Ransomware victim disclosure
← All victimsPrecision Vehicle Logistics
Claimed by Direwolf · listed 6 days ago
Status timeline
- ListedSep 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Direwolf
- Status
- Data leaked
- Country
- United States
- Sector
- Transportation
- Listed on leak site
- Sep 7, 2026
About the victim
AI dossier — public-source company profilePrecision Vehicle Logistics is a finished-vehicle yard management and processing operator based in Wayne, Michigan. The company operates yard facilities and vehicle movement systems for Ford, General Motors, and rail/intermodal operations, and also runs its own driveaway transportation business. It uses the AutoVentive YMS (Autovision platform) for managing vehicle assets, manifests, and logistics workflows.
- Industry
- Automotive Logistics & Yard Management
- Address
- Wayne, MI, USA
- Employees
- 1001-5000
Attack summary
Severity: critical — Exfiltration of complete production databases for two major automotive OEMs (Ford, General Motors) including vehicle manifests, GPS coordinates, user credentials, and operational logistics. Includes personally identifiable information (employee/driver accounts across 2,430 users), GPS telemetry, and sensitive supply-chain data affecting critical automotive manufacturing operations. Data spans multi-year period (2022–2026) with 7.9M rows across 6 databases.The direwolf group claims to have exfiltrated six complete PostgreSQL and Redshift database exports totalling ~6.5 GB and 7,993,438 rows. The databases contain detailed operational data spanning 2022–2026 including vehicle assets, manifests, user accounts, GPS telemetry, and sensitive logistics records for Ford and General Motors production yards, plus the company's own driveaway operations.
Data the group says was taken
AI dossier — extracted from the leak post- 550K vehicle assets (VINs, GPS coordinates, facility locations)
- 933K breach/telemetry alerts with device IDs and GPS coordinates
- 3.8M Ford production manifests, seal verification records, and logistics data
- 1.2M General Motors (Spring Hill) production records, VINs, and addresses
- 1.1M rail/intermodal container and railcar records (TTGX, BNSF)
- 2,430 user accounts with bcrypt password hashes
- 765K Ford ingress/access logs and telemetry blobs
- Battery charge records, vouchers, and payments (Ford EV charging)
- 48 emails across multiple domains (precisionvl.com, prevh.com, autoventive.com)
- Contract records (Ford, General Motors Corporation)
- Mobile app configurations and platform settings
What the group claims
Freight & Logistics Services
The leak post
captured from the group's site```
{"article":{"id":128,"title":"Precision Vehicle Logistics","content":"\u003ch1\u003eData Warehouse Briefing\u003c/h1\u003e\n\u003ch2\u003e1. Overview\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eItem\u003c/th\u003e\n\u003cth\u003eValue\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eBusiness\u003c/td\u003e\n\u003ctd\u003e\u003cstrong\u003ePrecision Vehicle Logistics (Wayne, MI) - finished-vehicle yard management \u0026amp; processing operator running AutoVentive YMS (AutoVentive \u0026#34;Autovision\u0026#34; platform) environments for Ford, General Motors and rail/intermodal operations, plus its own Driveaway business\u003c/strong\u003e (in-data evidence: admin account Preston Cole \u003ca href=\"mailto:[email protected]\" rel=\"nofollow\"\[email protected]\u003c/a\u003e across environments, extract recipients \u003ca href=\"mailto:[email protected]\" rel=\"nofollow\"\[email protected]\u003c/a\u003e / \u003ca href=\"mailto:[email protected]\" rel=\"nofollow\"\[email protected]\u003c/a\u003e, user emails on…Sources
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

