Ransomware victim disclosure
← All victimsAstemo, Ltd.
Claimed by Metaencryptor · listed 6 hours ago
Status timeline
- ListedSep 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Metaencryptor
- Status
- Data leaked
- Country
- Japan
- Sector
- Manufacturing
- Listed on leak site
- Sep 21, 2026
About the victim
AI dossier — public-source company profileAstemo, Ltd. is a global automotive supplier with approximately 80,000 employees across the United States, Asia, China, Europe, and Japan. The company operates three business segments (Electrification, Vehicle, and Motorcycle) developing, manufacturing, and servicing automotive parts, transportation machinery, industrial equipment, and systems including powertrain, chassis, brake, and autonomous driving solutions.
- Industry
- Automotive Parts & Systems Manufacturing
- Employees
- 80000
Attack summary
Severity: medium — Data has been published by the group (disclosed_status: data_published), indicating confirmed exfiltration. However, the truncated leak post provides no inventory of specific data types, scale, or sensitivity level, and no proof files are advertised. The attack affects a major global automotive manufacturer with significant operational footprint, elevating concern despite information limitations.The metaencryptor group claims to have attacked Astemo and published data. No specific details are provided in the truncated leak post regarding encryption, exfiltration, or the nature of compromised data.
What the group claims
Astemo operates worldwide as a global mega-supplier of automotive parts, with approximately 80,000 employees across the United States, Asia, China, Europe, and Japan. Through operations in three business segments (Electrification Business, Vehicle Business, and Motorcycle Business), we develop, manufacture, sell and service automotive parts, transportation and industrial machinery, equipment and systems.
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

