2026 Grupo ATC — extortion sale claim (unverified); 340GB+ logistics data alleged (MX/US)
Data compromised
Actor-claimed 23 databases / 340GB+ / 2B+ rows: employee PII (RFC, bank, CLABE), OAuth2/JWT/SFTP/API credentials, cleartext passwords, intercepted business emails, GPS/freight routing, and partner logistics data referencing Ford, Toyota, Tesla, GM, Stellantis—unverified
Technical writeup
Unverified extortion sale claim — indexed July 1–2, 2026. Threat-intelligence monitoring reported actor Straightonumberone offering for $1,000 what they describe as data stolen from Grupo ATC, a Mexico–U.S. logistics conglomerate comprising TLE, TLEA, and PHES, after an alleged failed ransom negotiation and file encryption. The listing claims 23 databases exceeding 340GB and more than two billion rows, including employee PII, credentials/tokens, business emails, GPS routing data, and references to automotive-industry partners. Grupo ATC had not publicly confirmed at catalog time. BreachHistory indexes recordsAffected 0 pending attestation; treat row-count marketing as unverified.
Root cause
Unverified actor Straightonumberone sale listing after alleged failed ransom negotiation against Grupo ATC (TLE, TLEA, PHES) Mexican logistics conglomerate—company had not confirmed at catalog time