Ransomware victim disclosure
← All victimsSsangYong Motor
Claimed by Snatch · listed 3 years ago
Status timeline
- ListedJun 2, 2023
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- South Korea
- Sector
- Automotive
- Listed on leak site
- Jun 2, 2023
About the victim
AI dossier — public-source company profileSsangYong Motor Company is a South Korean automobile manufacturer headquartered in Seoul, South Korea, known for producing SUVs, MPVs, and passenger vehicles. The company has passed through several ownership changes, including Daewoo Motors, SAIC Motor, Mahindra & Mahindra, and was acquired by KG Group in 2022. It operates manufacturing facilities primarily in Pyeongtaek, South Korea.
- Industry
- Automotive Manufacturing (Passenger Vehicles)
- Address
- 198, Cheonho-daero, Dongdaemun-gu, Seoul, South Korea
- Employees
- 4700
- Founded
- 1954
Attack summary
Severity: high — Data has been published by the threat actor (data_published status) from a major automotive manufacturer, indicating confirmed exfiltration and release of business data; while the exact data types are not fully enumerated, exfiltration from a large automotive OEM with potential IP, engineering, and employee data warrants a high severity rating.The Snatch ransomware group claims to have exfiltrated data from SsangYong Motor, with the disclosure status recorded as data_published, indicating stolen data has been released or made available. The specific volume of data exfiltrated was not stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business data
- Internal company documents
What the group claims
The company was named SsangYong Motor Company in 1988, following its acquisition by the chaebol SsangYong Group in 1986. SsangYong Motor was then acquired by Daewoo Motors, SAIC Motor, and then Mahindra & Mahindra. In 2022, the company was acquired by the KG Group and
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

