Jeff Wyler Automotive Family Inc.
bd_d56cb38199200046 · schema v1 · pii pii-v1
Full breach record for Jeff Wyler Automotive Family Inc. →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group 8base on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
When you're looking for a new car or need to have your car serviced, come visit Jeff Wyler, one of the top rated car dealers in Ohio, Kentucky, and Indiana. Whether you are looking to buy a new or used vehicle in Cincinnati, Dayton, Columbus or Louisville, need to have service completed on your vehicle, need auto parts and accessories, or body work that needs attention... You can trust your decision when you choose any one of our Jeff Wyler Dealerships. Our dealership reviews and testimonials attest to our long standing reputation, and we invite you to join the Jeff Wyler Family dealerships.https://wyler.com
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jun 13, 2023
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecryptbbbd_6321686bede1acae2023-07-04 · +21dVerified by operator
Regulatory filings (6) · sorted by filing gap
- Indiana State AGbd_619c0f6b4b5f85ee2024-02-13 · +245dVerified by operator
- Vermont State AGbd_c3843ad56d6f2e792024-02-13 · +245dVerified by operator
- Maine State AGbd_84a99a9eced554912024-02-15 · +247dVerified by operator
- Montana State AGbd_b65e79c63a02a5712024-02-19 · +251dVerified
Show 2 more filings ↓Show fewer ↑up to 265d gap
- New Hampshire State AGbd_0bd48e5174aa87312024-02-23 · +255dVerified by operator
- Massachusetts State AGbd_9271b6175e3bde4a2024-03-04 · +265dVerified by operator
Filing propagation · 7 filings · 6 states
View merged incident ↗Pattern: first filing Jun 13, last Mar 4 (MA) — a 265-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
8base
According to ransomware.live, The 8base Ransomware group made its first appearance in early March 2022, remaining somewhat quiet after the attacks. This group operates like other ransomware actors, engaging in double extortion. However, in mid-May and June 2023, the ransomware operation saw a spike in activity against organizations from various sectors, listing 131 organizations in just 3 months. The 8base data leak site was created and made available in March 2023, claiming honesty and simplicity in its discourse. VMware published a report on 8base, drawing some similarities with the ransomware group `RansomHouse`, pointing out resemblances such as the website used by 8base and the ransom notes presented in its attacks. Interestingly, the 8base Ransomware group does not have its own ransomware developed by the group. Instead, the actors took advantage of other leaked ransomware builders to customize the ransom note and present it to the victim organization as 8base's operation. Source : https://github.com/crocodyli/ThreatActors-TTPs