Ransomware victim disclosure
← All victimsFord Country Americas (CMAMERICAS S.A. DE C.V)
listed as fordcountrymotors.mx · Claimed by Lockbit3 · listed 2 years ago
Status timeline
- ListedOct 21, 2024
- Data leakeddate unknown
At a glance
- Group
- Lockbit3
- Status
- Data leaked
- Country
- Mexico
- Sector
- Business Services
- Listed on leak site
- Oct 21, 2024
About the victim
AI dossier — public-source company profileFord Country Americas is a Ford dealership in Guadalajara, Mexico specializing in the retail sale of new and pre-owned passenger cars and trucks. The dealership offers financing, maintenance services, and test drives.
- Industry
- Automotive Retail & Sales
- Address
- Avenida Américas No. 1166, Colonia Country Club, Guadalajara, Jalisco 44610, Mexico
Attack summary
Severity: medium — No proof files or screenshots advertised; no specific data categories confirmed in the post. However, automotive dealerships typically hold PII (names, contact details, financial/credit information for financing customers), warranting medium classification pending publication of proof.LockBit3 claims to have compromised the company and exfiltrated data. No specific details on encryption status or data categories are provided in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Customer personal data
- Contact information
- Financial/credit information (inferred from financing operations)
What the group claims
Greetings! Today we are posting here the new company, "CMAMERICAS S.A. DE C.V". Company Description: COUNTRY MOTORS specializes in the retail sale of new passenger cars and trucks. Headquarters: Avenida Américas No. 1166 Country Club, 44610...
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

