Cyber Digest

Threat Feed

Automotive News. Curated from across the open web and key dark web sources. Stay informed.

1144stories found
Clear filters
Channel
Topic
Results
Download filtered report (PDF) ↓Includes all 1144 matching stories (first 1,000).
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: McFarlane Agencies targeted by akira

McFarlane Agencies is targeted by akira.Victim Description: McFarlane Agencies is an independent insurance brokerage located in Okotoks, Alberta, specializing in a wide range of insurance an d financial services since 1975. They offer automobile, recreatio nal, commercial, travel, pet, farm, acreage, and property insuran ce, along with financial services through a partnership with Desj ardins Financial Security Investments Inc. We will upload 10gb of corporate data soon. Detailed clients' per sonal documents (SSNs, passports, DLs, addresses, phones and so o n), employee information, financials, client information, NDAs, e tc.Victim’s Country: CADiscovered: 21 Feb 2026, 01:58 SGT

Known TTPs associated with Akira
T1021.001 Remote Desktop ProtocolT1027.001 Binary PaddingT1036.005 Match Legitimate Resource Name or LocationT1059.001 PowerShellT1560.001 Archive via Utility
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: Dinnebiergruppe.de targeted by cloak

Dinnebiergruppe.de is targeted by cloak.Victim Description: [AI generated] "Dinnebiergruppe.de" is a German company incorporated into the automobile industry. They are authorized dealers for major car brands including Mercedes-Benz, smart, Audi, Porsche, and Volkswagen Commercial Vehicles. The company offers a broad range of services including car sales, leasing, financing, insurance, and extensive car maintenance. Moreover, they are also involved in real estate management, hotel industry, and operate petrol stations.Victim’s Country: DEDiscovered: 19 Feb 2026, 18:56 SGT

Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: Wagner Metal Concept targeted by spacebears

Wagner Metal Concept is targeted by spacebears.Victim Description: WMC-Metal (Wagner Metal Concept) - company specializing in the manufacturing and supply of metal products and components for various industries. It offers a wide range of products, including metal parts for engineering, automotive, construction, and energy sectors. The company focuses on using advanced manufacturing technologies and maintains strict quality control throughout all production stages. WMC-Metal actively collaborates with partners worldwide, ensuring timely deliveries and providing tailored solutions for its clients.- Supplier and Partner Contracts- Production and Technical Drawings- Financial Data- Customer Data and Orders- Management data https://wmc-metal.com/Victim’s Country: DEDiscovered: 17 Feb 2026, 15:57 SGT

Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: Kymco targeted by spacebears

Kymco is targeted by spacebears.Victim Description: Kymco (Kwang Yang Motor Co., Ltd.) - Taiwanese company founded in 1963, specializing in the production of motorcycles, scooters, and electric vehicles. It is known for offering a wide range of high-quality products, from small scooters to sport motorcycles and e-bikes. The company actively integrates innovative technologies, including electric drivetrains and advanced control systems, positioning itself as a leader in the market. Kymco also has a strong global presence, exporting its products to over 100 countries. Additionally, the company is committed to developing eco-friendly transportation solutions, such as electric scooters and e-bikes.- Patent and Innovation Data- Financial Data- Customer and Partner Data- 3D models of developments- Schematics and test results- Much more https://www.kymco.com.twVictim’s Country: TWDiscovered: 17 Feb 2026, 14:34 SGT

Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: S.Y.L Pastilhas e Sapatas de Freios targeted by nightspire

S.Y.L Pastilhas e Sapatas de Freios is targeted by nightspire.Victim Description: [AI generated] "S.Y.L Pastilhas e Sapatas de Freios" is a Brazilian company that specializes in the manufacture and marketing of brake pads and shoes. They provide products for a wide range of vehicles, maintaining focus on quality and performance for its customers. Besides, the company develops and executes technical and commercial training for professionals, promoting expertise in the automotive repair market.Victim’s Country: BRDiscovered: 14 Feb 2026, 23:08 SGT

Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: Emirates National Group targeted by thegentlemen

Emirates National Group is targeted by thegentlemen.Victim Description: www.enguae.com https://www.zoominfo.com/c/emirates-national-group-llc/390817579 Emirates National Group (ENG) is a premier transport and mobility solutions provider based in Abu Dhabi, United Arab Emirates. The group owns and operates a diverse portfolio of companies specializing in all forms of private and public transport, including car rentals and leasing, limousine services, taxi operations, and public bus systems. Additionally, the company provides ancillary automotive.Victim’s Country: AEDiscovered: 13 Feb 2026, 03:11 SGT

