Ransomware victim disclosure
← All victimsKarl Chevrolet
Claimed by Ransomhouse · listed 13 days ago
Status timeline
- Listed
May 7, 2026
- Data leaked
At a glance
- Group
- Ransomhouse
- Status
- Data leaked
- Country
- United States
- Sector
- automotive
- Listed on leak site
- May 7, 2026
- Data size
- 743 GB
- Ransom demanded
- $740
About the victim
AI dossier — public-source company profileKarl Chevrolet, Inc. operates a Chevrolet car dealership in the United States. It offers new and used cars, commercial vehicles, SUVs, trucks, and vans, along with automotive parts, accessories, and services including vehicle maintenance, repair, and inspection. The company also allows customers to order parts online and reports approximately $53.6 million in annual revenue.
- Industry
- Automotive Dealership
- Employees
- 350
Attack summary
Severity: high — 743 GB of data reportedly exfiltrated and published from an automotive dealership, which likely contains customer PII, financial records, and operational data at significant scale; disclosed status is 'data_published' indicating confirmed exfiltration.RansomHouse claims to have encrypted Karl Chevrolet's systems on or around April 3, 2026, with the disclosure status listed as 'data_published' and approximately 743 GB of data at stake. The group is advertising the data as evidence and indicates publication is contingent on ransom payment.
Data the group says was taken
AI dossier — extracted from the leak post- Vehicle inventory records
- Customer personal information
- Financial and sales records
- Parts and accessories inventory data
- Service and maintenance records
- Employee records
What the group claims
Karl Chevrolet, Inc. operates a Chevrolet car dealership. It offers new and used cars, commercial vehicles, SUVs, trucks, and vans. The company also provides automotive parts and accessories.
The leak post
captured from the group's site```
{"data":[{"id":"a1894b76b7004c75a3a0845799af49956592e3d9","display":"animated","header":"HOT NEWS","info":" Trellix is a global cybersecurity company.","url":"","sort":1,"views":"436242"},{"id":"336b257f582b17573c97578efd4b22762bf77344","sort":2,"header":"Trellix (McAfee & FireEye)","url":"https://www.trellix.com/","private":"false","revenue":"1.5-2 B$","employees":"5000","info":"Trellix is a global cybersecurity company formed from the October 2021 merger of McAfee Enterprise and FireEye. It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints. The companys open and native extended detection and response (XDR) platform helps organizations confronted by todays most advanced threats gain confidence in the protection and resilience of their operations. Trellix, along with an extensive partner ecosystem, accelerates technology innovation through machine learning and automation to empower over 40,000 business and government customers with living security","statusDate":"DEPENDS ON YOU","status":"EVIDENCE","published":"NOT YET","action":"Encrypted","actionDate":"17/04/2026","volume":"~","content":"cybersecurity.html"…Sources
Source
Indexed 13 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
