Ransomware victim disclosure
← All victimsKenworth del Sur S.A. de C.V.
listed as Kenworth Del Sur · Claimed by Hunters International · listed 1 year ago
Status timeline
- ListedApr 25, 2025
- Data leakeddate unknown
At a glance
- Status
- Data leaked
- Country
- Mexico
- Sector
- Transportation/Logistics
- Listed on leak site
- Apr 25, 2025
About the victim
AI dossier — public-source company profileKenworth del Sur is an authorized Kenworth distributor based in Puebla, Mexico, specializing in the sale of new and semi-new heavy-duty trucks, trailers, allied equipment, parts, and after-sales service including mechanical and body shop repairs. The company serves commercial trucking operations across Mexico with financing options and warranty policies.
- Industry
- Commercial Vehicle Sales & Distribution
- Address
- Prolongación Av. México Puebla #189, Col. Centro, San Juan Cuautlancingo, Cuautlancingo, Puebla, C.P. 72700, Mexico
Attack summary
Severity: medium — Confirmed dual attack (exfiltration + encryption) against a commercial entity with potential access to customer and business data, but no regulated sensitive data categories explicitly confirmed and no specific proof inventory disclosed in the available excerpt.The Hunters group claims to have exfiltrated data from Kenworth del Sur's systems while also encrypting them. The specific nature of exfiltrated data is not detailed in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Business records
- Customer information
- Financial/sales data
- Operational documents
What the group claims
Exfiltraded data : yes - Encrypted data : yes
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

