Ransomware victim disclosure
← All victimsSpratleys of Mortimer
Claimed by PrinzEugen · listed 2 days ago
Status timeline
- ListedJun 15, 2026
Current state: Listed for ransom
At a glance
- Group
- PrinzEugen
- Status
- Listed for ransom
- Country
- United Kingdom
- Listed on leak site
- Jun 15, 2026
- Data size
- hundreds of GBs
About the victim
AI dossier — public-source company profileSpratley's of Mortimer is a fifth-generation family-run garage near Reading, Berkshire, specializing in car servicing, MOT testing, repairs, and used car sales. They service most makes including Vauxhall, Ford, Volkswagen, Audi, and Renault, employing professionally trained technicians.
- Industry
- Automotive Service & Repair
- Address
- Mortimer, near Reading, Berkshire, GB (junction 11 of M4 on Berkshire/Hampshire border)
- Founded
- 1960
Attack summary
Severity: medium — Confirmed encryption and exfiltration of hundreds of GBs of business data from a small/medium business with no clear evidence of regulated PII at scale. The threat of ongoing network access adds operational concern but lacks proof of critical data types specific to automotive service operations.PrinzEugen claims to have encrypted hundreds of gigabytes across company file shares and exfiltrated data. The group states their beacon remains active within the network and threatens full public release of files if ransom is not paid.
Data the group says was taken
AI dossier — extracted from the leak post- company file shares
- internal business records
What the group claims
Hundreds of GBs of data encrypted across company file shares. The threat actor's beacon is still calling back from within the network.
The leak post
captured from the group's site[ spratleys.co.uk Hundreds of GBs of data encrypted across company file shares, If you would like the decryption key you just need to ask. 6/10/2026 - PS. Our beacon is STILL calling back from within your network. ](http://prinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd.onion/spratley-s-of-mortimer) ## [ Transitions Pro Centre Val de Loire The swift attack has resulted in both the exfiltration and encryption of hundreds of gigabytes. In the event of complete non-compliance; Files will be fully released for public download. ](http://prinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd.onion/transitions-pro-centre-val-de-loire) [ Beginning on February 27th 2026, The 3 week long attack on both Standard Bank and Liberty has resulted in 1.2TB of data being exfiltrated from internal servers. A peaceful resolution was sought out with Standard Bank, however after 2 weeks of back and forth they made the decision to abandon their customers. The haul of over 154,000,000 rows of exported SQL data includes but is not limited to: Customer PII (Full Names, Addresses, Emails, Phone Numbers, South African ID Numbers, Drivers License Numbers, Passport Numbers, Credit Card Numbers, Acco…
Screenshot of the leak post

Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

