Ransomware victim disclosure
← All victimsActive Green + Ross
Claimed by Sinobi · listed 5 months ago
Status timeline
- ListedJan 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Sinobi
- Status
- Data leaked
- Country
- Canada
- Sector
- Consumer Services
- Listed on leak site
- Jan 28, 2026
About the victim
AI dossier — public-source company profileActive Green + Ross operates a chain of Complete Tire & Auto Centres across Southern Ontario, Canada, with over 65 locations. The company offers tire sales for passenger and light truck vehicles from major manufacturers, alongside automotive repair and preventative maintenance services. It serves a broad consumer clientele and runs promotional rebate programs for tire purchases.
- Industry
- Automotive Tire & Repair Services
- Address
- Southern Ontario, Canada
- Employees
- 201-500
Attack summary
Severity: high — Data has been confirmed as published by the group across a 65+ location consumer automotive chain, indicating exfiltration of potentially significant business and customer data at scale, though specific regulated data categories are not confirmed.The ransomware group Sinobi claims to have compromised Active Green + Ross and has published data, though the specific nature of exfiltrated data and whether encryption occurred is not detailed in the post. The disclosure status indicates data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- Customer records
- Business operational data
- Employee information
- Financial records
What the group claims
Active Green + Ross operates a chain of Complete Tire & Auto Centres across Southern Ontario, offering a wide selection of passenger and light truck tires from leading manufacturers. Their services include tire sales, automotive repairs, and maintenance for various vehicle models, with a focus on preventative maintenance and repairs. The company emphasizes customer service and provides various promotions and rebates for tire purchases. With over 65 locations, they aim to serve a diverse clientele in the region.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

