Ransomware victim disclosure
← All victimsEstra Automotive
Claimed by Incransom · listed 2 months ago
Status timeline
- Listed
Mar 10, 2026
- Data leaked
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- Poland
- Sector
- Manufacturing
- Listed on leak site
- Mar 10, 2026
About the victim
AI dossier — public-source company profileEstra Automotive is an international automotive supplier specialising in the development and manufacture of thermal management components and systems for vehicles. Its product portfolio includes HVAC systems, heat exchangers, and engine cooling solutions supplied to global automotive manufacturers. The company operates across multiple markets as a Tier 1/Tier 2 supplier supporting vehicle efficiency and temperature regulation technologies.
- Industry
- Automotive Thermal Management Components & Systems
Attack summary
Severity: high — Data has been published (data_published status), confirming exfiltration rather than a mere listing. Estra Automotive is an international automotive supplier, meaning leaked data likely includes proprietary engineering designs, supply chain information, and business records of significant commercial sensitivity, warranting a high severity classification.Incransom claims to have compromised Estra Automotive and has published data (disclosed status: data_published), though the specific volume of exfiltrated data and whether encryption was also deployed are not stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Company internal documents
- Engineering or product design data
- Business operational records
What the group claims
Estra Automotive is an international automotive supplier that develops and manufactures thermal management components and systems for vehicles. The company focuses on products such as HVAC systems, heat exchangers, and engine cooling solutions used by global automotive manufacturers to maintain optimal vehicle temperature, improve efficiency, and support modern vehicle technologies
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
