Ransomware victim disclosure
← All victimsOrth Automobile
Claimed by Play · listed 4 hours ago
Status timeline
- ListedSep 30, 2026
- Data leakeddate unknown
At a glance
- Group
- Play
- Status
- Data leaked
- Country
- Germany
- Sector
- Manufacturing
- Listed on leak site
- Sep 30, 2026
About the victim
AI dossier — public-source company profileOrth Automobile is a German automotive dealership and service provider operating multiple locations in Beselich and Idstein. They sell new and used vehicles from brands including Mercedes-Benz, Volkswagen, SEAT, CUPRA, KIA, and Hyundai, and operate service workshops offering maintenance, repair, and vehicle diagnostics.
- Industry
- Automotive Retail & Service
- Address
- Beselich and Idstein, Germany
Attack summary
Severity: low — Leak post is a bare listing with no proof files, no stated data exfiltration, no operational impact, and no details of what was compromised. Disclosure status is 'data_published' but no data size is recorded and the post excerpt contains no substantive claims.The Play ransomware group claims to have attacked Orth Automobile. The leak post provides minimal detail; no specific data exfiltration or encryption claims are articulated in the truncated post excerpt.
What the group claims
Germany
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

