Ucar Listed by unsafe Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Ucar Listed by unsafe Ransomware Group (reported December 21, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On December 21, 2022, the French organisation Ucar was listed by the ransomware group unsafe, which claimed to have carried out an attack involving the exfiltration of internal files. Public detail on the incident remains limited: the number of people affected is unknown, and no fuller technical account of timing, intrusion method, or confirmed data contents has been released beyond the group's listing and the reported characterisation of internal files taken in a ransomware attack.
For a company of Ucar's profile — a French firm with reported revenue around 33 million euros — any such claim raises practical questions about what internal material may have left its systems and what that could mean for staff, customers, and partners. The listing itself is an unverified claim by the group; independent confirmation of the full scope has not been set out in the available record.
Breaking down the breach
According to the reported information, Ucar was named on December 21, 2022, in connection with activity attributed to the unsafe ransomware group. The available summary states that internal files were exfiltrated in a ransomware attack. No figure has been given for the number of people affected, and details such as the precise date the intrusion began, how access was obtained, whether encryption was deployed alongside theft, or the volume of data involved remain undisclosed.
What is on record is therefore narrow: a listing by the group, a French country association, a revenue figure of 33.00 million, and the description that internal files were taken. Without further official disclosure, it is not possible to state the scale of the incident or to confirm every element of the group's claim. Ransomware incidents commonly combine data theft with pressure to pay, but the specific sequence and outcome in this case have not been publicly detailed beyond the points above.
The group behind it: unsafe
Unsafe is known publicly as a ransomware operation that lists victims and claims data theft as part of its activity. Like other groups in this category, it typically seeks to obtain internal material, threaten publication or further distribution, and use leak-site postings to increase pressure. Public reporting on such actors generally describes double-extortion patterns — encryption of systems paired with exfiltration — though the exact tactics used against any single victim can vary and are not always independently verified.
In this instance, the group has listed Ucar and is associated with the claim that internal files were exfiltrated. No additional statements from unsafe about this specific victim — such as sample file counts, screenshots, or deadlines — are included in the facts at hand. The listing should therefore be treated as the group's claim rather than as confirmed fact until corroborated by the organisation or other reliable sources. Prior public activity by ransomware groups of this type has often involved opportunistic targeting across sectors rather than exclusive focus on one industry.
Who is Ucar?
Ucar is a French organisation with reported revenue of approximately 33 million euros. Publicly, Ucar is recognised as operating in the vehicle rental and mobility sector in France, providing cars and related services to private and business customers. Companies in this field routinely manage customer booking and identity data, payment and billing records, employee information, fleet and contract details, and internal operational documents.
A breach affecting such an organisation is consequential because rental and mobility businesses sit at the intersection of consumer services and logistics. They hold data that can identify individuals, link them to locations and travel patterns, and support financial transactions. Even when the precise contents of a claimed exfiltration are unconfirmed, the sector's typical data holdings mean that any successful theft of internal files can create lasting exposure risks for customers, staff, and commercial partners.
What was likely exposed
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown — such as customer databases, employee records, financial documents, or specific file categories — has been disclosed. The number of people affected is unknown.
Organisations of Ucar's type commonly hold customer contact and identification details, reservation and rental histories, payment-related information, employee HR and payroll data, supplier contracts, and internal operational or fleet records. It is reasonable to note that these categories are typical for the sector, yet it is not established that any particular category was present in the material the group claims to have taken. Exact contents remain unconfirmed; readers should not assume specific data types were exposed beyond the stated description of internal files.
The real-world impact
For individuals, the main risks in incidents involving internal corporate files are misuse of personal details if those details were present — for example unwanted contact, phishing that references real relationships with the company, or attempts at identity fraud. Because the affected population size and precise data types are unknown, the concrete exposure for any one person cannot be stated with certainty. People who have rented from or worked with Ucar may still wish to treat unsolicited messages that cite the company with caution and to monitor financial and account activity.
For the organisation, a claimed ransomware incident with data exfiltration can mean operational disruption, regulatory notification duties under European rules, contractual questions with partners, and longer-term reputational cost. Recovery often involves forensic work, system hardening, and communication with those who may be affected. None of these outcomes are confirmed in detail here; they are the ordinary consequences that follow when internal files are reported stolen in this manner.
Were you affected?
If you have been a customer, employee, or partner of Ucar, practical first steps include watching for unusual emails or calls that reference the company, reviewing account and payment statements, and enabling stronger authentication on important online accounts where available. Official guidance, if Ucar issues any, should be followed when it appears. Because public detail on this incident is limited and the number of people affected is unknown, there is no definitive public list to check against.
You can also run a free exposure scan of your email address to see whether your information has already surfaced in known breach data sets. That step does not confirm involvement in this specific incident, but it can help you judge whether your details appear elsewhere and whether further monitoring or password changes are warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Hartl European Transport Company Listed by unsafe Ransomware GroupTAG Aviation Listed by unsafe Ransomware GroupHorwitz Horwitz & Associates Listed by unsafe Ransomware GroupWings Etc Listed by unsafe Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Ucar Listed by unsafe Ransomware Group →
Publicly posted by unsafe — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.