Tan Chong Motor Holdings Berhad Listed by crypto24 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Tan Chong Motor Holdings Berhad has been listed by the crypto24 ransomware group, with internal files reported as exfiltrated. The listing was disclosed on 9 July 2025; the actual date of any intrusion has not been established. Anyone connected to the company should verify whether their information may have been exposed and take protective steps.
Tan Chong Motor Holdings Berhad, a Malaysian automotive group, was listed by the ransomware group crypto24 on or around 9 July 2025. The group claims it carried out a ransomware attack and exfiltrated more than 300 GB of internal files. The number of people affected is unknown, and independent confirmation of the intrusion or its full scope has not been made public.
Public information remains limited to the threat actor’s assertions on its leak site. No official statement from the company detailing the incident has been incorporated into the available record, leaving the precise timeline, entry method and verified impact undisclosed.
What happened
According to the listing reported on 9 July 2025, crypto24 claims to have conducted a ransomware attack against Tan Chong Motor Holdings Berhad that involved the exfiltration of internal files. The group stated that it removed over 300 GB of data. The facts identify the exposed material only as “internal files exfiltrated in ransomware attack,” with the more detailed inventory supplied solely by the attackers themselves. No public disclosure has confirmed when the intrusion began, how access was obtained, whether systems were encrypted, or whether a ransom demand was issued or paid. The scale of any operational disruption and the exact number of individuals whose information may have been involved remain unconfirmed.
Inside crypto24
Crypto24 is a ransomware group that has operated with a double-extortion model: after gaining access to a network, operators typically exfiltrate large volumes of data before deploying encryption and then threaten to publish the stolen material on a dedicated leak site if a ransom is not paid. The group has been observed listing corporate victims across multiple sectors and geographies, using the public naming of organisations as leverage. Its postings usually include sample file listings or volume claims to demonstrate possession of the data. In this case the listing of Tan Chong Motor Holdings Berhad constitutes an unverified claim by the group; no independent forensic confirmation of the attack or the volume of data has been released in the public record.
Who is Tan Chong Motor Holdings Berhad?
Tan Chong Motor Holdings Berhad is a long-established Malaysian company whose core activities centre on the assembly, distribution and retail of motor vehicles and related services. Organisations of this type routinely maintain extensive customer databases, sales and service records, dealer and partner contracts, financial systems, human-resources files and operational platforms that support invoicing, inventory and customer-relationship management. Because the company sits at the intersection of manufacturing, retail and finance within the automotive sector, a breach of its systems can expose both commercial information and personal data belonging to customers, employees and business partners. The potential reach of any compromise is therefore wider than a single corporate network.
What data was at risk
The facts state that internal files were exfiltrated. Crypto24 further claims the haul exceeded 300 GB and specifically listed customer databases (including systems identified as NAV, BRASSTAX, VTS, CRM and E-INVOICE), legal and HR documents, financial and employee records, and contractual documents with partners and customers. These categories are presented solely as the group’s assertions; independent verification of the precise contents, the completeness of any database, or the presence of particular personal identifiers has not been published. Organisations in the automotive distribution sector typically hold names, contact details, vehicle ownership and service histories, payment information, employment records and commercial agreements. Whether any or all of those elements were among the files taken remains unconfirmed beyond the threat actor’s statements.
Why it matters
If the claimed data are accurate, customers could face elevated risks of targeted phishing, identity fraud or unsolicited contact using details drawn from vehicle-purchase or service records. Employees whose HR or financial files were taken may be exposed to payroll diversion attempts, tax-related scams or credential-stuffing attacks. Business partners could see contractual terms or pricing information misused. For the organisation itself, the incident raises the possibility of regulatory scrutiny under data-protection rules, reputational damage among dealers and buyers, and the cost of forensic investigation, system remediation and customer notification. Because the number of affected individuals is unknown and the exact data elements unverified, the practical impact cannot yet be quantified, but the categories named by the group are among those that commonly enable secondary fraud when they appear in criminal markets.
What to do if you're exposed
Individuals who have done business with Tan Chong Motor Holdings Berhad or its subsidiaries, or who are current or former employees, should treat the possibility of exposure seriously even while details remain limited. Monitor bank and credit-card statements for unfamiliar activity, enable multi-factor authentication on email and financial accounts, and be alert to phishing messages that reference vehicle purchases, service appointments or employment details. Consider placing a fraud alert or credit freeze with the relevant credit-reporting agencies if you reside in a jurisdiction that offers those tools. Change passwords on any accounts that may have reused credentials linked to company systems. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan provides an early indication of whether personal information has circulated beyond this single incident.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
U.S. Vanadium Holding Company LLC Listed by crypto24 Ransomware GroupPalmgold Management Sdn Bhd Listed by crypto24 Ransomware GroupLarimart S.P.A Listed by crypto24 Ransomware GroupWarisan TC Holdings Berhad Listed by crypto24 Ransomware GroupLatest breaches
Publicly posted by crypto24 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.