Ransomware victim disclosure
← All victimsBehbehani Brothers WLL (Behbehani Motors Company)
listed as H-Behbehani Brothers WLL · Claimed by INC Ransom · listed 4 months ago
Status timeline
- ListedFeb 3, 2026
- Data leakeddate unknown
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- Bahrain
- Listed on leak site
- Feb 3, 2026
- Data size
- 1.3 TB
About the victim
AI dossier — public-source company profileBehbehani Motors Company, operating under H-Behbehani Brothers WLL, is a Kuwaiti automotive dealership established in 1957. It is the authorised representative of Volkswagen and Porsche in Kuwait and holds the distinction of being the first Porsche dealership in the Middle East. The company provides car sales, bodyshop services, and car rental.
- Industry
- Automotive Dealership & Services
- Address
- Kuwait (exact street address not stated)
- Founded
- 1957
Attack summary
Severity: high — 1.3 TB of confirmed exfiltrated data including customer PII, financial/accounting records, and internal communications represents a significant business and personal data exposure; data_published status indicates active leak rather than mere listing.INC Ransom claims to have exfiltrated 1.3 TB of data from Behbehani Motors Company, including internal email correspondence, accounting records, and customer information, with publication of all data threatened imminently.
Data the group says was taken
AI dossier — extracted from the leak post- Internal email/correspondence
- Accounting records
- Customer personal information
What the group claims
Behbehani Motors Company, established in 1957, represents iconic automotive brands such as Volkswagen and Porsche in Kuwait. The company offers a range of services including car sales, a bodyshop, and a car rental division. This was the first Porsche dealership in the Middle East and only the 9th worldwide. We have 1.3TB of data. Internal mail, accounting, company customer information and we will publish all the information next week.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

