Ransomware victim disclosure
← All victimsEnkei Corporation (U.S. operations)
listed as ENKEI******* · Claimed by Thegentlemen · listed 4 hours ago
Status timeline
- ListedSep 26, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Sector
- Manufacturing
- Listed on leak site
- Sep 26, 2026
About the victim
AI dossier — public-source company profileEnkei is the U.S. production arm of a major Japanese automotive wheel manufacturer, specializing in light-alloy aluminum wheels for original equipment manufacturers (OEMs). The company operates a casting plant in the American Midwest with in-house die-making capability, supplying factory rims directly to mass-market Japanese automakers and EV manufacturers for vehicle assembly lines.
- Industry
- Automotive Parts & Wheels Manufacturing
Attack summary
Severity: medium — Data published status and operational context (manufacturing/supply chain) suggest exfiltration occurred, but no proof files are mentioned, data inventory is absent, and no regulated data categories are explicitly confirmed. Supply chain disruption risk is present given the automotive OEM relationship.The threat actor claims to have accessed Enkei's systems and exfiltrated data. The post does not specify encryption, data types, or operational disruption; it appears to be an initial announcement.
What the group claims
This company specializes in manufacturing light-alloy aluminum wheels for automakers — that is, it supplies factory rims for new cars rather than selling to retail consumers. It is the U.S. production arm of a major Japanese group, a global leader in this industry, with a casting plant in the American Midwest and its own in-house die-making capability. Its main clients are large car manufacturers (mass-market Japanese brands and new EV makers), with products going straight to vehicle assembly lines. The business is currently undergoing restructuring: part of its capacity is being shut down due to labor shortages and high operating costs, with production being consolidated at a single plant.
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

