Ransomware victim disclosure
← All victimsUniversity Volkswagen Mazda
Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 18, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- United States
- Sector
- Consumer Services
- Listed on leak site
- Jan 18, 2026
About the victim
AI dossier — public-source company profileUniversity Volkswagen Mazda is a US-based automotive dealership selling and servicing Volkswagen and Mazda vehicles. Based on the brand names in its title, it likely operates one or more franchise dealership locations. No further operational details were available from the public site.
- Industry
- Automotive Dealership
Attack summary
Severity: medium — Status is listed as data_published, indicating some level of confirmed data disclosure, but no data categories, volume, or proof file count are described in the available post excerpt, limiting severity assessment to medium.Qilin claims to have compromised University Volkswagen Mazda and has published data, though the leak post excerpt does not specify whether encryption or exfiltration (or both) occurred, and no specific data categories or volume are stated in the available text.
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

