FactoryFive Listed by Metaencryptor Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
FactoryFive was listed by the Metaencryptor ransomware group on September 26, 2026. The group claims the company was breached, but has not specified how many people may be affected or what data was taken; anyone who has data with FactoryFive should check the company’s notices and consider protective steps.
On September 26, 2026, the ransomware group Metaencryptor listed FactoryFive — also identified in the listing material as Factory Five Racing Inc., a kit-car manufacturer based in Wareham, Massachusetts — on its leak site. Public detail is limited. The listing is an unverified claim by the group; FactoryFive has not publicly confirmed any incident as of writing. Numbers of people affected, if any, are unknown, and independent confirmation from the company, regulators, or established breach indexes is not part of the available record.
Leak-site posts are pressure tactics. They can be accurate, partial, recycled, exaggerated, or false. What follows treats Metaencryptor’s listing as a claim, explains what such a claim does and does not establish, and outlines conditional steps readers can take if they have a relationship with the firm.
What is being claimed
Metaencryptor has listed FactoryFive on its leak site, according to the report dated September 26, 2026. The organization is described in associated material as Factory Five Racing Inc., a maker of kit cars including Cobra replicas, GTM, Type 65 Coupe, and 33 Hot Rod models, with an address at 9 Tow Road, Wareham, MA 02571-1086. The same material references a workforce on the order of about 90 employees and on the order of 158 endpoints, with revenue figures in a stated range of roughly $5.5–6.5 million per year and credit-card processing volume on the order of $4.3 million with an average ticket around $1,245. Those figures appear in the claim-side description; they are not independently verified here.
The group’s listing material also describes a claimed data set on the order of about 130GB and names categories it says were taken, including correspondence such as PST archives, CRM contacts associated with GoldMine, ERP and pricing information, engineering CAD work (SolidWorks/Rhino), banking statements, insurance policies, tax documentation, legal contracts and NDAs, and database backups, as well as detailed materials said to relate to several ongoing lawsuits — parties, witnesses, testimonies, and related case files. Method of access, timing of any intrusion, ransom demands, and whether any files were actually published are not established in the public facts provided. Scale of individual impact remains unknown. Nothing in this article treats those category lists as a confirmed inventory.
Who is Metaencryptor?
Metaencryptor is a ransomware and extortion actor known in public reporting for encrypting systems and threatening to publish stolen data if payment is not made. Like other groups in this category, it has used dedicated leak sites to name alleged victims and to post samples or larger archives as leverage. Public write-ups of the brand have described double-extortion patterns: disruption inside a network paired with the threat of data exposure.
How the group operates in general — leak-site pressure, claims of exfiltration, and timed publication threats — is separate from what can be proven about any single listing. For FactoryFive, the only incident-specific point in the given facts is that Metaencryptor listed the company and described certain data categories and volumes. Those statements remain the group’s claims. They do not, by themselves, prove intrusion, successful theft, or the accuracy of the file descriptions.
FactoryFive and its sector
FactoryFive, operating as Factory Five Racing Inc., is a specialist manufacturer of kit cars and related components — vehicles and builds that customers often assemble or finish themselves, including well-known replica and specialty models. Firms in this niche sit at the intersection of manufacturing, design engineering, dealer and customer sales, and aftermarket support. They typically maintain supplier relationships, customer and prospect records, payment processing, and detailed product and tooling information.
A claimed incident involving a company of this type matters because kit-car and specialty automotive businesses often hold a mix of commercial, financial, and engineering information, and sometimes sensitive legal or insurance files tied to products, partners, or disputes. Customers, dealers, employees, and counterparties may have shared contact details, order history, or contractual documents in the ordinary course of business. A leak-site listing does not prove those materials left the company; it does explain why people connected to the firm pay attention when a ransomware brand names it.
What was likely exposed
The facts do not include a confirmed, independent inventory of exposed data. Metaencryptor’s listing material claims exfiltration on the order of about 130GB and lists categories such as email/PST correspondence, GoldMine CRM contacts, ERP and pricing data, SolidWorks/Rhino CAD, banking statements, insurance policies, tax documents, legal contracts and NDAs, database backups, and lawsuit-related files including parties, witnesses, testimonies, and case materials. Those are attacker-side descriptions, not verified findings.
If files of the kinds manufacturers and small industrial firms commonly hold were involved at all, organisations in this sector typically retain some combination of the following — without any assertion that these items were taken in this case:
- Customer, dealer, and prospect contact and order records
- Employee and HR-adjacent administrative files
- Financial, banking, tax, and insurance paperwork
- Engineering drawings, CAD, and product configuration data
- Contracts, NDAs, and other legal correspondence
- Internal email and operational backups
Exact contents, whether any publication occurred, and who if anyone is personally affected remain unconfirmed. People affected are listed as unknown in the available facts.
What's at stake
For individuals, risk is conditional. If business contact data, emails, or financial identifiers related to them were among any materials an attacker obtained, possible outcomes include targeted phishing that references real orders or projects, attempts to reuse passwords from older messages, or social-engineering calls that sound more credible because they cite genuine details. Lawsuit-related files, if genuinely present in any stolen set, could expose witnesses or parties to unwanted contact or reputational pressure; that possibility is not established as fact here.
For the organisation, a public extortion listing can mean operational distraction, customer questions, and legal or contractual follow-up even when the underlying claim is disputed or incomplete. Engineering and pricing data, if exposed, could matter to competitive position; financial and tax files, if exposed, could matter to fraud risk. None of that diagnoses FactoryFive’s security program or proves negligence. A leak-site entry establishes that a group chose to name the company and to market a data description — not that every claimed file is authentic or that defenses “failed” in a particular way.
Readers should also remember that listings sometimes recycle older material or inflate scope. Conditional caution is warranted; panic is not.
What to do now
Treat the Metaencryptor listing as an unverified claim until FactoryFive or another authoritative source confirms otherwise. If you are a customer, dealer, employee, supplier, or other contact of FactoryFive, practical steps stay conditional on whether your information was involved — which is not known from the public facts:
- Watch for phishing or calls that reference kit orders, invoices, engineering projects, or legal matters tied to the company; verify through channels you already trust.
- If you reused passwords on any portal connected to the firm, change them and enable multi-factor authentication where available.
- Monitor bank and card statements for unfamiliar charges, especially if you paid the company by card.
- Keep copies of important contracts and correspondence you already hold; do not send sensitive documents in response to unexpected requests.
- If you believe you are named in litigation materials the listing describes, consider notifying your counsel rather than engaging unknown contacts.
You can run a free exposure scan of your email to check whether your address has appeared in known breach data sets elsewhere. That kind of check does not prove or disprove this specific listing, but it can show whether your credentials or personal details have surfaced in other documented incidents. Stay alert to official statements from the company; until those exist, the public record on this matter is the group’s claim and the limited structured facts above — not a claimed breach narrative.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
Aquamar Inc Listed by Metaencryptor Ransomware GroupCorona Corporation Listed by Metaencryptor Ransomware GroupTrailer Transit Inc Listed by Metaencryptor Ransomware GroupPlatinum Healthcare Staffing Listed by Metaencryptor Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the FactoryFive Listed by Metaencryptor Ransomware Group →
Publicly posted by metaencryptor — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.