Ransomware victim disclosure
← All victimsMidwest Truck and Auto Parts, Inc.
listed as Midwest Truck · Claimed by Royal · listed 3 years ago
Status timeline
- Listed
May 4, 2023
- Data leaked
At a glance
- Group
- Royal
- Status
- Data leaked
- Country
- United States
- Sector
- Automotive
- Listed on leak site
- May 4, 2023
About the victim
AI dossier — public-source company profileMidwest Truck and Auto Parts, Inc. sources and supplies components to the heavy duty, light duty, and high-performance aftermarkets worldwide. The company has merged operations with S&S Truck Parts LLC and together offers over 30,000 quality parts across brands including Motive Gear, TEN Factory, Richmond Gear, and Powertrax. Their customers include warehouse distributors, dealerships, and international buyers.
- Industry
- Aftermarket Truck & Automotive Parts Distribution
- Address
- 600 W. Irving Park Road, Schaumburg, IL 60193
Attack summary
Severity: critical — The group explicitly claims exfiltration of highly regulated PII at scale — including SSNs, passports, and driver's licenses of employees and clients — alongside sensitive financial and contractual business records, meeting the threshold for critical severity.The Royal ransomware group claims to have exfiltrated corporate data from Midwest Truck and Auto Parts, including personal information (driver's licenses, addresses, phone numbers, passports, SSNs) and business records (financial documents, bank statements, incident reports, contracts), and states the data will be published to their blog.
Data the group says was taken
AI dossier — extracted from the leak post- Driver's licenses
- Home addresses
- Phone numbers
- Passports
- Social Security Numbers (SSNs)
- Financial documents
- Bank statements
- Incident reports
- Contracts
What the group claims
Midwest Truck and Auto Parts, Inc. sources and supplies various components to the heavy duty, light duty, and hi-performance aftermarkets worldwide. Someone thinks that if a business is small, that means that it needs nothing to do with clients and employees data to secure them. Same happened to Midwest Truck. Lack of cyber protection has led to upcoming uploading their corporate data with all the personal (drivers licenses, addresses, phones, passports, SSNs) and business (financial docs, bank statements, incident, contract) information to our blog. Stay in touch.
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