Known TTPs associated with The Gentlemen
T1021.002 SMB/Windows Admin SharesT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1486 Data Encrypted for ImpactT1685 Disable or Modify Tools
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: Clark Foam Products targeted by thegentlemen

Clark Foam Products is targeted by thegentlemen.Victim Description: clarkfoam.net zoominfo.com/c/clark-foam-products-corp/25809475 Clark Foam Products is a specialized foam fabricator with over five decades of experience serving various industries, including aerospace, automotive, medical, and packaging. They offer a diverse range of high-quality foam products such as crosslink foam, polyurethane foam, and filter foam, along with custom fabrication and design services tailored to meet specific client needs. The company is recognized for its innovative cuttingVictim’s Country: USDiscovered: 12 Feb 2026, 05:15 SGT

Known TTPs associated with The Gentlemen
T1021.002 SMB/Windows Admin SharesT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1486 Data Encrypted for ImpactT1685 Disable or Modify Tools
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: Museu do Caramulo targeted by thegentlemen

Museu do Caramulo is targeted by thegentlemen.Victim Description: museudocaramulo.pt zoominfo.com/c/museu-do-caramulo/547032458 Museu do Caramulo is a museum that showcases a diverse collection of ancient and modern art, automobiles, motorcycles, bicycles, and toys. It hosts various exhibitions and events, including the Caramulo Motorfestival and the Corrida dos Fundadores, aimed at engaging the community and promoting historical awareness. The museum also offers restoration workshops, classic vehicle insurance, and certification services for vehiclesVictim’s Country: PTDiscovered: 11 Feb 2026, 00:06 SGT

Known TTPs associated with The Gentlemen
T1021.002 SMB/Windows Admin SharesT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1486 Data Encrypted for ImpactT1685 Disable or Modify Tools
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: PrintForm targeted by spacebears

PrintForm is targeted by spacebears.Victim Description: Our mission is to make it easy for customers to buy custom-designed parts that meet their needs. PrintForm specializes in build-to-order custom-manufactured plastic and metal parts for various markets, including medical, aerospace & defense, automotive, appliances, energy, oil & gas, and consumer products. From a single prototype up to thousands of production parts, virtually any company designing new or improved products with plastic or metal components will benefit from the on-demand solutions PrintForm provides. As a single source for multiple manufacturing processes, PrintForm provides an expert-level service in transitioning customers through the design to manufacturing cycle.  Services include advanced 3D Printing/additive manufacturing processes and more traditional methods like Silicone molding, CNC Machining, Sheet metal, and Injection Molding.- Drawings- Working Projects- Confidential Client Documents https://printform.com/Victim’s Country: DEDiscovered: 11 Feb 2026, 00:00 SGT

Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: DUKOSI.COM targeted by clop

DUKOSI.COM is targeted by clop.Victim Description: [AI generated] DUKOSI.COM is associated with Dukosi Limited, a UK-based tech company that transforms the way advanced batteries are designed, deployed, and managed. The company focuses on developing a pioneering battery management technology to ease battery deployment in varying sectors, such as electric vehicles, energy storage, and aviation. They aim to improve battery performance, safety, and reduce costs.Victim’s Country: GBDiscovered: 08 Feb 2026, 05:10 SGT

Known TTPs associated with CL0P
T1059.001 PowerShellT1059.003 Windows Command ShellT1190 Exploit Public-Facing ApplicationT1505.003 Web ShellT1566 Phishing
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: bardahl.com.mx targeted by lockbit5

bardahl.com.mx is targeted by lockbit5.Victim Description: About Bardahl De México, SA De CV Bardahl de México specializes in automotive products, being a lea...Victim’s Country: MXDiscovered: 08 Feb 2026, 04:22 SGT

Known TTPs associated with LockBit
T1059.003 Windows Command ShellT1110 Brute ForceT1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1560.001 Archive via Utility
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: grupoferrosider.com.br targeted by lockbit5

grupoferrosider.com.br is targeted by lockbit5.Victim Description: Ferrosider Componentes is a leading provider of automotive parts and components designed for the met...Victim’s Country: BRDiscovered: 08 Feb 2026, 04:19 SGT

Known TTPs associated with LockBit
T1059.003 Windows Command ShellT1110 Brute ForceT1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1560.001 Archive via Utility
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: Silvi SRL targeted by thegentlemen

