OneDealer
bd_5484e57778c1fd84 · schema v1 · pii pii-v1
Full breach record for OneDealer →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Hellcat on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
We have obtained over 330,000 records from OneDealer partners, including sales reports, leads, customer data, and vehicle details with VINs and license plates. Affected companies include AutoHellas, AutoBesikos, KosmoCar, AWT, Karenta AE, QA, Proaxia, Hyundai, BMW, Audi, Kia,
Source provenance
- Source URL
- https://www.ransomware.live/
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 25, 2025
- Raw hash
- 8367e903766f6648311d85500b2c3deb1973558014706b2457528962759806a4
Reporting entity
- Name
- hellcat
Victim entity
- Name
- OneDealernorm: onedealer
- Domain
- onedealer.com
- Industry
- Retail & Consumer
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· hellcat
- Threat actor
- HellcatExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.