Ransomware victim disclosure
← All victimsMayco International
Claimed by Dark Project · listed 3 days ago
Status timeline
- ListedAug 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Dark Project
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Aug 5, 2026
About the victim
AI dossier — public-source company profileMayco International is a Michigan-based Tier-1 automotive supplier operating across 40 locations with 7,000+ employees. They provide modular systems for vehicle interiors and exteriors, offering end-to-end services from design and engineering through tooling, manufacturing, and logistics for leading OEMs and Tier-1 partners across North America and Mexico.
- Industry
- Automotive Supplier (Tier-1 Interior/Exterior Modules)
- Address
- 42400 Merril Road, Sterling Heights, MI 48314
- Employees
- 7000+
Attack summary
Severity: high — Confirmed exfiltration of 2TB of sensitive data including employee PII at scale, proprietary technical designs (critical for automotive OEM relationships), and financial records. No encryption mentioned but data publication confirms operational threat to a major Tier-1 supplier serving critical automotive customers.Dark Project claims to have exfiltrated approximately 2TB of data from Mayco International's infrastructure, including internal organizational documents, proprietary technical schemas, employee personally identifiable information, and financial records.
Data the group says was taken
AI dossier — extracted from the leak post- Internal organizational documents
- Proprietary technical schemas
- Employee personally identifiable information
- Financial records
What the group claims
About Mayco International At least 2Tb of sensitive data were exfiltrated from the company’s control following a cyberattack. The compromised dataset leaked from Mayco internatioins company infrastructure includes internal organizational documents, proprietary technical schemas, employee personally identifiable information, and a substantial volume of financial records.
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