Silvi SRL is targeted by thegentlemen.Victim Description: silvi.it Silvi SRL, established in 1990, specializes in advanced industrial automation solutions, offering a range of products including palletizing systems, depalletizing systems, and special machines. The company serves various sectors such as metal packaging, pet food, automotive, chemical and pharmaceutical, food and beverage, and warehouse logistics. With over 30 years of experience, Silvi SRL is known for its reliability and innovation, providing high-quality customer supportVictim’s Country: ITDiscovered: 07 Feb 2026, 02:45 SGT

Known TTPs associated with The Gentlemen
T1021.002 SMB/Windows Admin SharesT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1486 Data Encrypted for ImpactT1685 Disable or Modify Tools
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: Gady Family targeted by thegentlemen

Gady Family is targeted by thegentlemen.Victim Description: gady.at zoominfo.com/c/gady-family/431055072 Gady Family is a prominent automotive and agricultural machinery dealer in southeastern Austria, offering a wide range of new and used vehicles including brands like BMW, MINI, Opel, and Toyota. The company also specializes in agricultural machinery and parts, catering to clients in agriculture and farming. With a tradition dating back to 1936, Gady Family has established numerous locations supported by a team of around 500 employeesVictim’s Country: ATDiscovered: 07 Feb 2026, 02:41 SGT

Known TTPs associated with The Gentlemen
T1021.002 SMB/Windows Admin SharesT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1486 Data Encrypted for ImpactT1685 Disable or Modify Tools
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: H-Behbehani Brothers WLL targeted by incransom

H-Behbehani Brothers WLL is targeted by incransom.Victim Description: Behbehani Motors Company, established in 1957, represents iconic automotive brands such as Volkswagen and Porsche in Kuwait. The company offers a range of services including car sales, a bodyshop, and a car rental division. This was the first Porsche dealership in the Middle East and only the 9th worldwide. We have 1.3TB of data. Internal mail, accounting, company customer information and we will publish all the information next week.Victim’s Country: BHDiscovered: 03 Feb 2026, 12:08 SGT

Known TTPs associated with INC Ransom
T1021.001 Remote Desktop ProtocolT1078 Valid AccountsT1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1566 Phishing
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: JST Power Equipment targeted by akira

JST Power Equipment is targeted by akira.Victim Description: Founded in 1993, J.S.T. provides product development of any elect ric connection systems in products like amusement equipment, audi o and visual equipment, household appliances, office equipment, i ndustrial equipment, automobiles, and traffic systems. We will upload 70gb of corporate data soon. Employee information, financials, confidential clients information, large amount of pr ojects files, contracts and agreements, NDAs, etc.Victim’s Country: CNDiscovered: 02 Feb 2026, 23:56 SGT

Known TTPs associated with Akira
T1021.001 Remote Desktop ProtocolT1027.001 Binary PaddingT1036.005 Match Legitimate Resource Name or LocationT1059.001 PowerShellT1560.001 Archive via Utility
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: Wieson Technologies targeted by thegentlemen

Wieson Technologies is targeted by thegentlemen.Victim Description: www.wieson.com https://www.zoominfo.com/c/wieson-technologies-co-ltd/128565406 Wieson Technologies specializes in the design and manufacturing of connectors and cable assemblies, with a focus on super high-speed technology and wireless communications. Their product range includes interconnect components, wireless components, medical electronics, and automotive electronics. The company serves various industries such as cloud computing, data communication, and medical electronics. Established in 1990, Wieson Technologies aims to provide innovative solutions to clients in need of advanced electronic connectivityVictim’s Country: TWDiscovered: 31 Jan 2026, 10:05 SGT

Known TTPs associated with The Gentlemen
T1021.002 SMB/Windows Admin SharesT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1486 Data Encrypted for ImpactT1685 Disable or Modify Tools
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: anomatic.com targeted by chaos

anomatic.com is targeted by chaos.Victim Description: Founded in 1965 and headquartered in New Albany, Ohio, Anomatic is a full-service manufacturer of anodized aluminum and metalized packaging for the automotive, beauty, personal care, consumer electronics, pharmaceutical, medical devices, and spirits industries worldwideVictim’s Country: USDiscovered: 30 Jan 2026, 00:31 SGT

Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: Tahkout Group targeted by tengu

Tahkout Group is targeted by tengu.Victim Description: Tahkout Group is a large Algerian group of companies (sometimes described as a business alliance) founded and run by Mahieddine Tahkout, a well-known Algerian businessman in the automotive, transport, real estate and industrial sectors.Victim’s Country: DZDiscovered: 29 Jan 2026, 04:49 SGT

Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: Active Green + Ross targeted by sinobi

Active Green + Ross is targeted by sinobi.Victim Description: Active Green + Ross operates a chain of Complete Tire & Auto Centres across Southern Ontario, offering a wide selection of passenger and light truck tires from leading manufacturers. Their services include tire sales, automotive repairs, and maintenance for various vehicle models, with a focus on preventative maintenance and repairs. The company emphasizes customer service and provides various promotions and rebates for tire purchases. With over 65 locations, they aim to serve a diverse clientele in the region.Victim’s Country: CADiscovered: 28 Jan 2026, 08:07 SGT

Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: JP Research targeted by sinobi

JP Research is targeted by sinobi.Victim Description: JP Research, Inc. is a leading US statistical and engineering research firm providing research and a broad range of litigation support services in the fields of automotive and consumer product safety. The company integrates advanced statistics, data analytics and engineering (mechanical, automotive, design, and bioengineering) disciplines to address global safety research problems. In bringing together highly specialized technical fields of expertise, JP Research’s approaches to problem solving frequently set the bar for future research. JP Research founded an international consortium to support a Road Accident Sampling System for India (RASSI), and has established a fully incorporated company, JP Research India, Pvt., Ltd., to pursue automotive safety research, accident data collection and crash investigation in India. Specialties Statistical Modeling, Probability & Risk Analysis, Class Action, Comparative Risk Assessment, Claims, Consumer Complaints Analyses, Statistical Significance, Failure & Reliability Analysis, Regression Analysis, Quality Control Procedures, Review & Analysis of Police Accident Reports, Forecasting & Time SeriesBiomechanics and Automotive EngineeringStatistical/Economic EvaluationVictim’s Country: USDiscovered: 28 Jan 2026, 08:06 SGT

Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: ttmet.co.th targeted by incransom

ttmet.co.th is targeted by incransom.Victim Description: The company specializes in the import and export of machinery and spare parts used in the production and quality control for automotive manufacturing. They offer both wholesale and retail sales domestically and internationally, along with installation services, equipment inspections, and maintenance. Their intended clients include automotive manufacturers and businesses in need of machinery and parts. The company is committed to providing comprehensive services to ensure operational efficiency in the automotive sector. Employees: 150 Revenue: $30.4 Million Industry: Automobile Dealers - Retail Phone Number: +66 26255880Victim’s Country: THDiscovered: 28 Jan 2026, 07:40 SGT

Known TTPs associated with INC Ransom
T1021.001 Remote Desktop ProtocolT1078 Valid AccountsT1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1566 Phishing
Actor-profile intelligence; not confirmed in this individual incident, but included in heatmap count.
Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: premmotors.com targeted by tengu

premmotors.com is targeted by tengu.Victim Description: Prem Motors is a leading automobile dealership for Maruti Suzuki, established in 1990 and headquartered in Gwalior, India. The company operates 58 showrooms, 43 workshops, and various outlets across multiple states, providing a comprehensive range of services including sales, service, accessories, finance, and insurance. With a strong focus on customer satisfaction and a commitment to quality, Prem Motors has earned numerous awards for its performance and service excellence. The company aims to deliver a unique buying experience and maintain a professional reputation among manufacturers, financiers, and customers alike.Victim’s Country: INDiscovered: 26 Jan 2026, 21:37 SGT

Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: STRONG WINGS LLP targeted by tengu

STRONG WINGS LLP is targeted by tengu.Victim Description: STRONG WINGS LLP is an Indian Limited Liability Partnership operating in the automotive, vehicle maintenance, and related trading sectors, and is officially registered in Pune, Maharashtra, India.Victim’s Country: INDiscovered: 22 Jan 2026, 20:47 SGT

Dark Web Forum
Global Automotive Cyber Incidents/Eventsmedium

🕸️ Ransomware Detected: automax.com targeted by devman

automax.com is targeted by devman.Victim Description: [AI generated] AutoMax.com is a leading used car dealership group in the US. Known for its wide range of high-quality pre-owned vehicles, AutoMax.com provides affordable options with comprehensive auto inspection and warranty. They offer financing options for all credit situations. The company is committed to delivering excellent customer service through its knowledgeable and friendly staff.Victim’s Country: INDiscovered: 21 Jan 2026, 21:26 SGT

Dark Web Forum