Ransomware victim disclosure
← All victimsBardahl de México, S. de R.L. de C.V.
listed as bardahl.com.mx · Claimed by LockBit · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- LockBit
- Status
- Data leaked
- Country
- Mexico
- Sector
- Manufacturing
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileBardahl de México, S. de R.L. de C.V. is a Mexican manufacturer and distributor of automotive lubricants, oils, additives, antifreeze, brake fluids, and related chemical products, operating from Toluca, Estado de México. The company serves multiple vehicle segments including passenger cars, trucks, trailers, motorcycles, boats, and tractors, and sells through both a physical distribution network and an online store. It operates under the global Bardahl brand and also maintains a separate industrial products site (bardahlindustria.com.mx).
- Industry
- Automotive Lubricants & Chemical Products Manufacturing
- Address
- Calle Eje 1 Norte No. 16, Mz 1, Col. Parque Industrial Toluca 2000, C.P. 50233, Toluca, Estado de México, Mexico
- Founded
- 2015
Attack summary
Severity: high — Data has been confirmed as published by LockBit, indicating successful exfiltration of business data from a manufacturing company. While no specific regulated data categories (e.g., medical, government) are confirmed, the publication of exfiltrated data from a named corporate entity with operational scope warrants a high severity rating.LockBit claims to have attacked Bardahl de México and has published data (disclosed status: data_published), indicating exfiltration of company data. No ransom amount or specific data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Company internal documents
- Business data
What the group claims
About Bardahl De México, SA De CV Bardahl de México specializes in automotive products, being a lea...
Sources
- Victim sitebardahl.com.mx
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

