LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › OneDealer Listed by hellcat Ransomware Group

HIGH severityUnverified claimHow we verify

OneDealer Listed by hellcat Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·February 25, 2025
OneDealer Listed by hellcat Ransomware Group

Reported February 25, 2025.

HIGH
Severity
February 25, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

OneDealer was listed by the hellcat ransomware group on February 25, 2025, after internal files were exfiltrated in a ransomware attack; the date of the intrusion has not been established. Individuals should check whether their information was exposed and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target software and service providers that sit at the centre of industry supply chains, using data theft and public leak-site listings as leverage. In late February 2025 one such listing named OneDealer, an organisation whose partners include major automotive brands and regional dealers. The claim, made by the hellcat ransomware group, asserts that large volumes of internal and partner records were taken. Because the number of people affected remains unknown and independent confirmation is limited, the incident still warrants careful attention from anyone whose data may have passed through OneDealer systems.

Public reporting so far rests almost entirely on the group’s own statements. What is known is that hellcat listed OneDealer on 25 February 2025 and described the exfiltration of internal files during a ransomware attack. The precise method of initial access, the duration of the intrusion, and any ransom demand have not been disclosed by the organisation or by independent investigators.

Breaking down the breach

According to the hellcat listing, the group obtained more than 330,000 records belonging to OneDealer and its partners. The records are said to include sales reports, leads, customer data, and vehicle details that contain vehicle identification numbers (VINs) and licence plates. The listing names a series of affected companies: AutoHellas, AutoBesikos, KosmoCar, AWT, Karenta AE, QA, Proaxia, Hyundai, BMW, Audi and Kia. No official statement from OneDealer confirming or denying the scale of the theft has been made public, and the total number of individuals whose personal information may be involved remains unknown. Timing details beyond the 25 February 2025 reporting date are also undisclosed.

Who is hellcat?

Hellcat is a ransomware operation that has appeared on multiple dark-web leak sites in recent years. Like many contemporary groups it practises double extortion: encrypting systems while simultaneously stealing data and threatening to publish it if a ransom is not paid. The group typically posts victim names, sample files and brief descriptions of the stolen material on its leak site to increase pressure. Its earlier campaigns have focused on mid-sized enterprises and service providers whose data can be monetised or used for further social-engineering attacks. Claims made on such sites are unverified until corroborated by the victim or by forensic analysis; the OneDealer listing should therefore be treated as an assertion by the attackers rather than established fact.

About OneDealer

OneDealer operates in the automotive retail and dealer-management sector. Organisations of this type commonly supply software platforms, inventory tools or shared services that connect car manufacturers, importers and local dealerships. They routinely handle sales pipelines, customer contact details, vehicle stock information and financing records. Because these systems sit between multiple brands and independent dealers, a single compromise can expose data belonging to several separate companies at once. That interconnected role is why a listing of OneDealer draws attention beyond the organisation itself: partners such as the named European dealers and global marques may find their own customer and vehicle records implicated.

What was likely exposed

The hellcat group claims the following categories of material were taken:

Exact file inventories, the proportion of personal versus purely commercial data, and whether any payment-card or identity-document scans were present have not been independently confirmed. Organisations that serve automotive dealers typically store names, contact numbers, addresses, purchase histories and vehicle identifiers; those are the classes of information most likely to appear if the claim is accurate. Until OneDealer or a forensic report publishes a verified inventory, the precise contents remain unconfirmed.

Why it matters

For individuals, exposure of customer and vehicle data can enable targeted phishing, fraudulent loan applications or the cloning of vehicle identities. VINs and licence plates, once public, can be cross-referenced with other open sources to build detailed profiles of owners. For the named dealerships and manufacturers, the leak of sales reports and lead lists may reveal commercial strategies, pricing and customer pipelines to competitors. OneDealer itself faces operational disruption, potential regulatory scrutiny under data-protection regimes, and the longer-term cost of restoring partner trust. Because the number of affected people is still unknown, the full scope of personal harm cannot yet be measured, but the combination of personal identifiers and vehicle records creates a concrete risk of secondary fraud.

If your data was in this claimed breach

Anyone who has bought, leased or enquired about a vehicle through a OneDealer partner should treat the possibility of exposure seriously. Begin by monitoring bank and credit accounts for unexpected activity and place a fraud alert with the major credit bureaux if you live in a jurisdiction that offers that service. Change passwords on any online portals linked to the dealership and enable multi-factor authentication where available. Be sceptical of unsolicited calls or emails that reference recent vehicle purchases or quote VINs. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets; such scans provide an early indication that further protective steps are warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyOneDealer security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See OneDealer’s full breach history →

More recent breaches

P**o*** Listed by hellcat Ransomware GroupApril 7, 2025Potomac Financial Services Listed by hellcat Ransomware GroupApril 7, 2025CVTE Listed by hellcat Ransomware GroupApril 7, 2025LeoVegas AB Listed by hellcat Ransomware GroupApril 5, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the OneDealer Listed by hellcat Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by hellcat — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram