Ransomware victim disclosure
← All victimsFactory Five Racing Inc
Claimed by METAENCRYPTER · listed 1 hour ago
Status timeline
- ListedSep 16, 2026
Current state: Listed for ransom
At a glance
- Group
- METAENCRYPTER
- Status
- Listed for ransom
- Country
- United States
- Listed on leak site
- Sep 16, 2026
- Data size
- ~130GB
About the victim
AI dossier — public-source company profileFactory Five Racing Inc is a Massachusetts-based manufacturer of high-performance kit cars, including Cobra replicas, GTM, Type 65 Coupe, and 33 Hot Rod models. The company employs approximately 90 staff and generates annual revenue of $5.5–6.5 million, with significant credit card processing volume.
- Industry
- Automotive Manufacturing / Kit Car Production
- Address
- 9 Tow Road, Wareham, MA 02571-1086
- Employees
- 90
Attack summary
Severity: high — Confirmed exfiltration of ~130 GB+ of sensitive business, financial, and legal data including banking statements, tax documentation, active litigation files, customer payment records (PCI DSS scope), personal data (MA 201 CMR 17.00, GDPR, CCPA compliance impact), and ongoing regulatory audits (IRS, MA Sales Tax). Significant operational and regulatory risk.METAENCRYPTER claims to have exfiltrated approximately 130 GB of internal data, later increased by an additional 1 TB. The group asserts the company remains vulnerable to further compromise. Exfiltrated data includes correspondence, CRM records, ERP/pricing information, engineering designs, financial documents, legal contracts, and litigation files.
Data the group says was taken
AI dossier — extracted from the leak post- Email correspondence (PST archives)
- CRM contacts (GoldMine)
- ERP and pricing data
- Engineering CAD files (SolidWorks/Rhino)
- Banking statements
- Insurance policies
- Tax documentation
- Legal contracts and NDAs
- Litigation case files (parties, witnesses, testimonies)
- Database backups
What the group claims
Kit-car manufacturer (Cobra replicas, GTM, Type 65 Coupe, 33 Hot Rod). Located at 9 Tow Road, Wareham MA 02571-1086. Approximately 90 employees, 158 endpoints. Revenue $5.5-6.5M/yr. CEO: David T. Smith.
The leak post
captured from the group's siteThis platform publishes data belonging to organizations that have elected to forgo negotiation entirely.Upon a company's initial listing, the complete manifest of exfiltrated files is disclosed alongside a curated selection of representative samples. Should the organization fail to establish contact prior to the stated deadline, a portion of the compromised data is released into the public domain.Should all subsequent attempts at resolution prove fruitless, the full volume of acquired data is made permanently and unconditionally available to the general public — accessible without restriction to journalists, researchers, competitors, and any other interested party. Simultaneously, formal notifications are dispatched to the relevant data protection and regulatory authorities: the and in the United States; the , , , and the across Europe; the (Singapore), (South Korea), and (Japan) throughout Asia — all of whom are mandated to investigate and impose penalties upon the affected organization.In the event that a mutual agreement is reached, every file in our possession is permanently and irrevocably destroyed, and all references to that organization are expunged from this platform in th…
Data the group says was taken
- correspondence
- PST archives
- CRM contacts
- ERP/pricing data
- engineering CAD files
- banking statements
- insurance policies
- tax documentation
- legal contracts
- NDAs
- database backups
- lawsuit case files
- private correspondence
Screenshot of the leak post

Sources
Source
Indexed 1 hour agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

