Ransomware victim disclosure
← All victimsendeavourautomotive.co.uk
Claimed by BrainCipher · listed 20 days ago
Status timeline
- Listed
May 1, 2026
- Data leaked
At a glance
- Group
- BrainCipher
- Status
- Data leaked
- Country
- GB
- Sector
- Transportation/Logistics
- Listed on leak site
- May 1, 2026
About the victim
AI dossier — public-source company profileEndeavour Automotive (endeavourautomotive.co.uk) is a UK-based automotive group operating car dealerships and related automotive retail or servicing operations. Based on the domain and sector classification, the company operates within the UK automotive retail market. No further detail was available from the public site at the time of analysis.
- Industry
- Automotive Retail & Services
Attack summary
Severity: high — Data has been confirmed as published (disclosed status: data_published) with over 1 TB exfiltrated and made available across 10 Tor download links, indicating significant confirmed exfiltration of business data. The exact nature of the data is unspecified, but the volume and publication status warrant a high severity rating; if PII or financial records are included at scale it could escalate to critical.BrainCipher claims to have exfiltrated more than 1 TB of data from Endeavour Automotive, with the stolen data published and available for download via multiple Tor (.onion) links. No ransom amount was stated and no specific data categories were described in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Exfiltrated corporate data (>1 TB)
- Files published via Tor download links
The group's post references roughly 10 proof files.
Original description
AI-summarised, not from the leak postEndeavour Automotive is a UK-based car dealership group operating across England. The company sells new and used vehicles from multiple mainstream and premium brands, including Ford, Nissan, and others. It also provides vehicle servicing, parts, and aftersales support. Operating within the automotive retail industry, Endeavour Automotive runs several dealership locations primarily in the south and east of England.
The leak post
captured from the group's siteWe have more 1TB of data. If you think you are here by mistake, please contact us at [email protected] ⏳ 12d 8h 29m 41s remaining Download: 3fg2gfwrdks46drwvejpgpak5klrflclsjjo35dxtqfk3poeez6oezad.onion If you think you are here by mistake, please contact us at [email protected] Download: emdnfl2fv32jhssxcbxlo6dzg2at4d7qbw2md6inz63qzdfgyln5cwyd.onion If you think you are here by mistake, please contact us at [email protected] Download: a4vbe7yp4kluped6khuhpr5nmzshiimx2jt5j22ozriiq6ngsm3fcpyd.onion If you think you are here by mistake, please contact us at [email protected] Download: x3nb7qcygpem2j5xzstyzdtgzofzkwkx4eko3ug4r73i6uhcgvyffjyd.onion If you think you are here by mistake, please contact us at [email protected] Download: 3frnhzcnlkjnw5q3tm6elzizinm2k3bmrtf2xwqjzpcxzeqwn2tv6wyd.onion If you think you are here by mistake, please contact us at [email protected] Download: 6ft2dfh26wm3w44orpjcgviutvfp25ez2iyh5ego5egvfmifrws7vvqd.onion If you think you are here by mistake, please contact us at [email protected] Download: zijgmuqjzb6dc7pofxhtaiz36qqyg35lhutybmzaz6whzgei2casjgid.onion If you think…
Sources
Source
Indexed 20 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
