Ransomware victim disclosure
← All victimsTruckworx
Claimed by Nightspire · listed 4 days ago
Status timeline
- ListedAug 31, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- United States
- Sector
- Transportation
- Listed on leak site
- Aug 31, 2026
About the victim
AI dossier — public-source company profileTruckworx is a multi-location commercial truck dealership and fleet services provider operating across Alabama, Mississippi, and Florida's Panhandle. They sell new and used heavy-duty, medium-duty, and vocational trucks; offer leasing and rental services; provide parts, service, and repair; and operate a body shop and fleet solutions division.
- Industry
- Commercial Vehicle Dealership & Fleet Services
- Address
- Multiple locations: Birmingham, Calera, Dothan, Montgomery, Mobile, Huntsville, Graysville, Tuscaloosa, Thomasville AL; Laurel, Jackson, Gulfport MS; DeFuniak Springs FL
Attack summary
Severity: high — Confirmed exfiltration of sensitive business data including financial, tax, and legal records of a multi-location enterprise. Financial and tax documents constitute material business intelligence and potential regulatory/compliance exposure.The nightspire group claims to have exfiltrated financial records, accounting records, tax records, business operations documents, and legal/corporate records from Truckworx. No ransom demand or operational disruption is stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Financial records
- Accounting records
- Tax records
- Business operations documents
- Legal/corporate records
What the group claims
- Financial records- Accounting records- Tax records- Business operations documents- Legal/corporate records
Sources
- Victim sitetruckworx.com
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

