← Grupo ATC

2026 Grupo ATC — extortion sale claim (unverified); 340GB+ logistics data alleged (MX/US)

2026 Unknown records affected Share on X

Data compromised

Actor-claimed 23 databases / 340GB+ / 2B+ rows: employee PII (RFC, bank, CLABE), OAuth2/JWT/SFTP/API credentials, cleartext passwords, intercepted business emails, GPS/freight routing, and partner logistics data referencing Ford, Toyota, Tesla, GM, Stellantis—unverified

Technical writeup

Unverified extortion sale claim — indexed July 1–2, 2026. Threat-intelligence monitoring reported actor Straightonumberone offering for $1,000 what they describe as data stolen from Grupo ATC, a Mexico–U.S. logistics conglomerate comprising TLE, TLEA, and PHES, after an alleged failed ransom negotiation and file encryption. The listing claims 23 databases exceeding 340GB and more than two billion rows, including employee PII, credentials/tokens, business emails, GPS routing data, and references to automotive-industry partners. Grupo ATC had not publicly confirmed at catalog time. BreachHistory indexes recordsAffected 0 pending attestation; treat row-count marketing as unverified.

Root cause

Unverified actor Straightonumberone sale listing after alleged failed ransom negotiation against Grupo ATC (TLE, TLEA, PHES) Mexican logistics conglomerate—company had not confirmed at catalog time

References