Ransomware victim disclosure
← All victimsPonti
Claimed by Thegentlemen · listed 1 day ago
Status timeline
- ListedAug 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Poland
- Listed on leak site
- Aug 7, 2026
About the victim
AI dossier — public-source company profilePonti is a specialized automotive company based in Gdańsk, Poland, focused on the direct import, sales, and professional servicing of American vehicles. The company specializes in sourcing modern US cars, restoration of classic muscle cars and vintage vehicles, post-accident repairs, and mechanical maintenance for automotive enthusiasts.
- Industry
- Automotive Import & Sales
- Address
- Gdańsk, Poland
Attack summary
Severity: low — The leak post contains only company description with no evidence of proof files, data samples, specific data inventory, or details of what was actually exfiltrated or encrypted. No operational impact stated.The threat actor claims to have compromised Ponti and published data. No specific details on encryption, exfiltration scope, or data types are provided in the available post excerpt.
What the group claims
ponti.pl Ponti is a specialized automotive company based in Gdańsk, Poland, focused on the direct import, sales, and professional servicing of American vehicles. Operating as a leading expert in the US car market, the company handles everything from modern everyday models to the restoration of classic muscle cars and vintage vehicles. They provide a comprehensive range of services, including sourcing, repairing post-accident imports, and dedicated mechanical maintenance for automotive enthusiasts
Sources
- Victim siteponti.pl
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

