Ransomware victim disclosure
← All victimsTetrosyl Group
Claimed by Snatch · listed 3 years ago
Status timeline
- ListedJun 14, 2023
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Automotive
- Listed on leak site
- Jun 14, 2023
About the victim
AI dossier — public-source company profileTetrosyl Limited is the largest manufacturer and supplier of car care products in Europe and the UK's biggest independent oil blender, distributing to over 100 countries. The company operates 4 manufacturing sites producing over 188 million units per year, with over 16,000 formulations developed in its technical centres. It serves car care, automotive, and home care markets through retail, trade, and direct-to-consumer channels.
- Industry
- Automotive Car Care Products Manufacturing & Distribution
- Employees
- 501-1000
Attack summary
Severity: high — Data has been published by the threat actor ('data_published' status), confirming exfiltration from a large-scale European manufacturer with broad commercial operations across 100 countries, indicating significant business data exposure even though specific data categories are not enumerated.The Snatch ransomware group claims to have attacked Tetrosyl Group and has published data ('data_published' status), though no specific data volume or ransom demand is stated in the post. The nature of exfiltrated data is not detailed in the truncated leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business data
- Manufacturing and operational records
- Supplier and customer information
- Financial records
What the group claims
Tetrosyl Limited is the largest manufacturer and supplier of car care products in Europe and is the UK's biggest independent oil blender extending its global reach to 100 countries. Tetrosyl leads the way in brand management with a fine blend of innovation, technology and design
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

