Ransomware victim disclosure
← All victimsThe National Auto Loan Network
Claimed by Nova · listed 5 months ago
Status timeline
- ListedJan 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Nova
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Jan 14, 2026
- Data size
- 10 GB
- Records
- 100.000 customers
About the victim
AI dossier — public-source company profileThe National Auto Loan Network (NALN) specializes in auto loan refinancing, having refinanced over $2 billion in auto loans for more than 100,000 customers since its founding in 2010. The company was founded by finance professionals with over 40 years of combined experience and focuses on simplifying the refinancing process. NALN serves US-based individuals seeking to reduce monthly car payments through effective loan refinancing solutions.
- Industry
- Auto Loan Refinancing & Consumer Finance
- Founded
- 2010
Attack summary
Severity: critical — NALN is a consumer financial services company holding PII and financial records for over 100,000 customers; confirmed exfiltration and publication of this regulated financial data constitutes a critical-severity disclosure.The Nova ransomware group claims to have encrypted the company's systems on 12/01/2026 and subsequently leaked data on 27/01/2026 after the company did not make contact. The group states that customer data is at stake and notes the company did not respond to outreach.
Data the group says was taken
AI dossier — extracted from the leak post- Customer personal information
- Auto loan records
- Financial data
- Customer contact details
What the group claims
National Auto Loan Network specializes in auto loan refinancing, having successfully refinanced over 2 billion dollars in auto loans for more than 100,000 customers since its inception in 2010. The company is founded by finance professionals with over 40 years of experience and aims to simplify the refinancing process for clients. They pride themselves on excellent customer service and educating clients about their loans. NALN serves individuals looking to save money on their monthly car payments through effective loan refinancing solutions.
The leak post
captured from the group's siteDesysweb is a comprehensive technology solutions integrator specializing in telecommunications and IT services, including managed services and a Security Operation Center. With over 200 clients and more than 13 years of experience, they offer personalized consulting, high-quality materials, and competitive pricing. The company is ISO 27001:2022 certified, ensuring robust information security and data protection. Desysweb operates nationally with a presence in eight provinces and is committed to delivering tailored projects and 24/7 customer support through a team of certified engineers. - Los sistemas de la empresa están encriptados con más de 60 mil archivos en múltiples servidores. Tienes tiempo de contactarte con nuestro departamento a través de los canales indicados en el archivo de recuperación que está dentro de los sistemas encriptados. Una vez que termine la cuenta regresiva, ya no será posible recuperar la información y tus datos se perderán. Estamos listos para desencriptar cada uno de los archivos. Contáctanos cuanto antes. Since the company didn't reach us, Data has been Leaked. Since the company didn't reach us, Data has been Leaked. CHARLES CONSEIL COORDINATION (3CCC)…
Screenshot of the leak post

Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

