LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › rollxvans.com Listed by ransomhub Ransomware Group

HIGH severityUnverified claimHow we verify

rollxvans.com Listed by ransomhub Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 10, 2024
rollxvans.com Listed by ransomhub Ransomware Group

Reported September 10, 2024.

HIGH
Severity
September 10, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

rollxvans.com has been listed by the ransomhub ransomware group, with internal files reportedly exfiltrated. The incident was disclosed on September 10, 2024, though the actual date of the breach has not been established.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On September 10, 2024, the website rollxvans.com appeared on a leak site operated by the ransomware group known as ransomhub. The group claims that internal files belonging to the company were exfiltrated during a ransomware attack. The number of people affected remains unknown, and public detail on the precise timing, method, or full scope of the incident is limited.

Rollx Vans manufactures and sells wheelchair-accessible vehicles, including customized minivans and full-size vans equipped with lowered floors, ramps, and hand controls. Because the company serves individuals who rely on specialized mobility equipment, any exposure of internal records carries practical consequences for customers, employees, and the business itself. What follows is a factual account of what has been reported so far.

Breaking down the breach

Public reporting on the incident centers on a single confirmed development: rollxvans.com was listed by the ransomhub ransomware group on or around September 10, 2024. According to the group’s claim, the attack involved the exfiltration of internal files. No further technical details—such as the initial access vector, the duration of unauthorized access, encryption of systems, or any ransom demand—have been disclosed in available records.

The number of individuals whose data may have been involved is listed as unknown. No file counts, sample data sets, or confirmation of whether systems were encrypted have been made public. The listing itself constitutes an unverified claim by the threat actor; independent verification of the breach’s full extent has not been provided in the reported facts. In short, the known record is narrow: a ransomware group asserts that it removed internal files from the organization and has published that assertion on its leak site.

Who is ransomhub?

Ransomhub is a ransomware-as-a-service operation that became active in early 2024. It functions by recruiting affiliates who carry out intrusions and deploy the group’s ransomware tools; in return, the operators take a share of any payments. Like many contemporary ransomware groups, ransomhub typically employs double-extortion tactics: data is stolen before systems are encrypted, and the threat of public release is used to pressure victims into paying.

The group maintains a dark-web leak site where it posts the names of organizations it claims to have compromised, sometimes accompanied by sample files or countdown timers. Public reporting has linked ransomhub to a range of sectors, including manufacturing, healthcare, and professional services, though each listing must be treated as a claim until independently confirmed. No statements attributed specifically to ransomhub about rollxvans.com beyond the listing itself appear in the available facts.

rollxvans.com and its sector

Rollx Vans specializes in the design, manufacture, and sale of wheelchair-accessible vehicles. Its offerings include new and used minivans and full-size vans modified with lowered floors, power ramps, hand controls, and other adaptive features intended to improve mobility for people with disabilities. The company emphasizes quality, safety, and customer support, and it provides nationwide delivery and service options.

Organizations in the adaptive-vehicle sector routinely handle sensitive personal and operational information. Customer records often include names, contact details, addresses, vehicle specifications tailored to individual medical or mobility needs, financing or insurance information, and service histories. Employee records, supplier contracts, and internal engineering or inventory files are also typical. A breach affecting such a business is consequential because the customer base includes people who may already face elevated privacy and security risks, and because disruption of operations can delay access to essential mobility equipment.

The information in question

The only data category named in the reported facts is “internal files exfiltrated in ransomware attack.” No more granular inventory—such as customer databases, financial records, employee files, or technical drawings—has been publicly itemized. Exact contents therefore remain unconfirmed.

Companies that manufacture and sell customized mobility vehicles typically store customer personal identifiers, medical or disability-related notes needed for vehicle configuration, payment and financing data, vehicle identification numbers, service records, and internal business documents. Employee and contractor information, as well as supplier and logistics data, are also common. Until the company or independent investigators release a verified list, any assumption about which of these categories were actually taken would be speculative. The public record states only that internal files were claimed to have been removed.

Why it matters

For individuals whose information may have been among the exfiltrated files, the practical risks include identity theft, targeted phishing, and fraud. Personal details combined with knowledge of a customer’s mobility needs can make social-engineering attempts more convincing. Financial or insurance data, if present, could be used for unauthorized transactions or claims. Because many customers of adaptive-vehicle firms have ongoing medical or support needs, any misuse of their data can create additional stress and administrative burden.

For the organization, the consequences include potential regulatory scrutiny, notification costs, reputational damage among a specialized customer base, and possible interruption of manufacturing or delivery schedules. Even when systems are not encrypted, the mere fact of data removal can trigger contractual obligations to customers and partners. The absence of confirmed numbers of affected people does not eliminate these risks; it simply means the scale remains an open question.

What to do if you're exposed

If you have done business with Rollx Vans or believe your information may have been involved, begin with basic protective steps. Monitor bank and credit-card statements for unfamiliar activity. Consider placing a fraud alert or credit freeze with the major credit bureaus. Be alert for unsolicited emails, calls, or messages that reference vehicle purchases, mobility equipment, or personal details you have shared with the company; treat such contacts as potential phishing until verified through official channels. Change passwords on any accounts that reuse credentials associated with the company, and enable multi-factor authentication wherever available.

Because the full list of exposed records has not been published, it is useful to check whether your email address has already appeared in other known breach data sets. Readers can run a free exposure scan of their email to determine whether their information has surfaced in previously documented incidents. Stay informed through official company notices if any are issued, and consult identity-theft resources provided by government consumer-protection agencies for further guidance tailored to your situation.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyrollxvans.com security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See rollxvans.com’s full breach history →

More recent breaches

www.alliancemat.com Listed by ransomhub Ransomware GroupDecember 27, 2024www.tekni-plex.com Listed by ransomhub Ransomware GroupDecember 7, 2024tekni-plex.com Listed by ransomhub Ransomware GroupDecember 7, 2024hanwhacimarron.com Listed by ransomhub Ransomware GroupDecember 5, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the rollxvans.com Listed by ransomhub Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by ransomhub — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram