Ransomware victim disclosure
← All victimsOmax Autos Limited
listed as omaxauto.com · Claimed by Lockbit5 · listed 3 months ago
Status timeline
- ListedMar 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- India
- Sector
- Manufacturing
- Listed on leak site
- Mar 1, 2026
About the victim
AI dossier — public-source company profileOmax Autos Limited is one of India's leading manufacturers of sheet metal components, serving commercial vehicle, passenger car, and railways & heavy fabrication segments. The company is headquartered in Gurugram, Haryana, and is noted as the largest commercial vehicle chassis manufacturer in India and India's only Tier 1 company capable of delivering paintless coach shells. It is a publicly listed entity (CIN: L30103HR1983PLC026142) incorporated in 1983.
- Industry
- Automotive Sheet Metal Components Manufacturing
- Address
- Plot No. B-26, Institutional Area, Sector-32, Gurugram (Haryana), India - 122001
- Founded
- 1983
Attack summary
Severity: high — Data has been published (data_published status) by the group, confirming exfiltration from a publicly listed manufacturing company. The company's investor, financial, shareholder, and HR data are likely included, representing significant business and potentially regulated data exposure. No confirmed PII at scale or medical/government data elevates this to high rather than critical.The LockBit 5 ransomware group claims an attack on Omax Autos Limited and has published data (disclosed status: data_published), though no specific data size or ransom amount has been stated in the post. The group's post indicates exfiltration of company data, with no explicit detail on encryption.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate financial information
- Shareholder disclosures
- Board and governance documents
- Customer data
- HR/employee records
- Regulatory filings
What the group claims
OMAX Autos Limited is a leading manufacturer of sheet metal components, specializing in commercial v...
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

