Ransomware victim disclosure
← All victimsGSAC Auto Financing
Claimed by Storm · listed 2 days ago
Status timeline
- ListedSep 3, 2026
- Data leakeddate unknown
At a glance
- Group
- Storm
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Sep 3, 2026
About the victim
AI dossier — public-source company profileGSAC Auto Financing is a specialized lender offering auto loans to individuals with poor or challenged credit histories. The company works with a network of dealers to help clients obtain vehicles while reporting payment histories to credit bureaus to support credit repair.
- Industry
- Auto Finance & Credit Services
- Address
- 1645 Ogden Avenue, Downers Grove, IL 60515, United States
- Employees
- 11-50
Attack summary
Severity: medium — Financial services company handling credit and personal data; however, no proof files, screenshots, or specific data inventory are mentioned in the post. The claim lacks substantiation.The Storm group claims to have compromised GSAC Auto Financing; however, the leak post provides only a company description and no specific details about what data was exfiltrated, whether encryption occurred, or what proof of compromise exists.
Data the group says was taken
AI dossier — extracted from the leak post- loan application records
- credit history data
- personal identifying information
- payment history records
What the group claims
GSAC Auto Financing specializes in providing auto loans for individuals with challenged credit. They offer assistance in rebuilding credit while helping clients find suitable vehicles through their network of dealers. The company emphasizes that bad credit does not have to be a barrier to obtaining a car. GSAC is committed to accurately reporting payment histories to credit bureaus to aid in credit repair. The company headquarters is located in 1645 Ogden Avenue, Downers Grove, IL 60515, United States. 11-50 Employees
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

