and so on.Victim’s Country: USDiscovered: 15 Apr 2026, 20:03 SGT
Known TTPs associated with Akira
T1021.001 Remote Desktop ProtocolT1027.001 Binary PaddingT1036.005 Match Legitimate Resource Name or LocationT1059.001 PowerShellT1560.001 Archive via Utility
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: LACROIX targeted by lamashtu
LACROIX is targeted by lamashtu.Victim Description: Pièces d'Auto Lacroix is a Canadian company specializing in the retail distribution of automotive parts and accessories across several locations in Quebec.Victim’s Country: CADiscovered: 15 Apr 2026, 04:23 SGT
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: Apply Capnor targeted by dragonforce
Apply Capnor is targeted by dragonforce.Victim Description: Capnor specializes in laser scanning, engineering, and 3D data management services, offering a comprehensive range of solutions including design engineering, reverse engineering, and dimensional control. Their services cater to various industries such as oil and gas, marine, chemical, power, pulp and paper, automotive, steel, and food. Capnor utilizes advanced technologies like drone inspections and 3D modeling to enhance project efficiency and accuracy. The company is dedicated to providing innovative solutions that improve project lifecycle phases and ensure quality and safetyVictim’s Country: NODiscovered: 15 Apr 2026, 00:55 SGT
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: gas.mercedes-benz.com.eg targeted by lockbit5
gas.mercedes-benz.com.eg is targeted by lockbit5.Victim Description: Mercedes-Benz, founded in 1967 and headquartered in Giza, Egypt, is a automobile dealer and motor ve...Victim’s Country: EGDiscovered: 14 Apr 2026, 18:58 SGT
Known TTPs associated with LockBit
T1059.003 Windows Command ShellT1110 Brute ForceT1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1560.001 Archive via Utility
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: GEM Terminal targeted by thegentlemen
GEM Terminal is targeted by thegentlemen.Victim Description: gem.com.tw zoominfo.com/c/gem-terminal-industry-co-ltd/46452181 Gem Terminal Ind. Co., Ltd. is engaged in the manufacture and sale of terminals used for electronic communication, automobile transportation and electrical plugs. The Company also offers ceramic ferrules, bushings and modules. During the year ended December 31, 2007, the Company obtained approximately 92% of its total revenue from terminalsVictim’s Country: TWDiscovered: 14 Apr 2026, 18:28 SGT
Known TTPs associated with The Gentlemen
T1021.002 SMB/Windows Admin SharesT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1486 Data Encrypted for ImpactT1685 Disable or Modify Tools
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Global Automotive Cyber Incidents/Eventsmedium
🕸️ Ransomware Detected: Thai Rung Union Car targeted by thegentlemen
Thai Rung Union Car is targeted by thegentlemen.Victim Description: thairung.co.th zoominfo.com/c/thai-rung-union-car-public-company-ltd/104628554 Thai Rung Union Car Public Company Limited focuses on providing high-quality automotive solutions tailored for the Thai market. The company emphasizes constant innovation and sustainable development in its operations. It aims to build a better community through its products and services. Their target clients include individuals and businesses seeking reliable and innovative automotive optionsVictim’s Country: THDiscovered: 08 Apr 2026, 23:31 SGT
Known TTPs associated with The Gentlemen
T1021.002 SMB/Windows Admin SharesT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1486 Data Encrypted for ImpactT1685 Disable or Modify Tools
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.