FactoryFive Listed by metaencryptor Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
FactoryFive was listed by the metaencryptor ransomware group on August 23, 2026, with the breach involving an undisclosed number of individuals’ personal data. Anyone who has interacted with the organisation should verify whether their information was exposed and take appropriate protective steps.
On August 23, 2026, the ransomware group metaencryptor listed FactoryFive — also identified in the listing material as Factory Five Racing Inc., a kit-car manufacturer based in Wareham, Massachusetts — on its leak site. That listing is an unverified claim by the group. As of writing, FactoryFive has not publicly confirmed that an incident occurred, that systems were accessed, or that any data left its environment. Public detail beyond the group’s own post remains limited.
Leak-site posts are pressure tactics. They can be accurate, inflated, recycled, or false. Until a company, regulator, or other independent source corroborates events, the responsible way to read this material is as an accusation, not as an established breach. What follows separates what metaencryptor claims from what is known about the firm and the kinds of risk that would matter if sensitive files were ever involved.
What is being claimed
metaencryptor has listed FactoryFive on its leak site and, in associated listing text, has described the organization as Factory Five Racing Inc., a maker of kit cars including Cobra replicas, GTM, Type 65 Coupe, and 33 Hot Rod models, with an address at 9 Tow Road, Wareham, MA 02571-1086. The same material refers to a workforce on the order of about 90 employees, roughly 158 endpoints, and annual revenue in a band of about $5.5–6.5 million, including figures related to credit-card processing volume. Those operational details appear in the group’s presentation; they are not independently verified here.
The listing material also asserts that a large volume of data — described as on the order of about 130GB — was taken, and it names categories the group says are included. Timing of any intrusion, method of access, ransom demands, negotiation status, and whether any files were actually published are not established in confirmed public reporting tied to this article. The number of people who might be affected is unknown. Nothing in the available record should be treated as proof that the claimed exfiltration happened as described.
Inside metaencryptor
metaencryptor is known publicly as a ransomware and extortion-oriented crew that follows a pattern common among modern leak-site operators: encrypt or threaten encryption, claim theft of internal files, and use a public site to name victims and pressure payment by threatening disclosure. Groups in this category often advertise supposed archives, sample files, or category lists to make listings look credible. Those posts are marketing for coercion. They are not audited inventories, and they are not confirmation from the named organization.
Public reporting on such actors generally notes double-extortion style pressure — disruption plus the threat of data release — and opportunistic targeting across industries rather than a single exclusive sector. For this FactoryFive listing specifically, only what appears in the group’s claim should be attributed to metaencryptor. No additional statements by the group about this victim are treated as fact beyond that listing context, and the listing itself remains unconfirmed by the company.
Who is FactoryFive?
Factory Five Racing Inc. is publicly known as a United States kit-car manufacturer. Firms in this niche design and sell vehicle kits and related components — replica and specialty platforms such as those named in the listing text — and work with customers, suppliers, dealers, and professional partners through design, sales, manufacturing support, and aftersales channels. A business of this type typically sits at the intersection of consumer sales, engineering design, and small-to-mid-size manufacturing operations.
A leak-site claim against such a company matters because kit-car and specialty automotive manufacturers often hold a mix of customer and dealer contact data, payment-related records, engineering and design files, supplier and pricing information, and ordinary corporate finance and legal records. Whether any of that was involved here is unconfirmed. The consequence of a credible incident in this sector would not be abstract: it would touch customers, employees, litigation counterparties, and commercial partners who depend on confidentiality of designs, contracts, and personal or financial details. Again, that is why listings attract attention — not because this listing has been proven true.
The information in question
Structured public fields associated with this report mark named exposed data types as not disclosed in a confirmed sense. The metaencryptor listing text, however, claims a broad set of categories totaling on the order of about 130GB. According to that claim, the material would include correspondence such as PST email archives, CRM contacts associated with GoldMine, ERP and pricing information, engineering CAD work in formats associated with SolidWorks and Rhino, banking statements, insurance policies, tax documentation, legal contracts and NDAs, and database backups. The same listing language asserts inclusion of detailed materials related to several ongoing lawsuits — parties, witnesses, testimonies, and related case files. That description is the group’s assertion, not a verified inventory.
Organizations in manufacturing and specialty automotive commonly hold some combination of customer and prospect contacts, order and payment data, employee records, engineering drawings, supplier terms, and privileged legal files. If files of those kinds were ever taken from any similar firm, the sensitivity would vary widely: CAD and pricing can affect competitive position; correspondence and CRM data can expose personal and business contact details; banking, tax, and insurance records can enable fraud; litigation files can harm privacy and legal strategy for people far outside the company. None of that establishes what, if anything, left FactoryFive’s systems. Exact contents, if any, remain unconfirmed.
The real-world impact
For people who deal with FactoryFive as customers, employees, suppliers, or parties connected to legal matters, the practical question is conditional. If contact databases or email archives were involved, risks could include targeted phishing, social engineering that references real orders or projects, and misuse of names, addresses, or phone numbers. If financial or tax-related documents were involved, identity fraud and payment diversion attempts become more plausible. If engineering files were involved, the harm is more commercial than personal — design leakage and competitive disadvantage — though individuals named in project correspondence could still be drawn into follow-on scams. If litigation-related files were involved, witnesses and counterparties could face privacy harm and pressure unrelated to any fault of their own.
For the organization, a public extortion listing can damage trust, distract leadership, and create legal and notification questions even when facts are disputed. A listing alone does not prove negligence, does not prove successful theft, and does not prove that published dumps will follow. It does establish that a known extortion brand has chosen to name the firm, which is enough reason for caution among people who have shared sensitive information with the business — and enough reason to wait for confirmation before treating any category list as settled fact.
What to do now
Treat this as a caution signal, not as notice that your data is definitely exposed. If you are a customer, employee, or partner, watch for unexpected messages that reference kit orders, invoices, engineering projects, or legal matters and that push you to click links, open attachments, or move money. Prefer official channels you already trust when verifying any urgent request. Consider placing appropriate fraud alerts with major credit bureaus if you have shared financial identifiers with the company, and review bank and card statements for unfamiliar charges. If you use unique passwords and multifactor authentication on email and financial accounts, keep those habits; if you reused passwords anywhere connected to work or purchases, change them on a device you trust.
If FactoryFive or a regulator later confirms an incident and offers guidance or monitoring, follow that primary notice over third-party summaries. Until then, avoid circulating unverified “dump” files or paying anyone who claims they can remove your data from a leak site. Readers who want a practical next check can run a free exposure scan of their email to see whether their address has already appeared in known breach datasets unrelated to this claim, and then tighten account security based on what they find.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Weber Water Resources Listed by metaencryptor Ransomware GroupAquamar Inc Listed by metaencryptor Ransomware GroupWoodlore International Inc. Listed by metaencryptor Ransomware GroupTrailer Transit Inc Listed by metaencryptor Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the FactoryFive Listed by metaencryptor Ransomware Group →
Publicly posted by metaencryptor — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.