Dipecarr Listed by Eclipse Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Dipecarr was listed by the Eclipse ransomware group on 8 October 2026, with the group claiming to hold data belonging to an undisclosed number of individuals. Anyone who may have shared information with Dipecarr is advised to review their accounts and consider protective steps.
A ransomware group has publicly named Dipecarr on a leak site, which raises practical questions for customers, suppliers, and staff whose details may sit in the company’s systems. Nothing in the public record confirms that a breach occurred or that any particular person’s information left the company. Still, when a business that serves tens of thousands of truck owners and fleet operators is listed this way, people who deal with it have reason to watch for unusual contact, invoice fraud, or account misuse—and to act on a conditional basis until clearer facts appear.
As of writing, Dipecarr has not publicly confirmed the claim. The listing is an accusation from the group that posted it, not a verified inventory of stolen files. Reported timing on the claim is October 08, 2026; the number of people affected and the types of data involved are not disclosed in the available material.
What is being claimed
Eclipse has listed Dipecarr on its leak site. The public summary attached to that listing describes Dipecarr as Brazil’s top truck parts distributor, founded in 1994 by Adilson José de Almeida, with a large catalogue, brand partnerships, roughly 80,000 customers, and seven branches in key Brazilian states. Beyond the act of listing the company and that organisational description, the material does not state how any intrusion supposedly happened, what volume of data is involved, whether files were actually published, or a confirmed timeline of technical events.
Scale, method, and exact contents remain undisclosed. The listing should be read as the group’s claim: that it holds or intends to pressure the company with data. Independent confirmation from the company, a regulator, or a recognised breach index is not part of the facts provided here.
Who is Eclipse?
Eclipse is known publicly as a ransomware and extortion-style actor that pressures organisations by threatening to publish material on dedicated leak sites. Groups in this category typically claim access to internal systems, demand payment, and use timed listings or sample dumps as leverage. Their posts are marketing and coercion tools; they are not audited reports.
For this incident, only what appears in relation to the Dipecarr listing can be tied to Eclipse’s claim. No additional statements from the group about specific file sets, ransom amounts, or technical paths into Dipecarr are included in the facts at hand. Readers should treat “Eclipse listed Dipecarr” as the core allegation, not as proof of successful theft or of any particular dataset.
About Dipecarr
Dipecarr operates in Brazil’s commercial vehicle parts distribution sector. Public-facing description of the business points to a long-running distributor founded in the mid-1990s, a wide ready-to-ship catalogue, partnerships with known brands, multi-state branch presence, and a large customer base of truck owners and related buyers. Firms in this line of work typically sit between manufacturers, workshops, fleets, and individual operators: they process orders, deliveries, warranties, and accounts receivable and payable.
A claimed incident involving such a distributor matters because the sector routinely handles commercial contact data, delivery and billing details, and operational records that can be reused for fraud or competitive intelligence if they were ever copied. That consequence is about the kind of business Dipecarr is—not a finding that any specific systems failed. A leak-site name alone does not establish how the company defends itself or whether anything left its environment.
What data was at risk
The facts state that data types named as exposed are not disclosed. There is therefore no verified list of fields, databases, or document categories for this claim.
If files from a truck-parts distributor were taken, organisations of this type commonly hold customer and workshop contact information, order and invoice histories, shipping addresses, supplier and brand-partner records, employee directory data, and internal commercial documents. Those are sector norms, not a confirmed inventory of what Eclipse claims to have. Exact contents for this listing remain unconfirmed; any discussion of risk stays conditional on whether material was actually obtained and what it contained.
The real-world impact
For individuals and small businesses that buy parts or run accounts with a distributor, the practical worry—if data were involved—would centre on phishing that references real orders, fake payment or delivery notices, password reuse against customer portals, and social-engineering calls that sound informed about past purchases. Fleet and workshop contacts could see attempts to redirect payments or spoof supplier relationships. None of that is established as having happened here; it is the pattern people prepare for when a familiar vendor is named on an extortion site.
For the organisation, an unverified listing can still mean reputational pressure, customer questions, and the cost of investigating whether systems were touched. A leak-site post does not by itself prove exfiltration, encryption, or downtime. It also does not prove negligence. It establishes only that a named group chose to put Dipecarr on a public pressure page on or about the reported date, while company confirmation is absent from the public facts used for this article.
Steps worth taking either way
Treat outreach that cites Dipecarr orders, invoices, or branch details with extra caution until you can verify it through a channel you already trust. Prefer official apps or known phone numbers over links in unexpected messages. If you use a customer or supplier portal tied to the company, use a unique password and turn on multi-factor authentication where it exists. Watch bank and card statements for charges you do not recognise, and be slow to change payment instructions solely because of an email or message.
If you are an employee or contractor, follow your organisation’s normal guidance on suspicious mail and do not assume internal files are public based only on a third-party listing. Because the claim is unconfirmed and data types are undisclosed, these steps are prudent hygiene rather than a response to proven exposure of your record.
Readers who want a simple check can run a free exposure scan of their email address against known breach corpora to see whether that address has already appeared in unrelated, previously published dumps—useful context, not proof about this particular listing.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
Global AirFreight International Listed by Eclipse Ransomware GroupThe Japan Times Listed by Eclipse Ransomware GroupRosello et Fils Listed by Eclipse Ransomware GroupDublin City Schools GA Listed by Eclipse Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Dipecarr Listed by Eclipse Ransomware Group →
Publicly posted by eclipse — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.